4 Best Practices for Protecting Against Software Supply Chain Attacks

Integrating secure code signing, threat and malware detection, and SBOM generation

Published April 2024

x

Software supply chain attacks are increasing in frequency. A recent Gartner report says that 45% of companies worldwide will experience attacks on their software supply chains by 2025, a threefold jump from 2021.

Companies large and small are experiencing these attacks. By now, most everyone has heard of supply chain attacks at SolarWinds, CircleCI and 3CX. More recently, Micro-Star International (MSI) suffered an attack that compromised the private code signing keys used for its BIOS as well as keys used for Intel’s BootGuard.

While basic security measures, such as Zero Trust principles, provide companies with a first line of defense, more action is needed to secure a company’s software supply chain and software development lifecycle. Are you prepared?