Report by Black Duck
Navigating Software Supply Chain Risk in a Rapid-Release World
Key Findings
54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.
76% of organizations check AI code for security risks.
Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.
63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.
60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.
Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.
35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.
Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.
59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.
95% of surveyed organizations reported using AI tools in software development.
49% of organizations using at least three compliance controls remediate critical vulnerabilities within a day.