Atlantic Council experts assess software supply chain security gaps
Five cybersecurity experts discuss challenges in securing software supply chains, emphasizing the need for improved public-private collaboration, open-source ecosystem investment, and government coordination.
The Atlantic Council convened five cybersecurity experts to examine the national security implications of insecure software supply chains and pathways to improvement. The discussion highlighted that modern infrastructure depends heavily on open-source code maintained by volunteers for whom security may not be a priority. Between 2010 and 2021, at least forty-two attacks or vulnerability disclosures involved open-source projects, including the SolarWinds compromise. Experts noted that President Biden's May 2021 Executive Order 14028 and subsequent NIST guidance represented important first steps, but significant policy gaps remain.
The panelists emphasized that securing software supply chains is extraordinarily complex, with vulnerabilities cheap to create but expensive to find. They noted that software bill of materials (SBOMs) are only one piece of the puzzle and cannot alone assess whether components are secure. The experts called for "shift left" approaches that assume vulnerabilities exist and focus on systematic ecosystem improvements through better programming languages, scalable vulnerability-finding tools, and early detection. They stressed the importance of multi-factor authentication adoption across platforms like GitHub and the need for coordinated transatlantic standards.
Key recommendations included establishing dedicated government offices for open-source security within CISA, creating grant-making capabilities to fund community-driven security improvements, ensuring legal protections for good-faith security researchers, and treating open source as critical infrastructure deserving regular proactive investment. The experts agreed that collaboration between government, industry, and the open-source community through forums like the Open Source Security Foundation (OpenSSF) represents the most promising path forward, but emphasized that piecemeal initiatives cannot comprehensively address lifecycle security challenges.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-55reflections-on-trusting-trust-securing-software-supply-chains
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free