Report by Black Duck

BSIMM15 Report

6 FINDINGSPublished Jan 1, 2025
View Original Report →

Key Findings

The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.

Black DuckBSIMM15 Report ·Jan 1, 2025
Adversarial tests

There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.

Black DuckBSIMM15 Report ·Jan 1, 2025
SCA

The number of organisations employing research groups to develop new attack methods has grown by 30%.

Black DuckBSIMM15 Report ·Jan 1, 2025
Research groups

A 22% rise in the number of organizations creating software bills of materials (SBOMs) for deployed software has been observed.

Black DuckBSIMM15 Report ·Jan 1, 2025
SBOMs

In 2008, 100% of organizations in BSIMM1 conducted software security awareness training. By BSIMM15, this rate has declined to 51.2% of organizations, marking the lowest rate to date.

Black DuckBSIMM15 Report ·Jan 1, 2025
Software security awareness training

Only 51.2% of organisations now offer basic security training, which is the lowest rate observed since the BSIMM initiative began in 2008.

Black DuckBSIMM15 Report ·Jan 1, 2025
Training