RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityMarch 8, 2023

Why software transparency is critical

Understanding supply chain security is critical in a software-driven society. Here's an overview of our upcoming book.

Chris Hughes, Co-founder and CISO, Aquia.Chris Hughes
FacebookFacebookXX / TwitterLinkedIn
LinkedIn
blueskyBluesky
Email Us

Main Story

IntroChapter 1: Background on software supply chain attacksChapter 2: Existing approaches to supply chain risk managementChapter 3: Vulnerability databases and scoring methodologiesChapter 4: Rise of the Software Bill of Materials (SBOM)Chapter 5: Challenges in software transparencyChapter 6: The cloud and containerization of softwareChapter 7: Existing and emerging supply chain guidanceChapter 8: Software transparency in operational technologyChapter 9: Practical guidance for software suppliersChapter 10: Practical guidance for software consumersChapter 11: Top software transparency predictionsMoving forward on supply chain security

By now the topic of software supply chain security is clearly among the most discussed topics in the IT/Cybersecurity industry. We know from reports from groups such as Sonatype that software supply chain attacks are up 742% over the last 3 years, and we have seen incidents hit everything from proprietary software vendors to open-source software (OSS) projects and components, impacting thousands of customers and millions of users around the world.

This is why along with my co-author Tony Turner, we decided to write “Software Transparency: Supply Chain Security in an Era of a Software-Driven Society” with the publisher Wiley. Our technical editor is CycloneDX and Dependency Track founder/creator Steve Springett from OWASP, and our Foreword is written by Dr. Allan Friedman, who has spearheaded Software Bill of Materials (SBOM efforts), first for the NTIA and now CISA.

The book (available now for pre-order) is set to be published in June of 2023. Here's an overview, with walk-throughs on each chapter, explaining what we cover and what readers will learn.

Chapter 1: Background on software supply chain attacks

In this initial chapter of the book we cover various topics such as the incentives for attackers, anatomy of hypothetical software supply chain attack as well as threat modeling to mitigate the risk of software supply chain attacks. We also cover various landmark cases that have impacted proprietary software vendors, open source software (OSS) components and managed service providers (MSP)’s.

Chapter 2: Existing approaches to supply chain risk management

Following the initial chapter of the book we take a look at the traditional approaches to vendor and supply chain risk management. This includes covering various application security maturity models, application security assurance testing methodologies and tooling as well as approaches to hashing and code signing.

Chapter 3: Vulnerability databases and scoring methodologies

This chapter provides a detailed and comprehensive overview of the vulnerability database ecosystem. We discuss some of the longstanding vulnerability databases and their origins, as well as emerging databases that address some of the existing gaps. We also take a deep dive into vulnerability scoring, metrics and exploit prediction.

Chapter 4: Rise of the Software Bill of Materials (SBOM)

If you’ve been paying any attention to the software supply chain conversation, you’ve inevitably heard the term “SBOM”. This chapter is dedicated to providing an overview of the origin story of SBOM, from sources such as NTIA and CISA among others, as well as detailed breakdowns of the various SBOM formats. We also discuss the emergence of efforts such as Vulnerability Disclosure Programs and Reports, as well as Vulnerability Exploitability eXchange (VEX), which aims to provide context to SBOM’s to make them actionable for software consumers.

Chapter 5: Challenges in software transparency

One thing that is certain is that the path to software transparency is complex and challenging. In this chapter we discuss concepts such as firmware and embedded software as well as the OSS ecosystem. We also discuss user and legacy software and the challenges around secure transport of software, data and artifacts.

Chapter 6: The cloud and containerization of software

Software transparency on-premise and in the cloud look much different, each with their own unique considerations. In this chapter we cover cloud computing, different service models, complexity as well as the emergence and growth of Containers, Kubernetes and Serverless. We also discuss challenges associated with Software-as-a-Service (SaaS) and the continued adoption of DevSecOps.

Chapter 7: Existing and emerging supply chain guidance

Software supply chain security is a complicated topic. Luckily we are seeing a tremendous amount of emerging guidance, resources and best practices. This chapter is focused on covering guidance from sources such as NIST, Google, CIS, Microsoft, OWASP and others, culminating in the most comprehensive coverage of existing guidance on the topic anywhere in the industry.

