The disconnect between senior executives and hands-on staff on software supply chain security is exacerbating the already rampant attacks on vulnerable software. While executives tend to have an overly optimistic view of their organization’s security posture, hands-on staff are more realistic about the threats and vulnerabilities. The gap in perception is evident in the implementation of security practices, use of solutions, and defense against open-source risk. Additionally, executives underestimate the time spent on vulnerability remediation and software package approvals. The research also highlights region-specific concerns, with North America leading in AI and ML adoption, EMEA exercising caution due to stringent regulations, and APAC showing enthusiasm for AI and ML tools, which could lead to increased security risks.

Software Supply Chain Security Divide
Executives believed they were implementing more security practices, using more solutions, and defending more effectively against open-source risk.










