From Dev to Deploy: Standing Up A Software Supply Chain Security Program

Опубликовано: 27 Февраль 2026
на канале: ReversingLabs
74
1

Attacks like those targeting SolarWinds and 3CX have prompted calls for software producers to develop their applications with security in mind.

However, cybercriminals and state-backed hacking crews won’t wait for that to happen, and businesses can’t wait to use their commercial software either.

As such, we need to consider all the roles that participate in the supply chain, from development to procurement. That way, we can begin to manage this risk even when the software we rely on isn’t always secure by design.

However, securing software supply chains is no simple task.

Fortunately, a new book charts out a path for organizations to broadly identify cybersecurity risks and lock down development and procurement pipelines. In the latest edition of the RL Book Club Series, host Paul Roberts interviews Cassie Crossley, the Vice President of Supply Chain Security at Schneider Electric about her new book from O’Reilly: Software Supply Chain Security.

Key discussion points:

✓ The rapidly evolving threat environment of software supply chain attacks
✓ Where the weakest links are in organization’s software supply chain
✓ How software producers can assemble the building blocks for a robust software supply chain security program
✓ Why it is essential for software buyers to evaluate third-party risk in the supply chain

About RL
ReversingLabs is the trusted name in file and software security, to verify and deliver safe binaries. With the largest Threat Repository in the industry with over 40 billion searchable files, the Fortune 500 trusts their software supply chain security and malware analysis with ReversingLabs. Learn more: https://www.reversinglabs.com/

RL - Trust Delivered.

Be sure to subscribe to RL and follow us on social media →
  / reversinglabs  
  / reversinglabs  
  / reversinglabs  
  / reversinglabs