Chapter 8: Software transparency in operational technology

Software transparency in IT is often the primary point of conversation around software supply chain security, that said Operational Technology (OT) doesn’t get sufficient attention. This chapter focuses on the potential kinetic effects of software, legacy software risks and also software transparency considerations and risks for industrial control systems (ICS).

Chapter 9: Practical guidance for software suppliers

Software supply chain risks most often originate through suppliers. Hence why this chapter is dedicated to providing practical guidance to software suppliers when it comes to transparency and supply chain security. Topics include vulnerability disclosure and response, product security teams, copyright concerns, the use of OSS and where and how to leverage automation.

Chapter 10: Practical guidance for software consumers

While suppliers are in the best position to address risks, it is often the consumers who bear the brunt of security incidents and data breaches. This chapter provides comprehensive guidance to software consumers on how to mitigate their risks of being impacted by software supply chain attacks. This includes guidance around the use of SBOM’s, VEX and vulnerability disclosures, understanding their software supply chain and suppliers, and the role that activities such as virtual patching play in some scenarios.

Chapter 11: Top software transparency predictions

While attempting to predict the future is futile, we do our best to take a look at the direction the industry and society is headed and what we may be able to anticipate moving forward. This includes detailed coverage of emerging regulations and requirements, the power of Governments to affect markets, the acceleration of supply chain attacks and risks associated with our ever increasingly connected societies.

Coverage includes efforts in the U.S. such as the Cyber Executive Order (EO) and National Cyber Strategy, as well as efforts from the EU, UK and others around the world. All of these efforts are aimed at addressing the systemic risk we now face as a society due to the pervasive nature of software in nearly every aspect of our lives.

Moving forward on supply chain security

It is clear that the trend of software supply chain attacks is only accelerating as malicious actors realize the value of compromising a single target, whether a proprietary software vendor, OSS component or service provider and have a massive cascading downstream impact.

This reality requires further collaboration between development, security and operations — along with a whole industry effort to adopt modernized software supply chain practices and tooling, which we touch on throughout the book.

Given the ubiquity of software in every area of society, coupled with the complex interdependencies of the modern software supply chain, it is what many refer to as a Gordian knot of a challenge that presents unprecedented levels of systemic risk.

Tags:AppSec & Supply Chain Security

More Blog Posts

Main Story

IntroChapter 1: Background on software supply chain attacksChapter 2: Existing approaches to supply chain risk managementChapter 3: Vulnerability databases and scoring methodologiesChapter 4: Rise of the Software Bill of Materials (SBOM)Chapter 5: Challenges in software transparencyChapter 6: The cloud and containerization of softwareChapter 7: Existing and emerging supply chain guidanceChapter 8: Software transparency in operational technologyChapter 9: Practical guidance for software suppliersChapter 10: Practical guidance for software consumersChapter 11: Top software transparency predictionsMoving forward on supply chain security

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagram
Chris Hughes
Why software transparency is critical: Understanding supply chain security in a software-driven society

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get key insights into why Gartner® said binary analysis is a must-have control in its recent CISO Playbook for Commercial Software Supply Chain Security.
  • Update your understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security,

Instagram
YouTubeYouTube
blueskyBluesky
Spectra Detect
for scalable file analysis,
Spectra Analyze
for malware analysis and threat hunting, and
Spectra Intelligence
for reputation data and intelligence.

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Related

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the riseFrontier AI agents: Only as safe as their containmentAI domain takeover takeaway: Focus on the harness not the model

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Learn More about OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

Frontier AI agents: Only as safe as their containment

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Learn More about Frontier AI agents: Only as safe as their containment
Frontier AI agents: Only as safe as their containment

AI domain takeover takeaway: Focus on the harness not the model

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Learn More about AI domain takeover takeaway: Focus on the harness not the model

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
AI domain takeover takeaway: Focus on the harness not the model
Robot agent
AI guardrails
Frontier AI controls