Black Duck

42 STATS5 REPORTS

All Statistics

54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Compliance ControlsVulnerability ManagementCritical VulnerabilitiesCritical Vulnerability Remediation

76% of organizations check AI code for security risks.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
AI CodeSoftware DevelopmentAI Code Security RisksVulnerability Management

Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Open SourceSoftware SecurityOpen Source DependenciesVulnerability Management

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Third-Party Software SecuritySoftware Supply ChainSBOM ValidationVulnerability Management

60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Vulnerability ManagementSoftware DevelopmentAutomatic Continuous MonitoringCritical Software Vulnerabilities

Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
AI-Generated CodeSoftware DevelopmentAI-Generated Code SecurityVulnerability Management

35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
ComplianceRegulatory

Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Vulnerability ManagementCritical Software VulnerabilitiesCritical Software Vulnerability Remediation

59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
SBOMSBOM ValidationVulnerability Management

95% of surveyed organizations reported using AI tools in software development.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
AI ToolsSoftware Development

49% of organizations using at least three compliance controls remediate critical vulnerabilities within a day.

Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Compliance ControlsVulnerability ManagementCritical VulnerabilitiesCritical Vulnerability Remediation

31.5% of organizations produce SBOMs due to industry regulations.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AISBOMs

96.1% of organizations are integrating open source AI models into their products.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AI

18% of companies are affected by "Shadow AI".

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AIShadow AI

21.1% of companies lack confidence in their ability to prevent AI from introducing security vulnerabilities.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AISecurity vulnerabilities

70.8% of organizations now produce Software Bills of Materials (SBOMs).

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AISBOMs

39.4% of organizations produce SBOMs due to customer and partner requirements.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AISBOMs

89.3% of organizations are already using AI-powered coding assistants.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AIAI coding assistant

A decisive shift towards memory-safe languages has been adopted by 80.4% of companies.

Black DuckThe State of Embedded Software Quality and Safety 2025·Aug 26, 2025
AI

91% of audited applications contain outdated open source software components.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

86% of audited applications contained open source vulnerabilities, with 81% containing high- or critical-risk vulnerabilities.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

The number of open source files in an average application has tripled over the last four years.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

64% of open source components were transitive dependencies.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

56% of all audited applications had license conflicts.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

97% of all applications evaluated contained open source software.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

Nearly 30% of component license conflicts were caused by transitive dependencies.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

90% of the applications contain components more than 10 versions behind the most current version.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

33% had open source software components with no license or a customized license.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

Automated verification of infrastructure security surged by more than 50%.

Black DuckBSIMM16·Feb 4, 2025
Infrastructure SecurityAutomationApplication Security

Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.

Black DuckBSIMM16·Feb 4, 2025
AI SecurityThreat IntelligenceApplication SecurityAI Vulnerabilities

Application of custom rules to automated code review tools to catch issues unique to AI-generated code increased by 10%.

Black DuckBSIMM16·Feb 4, 2025
AI SecurityCode ReviewDeveloper ToolsAI-Generated Code

Use of risk-ranking methods to determine where LLM-generated code is safe to deploy increased by 12%.

Black DuckBSIMM16·Feb 4, 2025
AI SecurityRisk ManagementApplication SecurityLLM-Generated Code

Streamlining of responsible vulnerability disclosure grew by more than 40%.

Black DuckBSIMM16·Feb 4, 2025
Vulnerability DisclosureRegulatory ComplianceApplication SecurityResponsible Vulnerability Disclosure

Organizations delivering expertise through open collaboration channels increased by 29%.

Black DuckBSIMM16·Feb 4, 2025
Collaboration

Establishment of standardized technology stacks rose by more than 40%.

Black DuckBSIMM16·Feb 4, 2025
Technology StackApplication Security

Nearly 30% more organizations now produce SBOMs to meet transparency requirements.

Black DuckBSIMM16·Feb 4, 2025
SBOMRegulatory Compliance

The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.

Black DuckBSIMM15 Report ·Jan 1, 2025
Adversarial tests

There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.

Black DuckBSIMM15 Report ·Jan 1, 2025
SCA

The number of organisations employing research groups to develop new attack methods has grown by 30%.

Black DuckBSIMM15 Report ·Jan 1, 2025
Research groups

A 22% rise in the number of organizations creating software bills of materials (SBOMs) for deployed software has been observed.

Black DuckBSIMM15 Report ·Jan 1, 2025
SBOMs

In 2008, 100% of organizations in BSIMM1 conducted software security awareness training. By BSIMM15, this rate has declined to 51.2% of organizations, marking the lowest rate to date.

Black DuckBSIMM15 Report ·Jan 1, 2025
Software security awareness training

Only 51.2% of organisations now offer basic security training, which is the lowest rate observed since the BSIMM initiative began in 2008.

Black DuckBSIMM15 Report ·Jan 1, 2025
Training