RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.

Read More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityApril 20, 2023

Companies scramble to cover software supply chain security gaps: 3 key survey takeaways

In a new ReversingLabs Software Supply Chain Risk Survey, IT pros say supply chain security poses an “enterprise-wide” risk that traditional app sec tools can't address.

paul roberts headshot black and white
Paul Roberts, Director of Content and Editorial at RLPaul Roberts
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
man stretched between browser windows

The cyber risks posed by vulnerabilities in the internal, open-source and third-party software that make up modern supply chains are a source of intense concern for both development teams and security operations centers, according to a recent Dimensional Research survey more than 300 IT professionals commissioned by ReversingLabs.

The ReversingLabs Software Supply Chain Risk Survey polled executives and IT professionals responsible for software at enterprise-scale companies. Respondents were split between North America (67%) and Europe (33%), with most saying they work in the technology (19%), financial services (13%), healthcare (9%) and telecommunications (8%) industries.

The findings underscore a growing alarm over the protection gap within both software development firms and their customers as software supply chain attacks and breaches, such as the 2020 SolarWinds attack and the more recent compromise at voice over IP (VoIP) vendor 3CX, become more common.

Here are three key insights from the ReversingLabs Software Supply Chain Risk Survey.

See survey infographicReplay: Webinar on the Supply Chain Risk SurveyGet eBook: Why Traditional App Sec Testing Fails on Supply Chain Security

1. Software supply chain risks are a major issue

The risks posed by the software supply chain looms large for most survey respondents.

Eighty-eight percent of respondents said software supply chain security presented an “enterprise-wide risk” to their organizations, while nearly two thirds (65%) said their organizations' software supply chain security program wasn't as mature as it should be.

88 percent of respondents said that software supply chain security presented an enterprise wide risk at their organization

Eighty-seven percent said their company detected software issues in its software supply chain in the last 12 months. Those risks came from several sources, including internally developed software, software licensed from third-party suppliers, and open-source software.

animated statistic of above text

Most organizations focus on vulnerabilities when assessing software supply chain risk, but understanding of the cyber risk is broadening. Asked what issues pose the biggest business risk to their organizations, 82% of respondents cited software containing vulnerabilities, and 55% said the exposure of secrets such as sensitive information, access tokens and credentials in software code, followed by secrets in malicious code (52%), and suspicious code (46%) that had been inserted into applications.

Software vulnerabilities in code were the most common issue survey takers reported, with 65% having encountered them in the last 12 months. But they also cited certificate misconfigurations (37%), exposed secrets (25%) and suspicious code (24%).

2. Supply chain risk goes beyond open source

The complexity of software supply chain security reflects the complexity of modern software development itself. Most respondents said their organizations rely on non-employees to help them develop software, including contractors (67%) and third-party software development firms (59%). And their organizations rely on internally developed (82%), commercial (79%) and open-source (74%) code in about equal measure.

When asked to name the source of software security issues such as tampering, vulnerabilities and malicious code, 70% cited open-source software. Far fewer cited internally developed software (59%) or software developed by contractors and third parties (57%).

But when asked to reflect on the issues within their own organizations, 47% said internally developed software was a major source of issues affecting their software supply chain — nearly as many as the 49% who named open-source software.

animated statistic of above text

3. Companies are retooling to secure the software supply chain

Despite the prevalence of supply chain risk, enterprise defenses for supply chain risks and threats are not where they should be. Asked whether their organizations' software supply chain security programs were “as mature as it should be,” nearly two thirds of respondents (65%) said no.

animated statistic of above text

That could be the result of a tooling gap. Existing application security technologies such as static and dynamic application security testing (SAST and DAST) focus on the problem of identifying software vulnerabilities in code under development. Software composition analysis (SCA) technology — another common application security tool — uses an inventory of the open-source modules used in enterprise code bases to root out issues related to licensing, compliance and code quality.

Both technologies are in wide use. More than half (54%) of respondents said their organizations use SAST technology, 42% use DAST and 40% use SCA tools. But most survey respondents said these legacy technologies aren’t adequate to address the full spectrum of supply chain risks. Asked whether SAST, DAST and SCA solutions “fully protect companies from current software supply chain threats,” nearly three quarters (74%) said no.

bar graph of previous text statistics

Enterprises are already taking steps to address the gaps. Eighty percent of respondents said their organizations had initiatives under way to improve software supply chain security. The exact shape those initiatives will take isn’t clear, but 70% said solutions to mitigate software supply chain threats were “extremely” or “moderately” important.

Rising awareness is driving supply chain security changes

Current events are likely to drive even more attention to supply chain threats and attacks. Respondents showed a strong interest in supply chain security technologies before the recent revelations of a supply chain attack on the voice over IP firm 3CX, which led to compromises at several of the company’s customers.

Some of these attacks may be preventable. For example, a ReversingLabs analysis of the compromised software update to 3CX’s Windows and Mac OS desktop clients revealed clear signs of tampering. Had 3CX detected those signs in advance, it never would have released the update to customers.

Incidents such as SolarWinds and 3CX have raised awareness of software supply chain risks, including threats posed by software tampering, malicious code and secrets exposure from public and private code repositories. Those high levels of awareness are just the beginning of what's likely to be a much larger transformation in how enterprises handle software supply chain security.

See survey infographicJoin May 17 Webinar on the Supply Chain Risk SurveyGet eBook: Why Traditional App Sec Testing Fails on Supply Chain Security

Keep learning

  • Get up to speed on the Agentic Development Security tools landscape in this June 18 webinar with Forrester Sr. Analyst Janet Worthington.
  • Learn why binary analysis is a must-have control in the Gartner® CISO Playbook for Commercial Software Supply Chain Security.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:AppSec & Supply Chain Security

More Blog Posts

Shift lanes

5 lessons from vulnerability management's front lines

VM success is determined by findings reaching developers with context — which is getting more challenging. Here's why to shift gears.

Learn More about 5 lessons from vulnerability management's front lines
5 lessons from vulnerability management's front lines
Ransomware

Dependency attack takes down ed-tech platform at scale

The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

Learn More about Dependency attack takes down ed-tech platform at scale
Dependency attack takes down ed-tech platform at scale
Developer in action

GitHub breach: The development ecosystem is in the hot seat

This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.

Learn More about GitHub breach: The development ecosystem is in the hot seat
GitHub breach: The development ecosystem is in the hot seat
Robot Army

AI agents are the new insider threat

AI security leader and author Steve Wilson explains why you need to rethink security — and treat AI agents as digital workers.

Learn More about AI agents are the new insider threat
AI agents are the new insider threat

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top