Practical Software Supply Chain Security Solutions - Robert Marion @OWASPGLOBAL
Practical Software Supply Chain Security Solutions - Robert Marion  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
The frequency of Software Supply Chain attacks has been increasing over the last several years. This is, in part, due to the fact that the term “Software Supply Chain Attack” actually refers to a set of attacks that include: Repo Jacking, Repo Poisoning, Typo Squatting, and Dependency Confusion. Threat actors, such as Nation states, select high value targets that can be extremely disruptive. They weaponize the software supply chain against their enemies (real or perceived) to wreak physical infrastructure damage or engage in commercial and governmental espionage. Attackers who are motivated by money have been able to demand huge ransoms, which would have been impractical in the past but have been made easy by cryptocurrencies. Frequently, they seek soft targets. Hospitals, municipalities and schools can be notoriously lax in their software security efforts. Often, they lack the capital and expertise to enable a successful defense against ransomware gangs.


Governments and the private sector are investing in defensive measures. Europe has responded with the Cyber Resilience Act. The US has mandated SBOMs as a countermeasure against supply chain attacks. If you know what is in your code then such an attack is unlikely. Right? Not exactly. In the commercial sector, a huge software security industry has arisen. In 2023 it was estimated to be valued at approximately 172 billion USD and it is a growing market. Yet this has not resulted in a diminishing threat.


In this presentation, I am going to describe practical strategies for improving your organization’s ability to defend against software supply chain attacks.

-

Managed by the OWASP® Foundation
owasp.org
Practical Software Supply Chain Security Solutions - Robert MarionDay In the Life Of Supply Chain Security ResearcherOWASP VXDF: Is that really vulnerable? Show me the VXDF!Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough  - Track 1OWASP Global Board of Directors - March 2026 Public MeetingOWASP Global Board of Directors Meeting - June 2025Trust No One – Especially the Agents  Building Zero Trust Through Machine Identity Track 2OWASP Board Finance Summary - July 2026Credential Sharing as a Service: the Dark Side of No CodeOWASP Cornucopia - Stop Lecturing, Start Playing!Building Resilient Applications with Effective Threat ModelingBridging Security & Privacy Standards: Harnessing OpenCRE for Effective Mapping - Dimitar Raichev
OWASP Foundation |

Practical Software Supply Chain Security Solutions - Robert Marion

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER