Devops iconDevopsSep 28, 2026 ~3 min source read

Survey Finds Widespread Doubt in Tools That Protect Software Supply Chains

A Cloudsmith survey of 400 platform and security engineers in the U.S. and UK shows 73% have only moderate or no confidence in their artifact management tools to prevent supply-chain attacks, and many organizations still rely on manual incident responses and ad hoc SBOM use.

Survey: Lack of Confidence in Software Supply Chain Security Runs High

Share this story

Send the public story page.

Useful takeaways from this story.

73% of respondents are only moderately confident (58%) or not confident (15%) in existing artifact-management tools to stop software supply-chain attacks.

Responsibility for trust decisions is split: 39% favor centralized security/platform teams, 37% treat dependency trust as a shared responsibility with developers.

The useful part

Only 37% said they can automatically identify, block, and trace an intrusion within minutes. As a result, nearly two thirds (65%) are either investigating a different approach to compliance (45%) or are evaluating some type of security framework (25%), the survey finds. Cybercriminals will increasingly target those binaries using cyberattacks that will be launched at machine speed.

How it works

  • Overall, the top three concerns are attacks exploiting code to introduce malicious dependencies, followed by supply chain attacks blending into normal DevOps activities and automated systems modifying...
  • On the plus side, however, 61% are at least moderately confident that AI coding tools are not introducing additional vulnerabilities into their software supply chains.
  • However, only 32% said they are scanning the AI models they employ for specialized threats, compared to 41% that are scanning for basic integrity to, for example, verify checksums/provenance.
  • Half of respondents (50%) are relying on provenance or attestation data to validate software builds.
  • Additionally, a full 95% said they generate software bill of materials (SBOM) data but only 25% integrate and automate SBOM verification into security gatekeeping.

What to take from it

and UK are managing software supply chain security, compliance, AI-related risks and software artifacts. The challenge is that securing binaries is a much more complicated challenge than simply trying to fix issues at the source code level, he added. More challenging still, only 27% said they are very confident their organization could pass an unexpected audit of their software supply chain.

Example or evidence

  • Regardless of who is ultimately held accountable for securing the software supply chain, the one thing that is certain is more cybercriminals than ever are discovering just how soft the underbelly of...
  • Instead, three quarters (75%) said they use that data for ad hoc compliance only.
  • Finally, nearly half (49%) of respondents said their organizations will occasionally skip implementing a new security/developer feature, compared to 28% that admitted they do so regularly.
  • Ultimately, it's not clear which teams have responsibility for securing software supply chains.

Details worth keeping

Lack of Confidence in Software Supply Chain Security Runs High. Conducted by Cloudsmith, a provider of a platform for managing software artifacts, the survey also finds nearly half of respondents (48%) can identify an intrusion in their software supply chain but need to rely on manual efforts to enforce some type of quarantine or resolve the issue. Cloudsmith CEO Glenn Weinstein said that as it becomes more apparent in the AI era that changes will be made to how software supply chains will need to be secured, there will be more focus on securing binaries after applications are deployed.

Related coverage

  • Devops: March 2026: malicious versions of axios get published directly to npm.
  • Jscrambler: Software supply chain security has a well-defined starting line. It has no finish line, even though most programs are built as if it does. In recent years, organizations have made…
  • Dzone: Fifteen years in, and the conversation I have most often with security leads still starts the same way: how's your perimeter, how's your endpoint coverage, how's your SOC staffed?
  • Smartermsp: In 2026, supply chain attacks have become one of the most feared threats in cybersecurity, and for good reason.
  • Devops: CI/CD pipelines often hold privileged credentials, execute third-party code and connect directly to production, making pipeline security one of the most overlooked risks in modern DevOps.

More context around this story.

Why Software Supply Chain Security Is Moving to the Gate
Devops iconDevopsSep 24, 2026

Why Software Supply Chain Security Is Moving to the Gate

March 2026: malicious versions of axios get published directly to npm. May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection. August 2026: a worm uses one maintainer’s stolen credentials to self-propagate through keyv and its dependent packages.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app