The State of

Software Supply Chain Security

Open-source threats are everywhere, and so is the spending to stop them. Yet most organizations still struggle to understand real risk, and more tools haven’t led to better outcomes.

This report cuts through that complexity.

Synthesis of 30+ Industry Reports

We spent 100+ hours analyzing reports, cutting through the noise, and distilling what organizations are actually doing in practice.

Common Anti-Patterns

Across organizations, the same problems show up: vulnerability alert fatigue, inconsistent or lapsed governance, and risks teams aren’t even aware of.

Benchmark Your Organization

Many teams rely heavily on CVSS scores to prioritize vulnerabilities—but this often leads to noise, missed context, and ineffective risk management.