Securing Supply Chains in the Open Source Era. Panel Discussion

Опубликовано: 16 Март 2026
на канале: Kaspersky Tech
187
0

As supply chains become an increasingly attractive target for cyberattacks, the urgency for improving their security is imminent. In this context, issues related to the use of open source software (OSS) in supply chains come to the forefront. On one hand, OSS offers immense opportunities for ICT developers worldwide, as well as helping to decrease the expenditures in supply chains. But on the other hand, it might be characterized as highly prone to cyberthreats and thus can become a “weak link”.
The latter is further aggravated by existing ambiguity regarding who is responsible for addressing the vulnerabilities in OSS.
Consequently, the “rules of the game”, securing the use of OSS in supply chains are anything but a “must” for the industry and the ICT community. Work on them requires input from developers of opensource components, their customers as well as from regulators and researchers.
During this session, we will delve into the complex world of supply chain cybersecurity focusing on open-source software from the perspectives of key stakeholder groups.
Participants will discuss:
• What makes supply chain attacks via vulnerabilities in open-source software more difficult to mitigate?
• When the code belongs to everyone, who is responsible for its security?
• Which regulatory approaches exist to ensure the cybersecurity of OSS in supply chains?

#SAS2023 #SupplyChain #Kaspersky