76% of organizations check AI code for security risks.
Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
AI CodeSoftware DevelopmentAI Code Security RisksVulnerability Management
Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.
Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Open SourceSoftware SecurityOpen Source DependenciesVulnerability Management
63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.
Black DuckNavigating Software Supply Chain Risk in a Rapid-Release World ·Dec 17, 2025
Organizations delivering expertise through open collaboration channels increased by 29%.
Black DuckBSIMM16·Feb 4, 2025
Collaboration
Establishment of standardized technology stacks rose by more than 40%.
Black DuckBSIMM16·Feb 4, 2025
Technology StackApplication Security
Nearly 30% more organizations now produce SBOMs to meet transparency requirements.
Black DuckBSIMM16·Feb 4, 2025
SBOMRegulatory Compliance
The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.
Black DuckBSIMM15 Report ·Jan 1, 2025
Adversarial tests
There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.
Black DuckBSIMM15 Report ·Jan 1, 2025
SCA
The number of organisations employing research groups to develop new attack methods has grown by 30%.
Black DuckBSIMM15 Report ·Jan 1, 2025
Research groups
A 22% rise in the number of organizations creating software bills of materials (SBOMs) for deployed software has been observed.
Black DuckBSIMM15 Report ·Jan 1, 2025
SBOMs
In 2008, 100% of organizations in BSIMM1 conducted software security awareness training. By BSIMM15, this rate has declined to 51.2% of organizations, marking the lowest rate to date.
Black DuckBSIMM15 Report ·Jan 1, 2025
Software security awareness training
Only 51.2% of organisations now offer basic security training, which is the lowest rate observed since the BSIMM initiative began in 2008.