# Experts Debate Software Supply Chain Policy Gaps

Published: 2022-05-12 · Severity: low · Sectors: government-national, defense, energy, telecommunications, healthcare, non-profit
Canonical: https://vorant.io/reports/edb68730-e626-53ae-b776-c521f923d9fc/experts-debate-software-supply-chain-policy-gaps

> Atlantic Council panel of five experts discusses policy challenges in securing open-source software supply chains, citing SolarWinds and Log4j as key drivers.

This is a policy discussion piece from the Atlantic Council's Cyber Statecraft Initiative, featuring five experts (from NCC Group, Electronic Arts, Chainguard, Cisco, and the Atlantic Council itself) reflecting on the state of software supply chain security. The panel addresses national security implications of insecure open-source dependencies, referencing Executive Order 14028 and NIST's supply chain risk management guidance as recent US policy responses. Key incidents cited include the Sunburst/SolarWinds espionage campaign, the Log4j vulnerability, and the Blackbaud ransomware incident affecting over a thousand nonprofit organizations.

The discussion is largely conceptual and policy-oriented rather than tied to a specific active threat. Experts highlight structural challenges including the complexity of software dependencies, the difficulty of tracking open-source components (SBOMs as a partial solution), under-resourced maintainers, and gaps in public-private collaboration such as CISA's Joint Cyber Defense Collaborative and OpenSSF. Proposals include establishing dedicated federal offices for open-source security, incentivizing responsible vulnerability disclosure, and greater US-EU coordination on standards.

This article contains no new technical indicators, active campaigns, or novel threats — it is a retrospective and forward-looking policy piece referencing well-known historical incidents (SolarWinds, Log4j, Blackbaud) to frame recommendations for legislative and organizational action on software supply chain risk management.

## Mentioned in this report

- Campaigns: Sunburst

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-55reflections-on-trusting-trust-securing-software-supply-chains

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/edb68730-e626-53ae-b776-c521f923d9fc/experts-debate-software-supply-chain-policy-gaps.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
