Supply Chain Council of European Union | Scceu.org
News

Software supply chain attacks hit three out of five companies in 2021

Credit: Dreamstime

More than three in five companies were targeted by software supply chain attacks in 2021, according to a recent survey by Anchore

The survey of 428 executives, directors, and managers in IT, security, development, and DevOps found that the organisations of nearly a third of the respondents (30 per cent) were either significantly or moderately impacted by a software supply chain attack in 2021. Only six per cent said the attacks had a minor impact on their software supply chain.

The survey bracketed the discovery of the vulnerability found in the Apache Log4 utility. Researchers conducted the survey from December 3 to December 30, 2021. Log4j was revealed December 9. Before that date, 55 per cent of respondents said they had suffered a software supply chain attack. After that date, that number jumped to 65 per cent.

“That means there were brand new people who had not experienced a supply chain attack before Log4j, and that there were people who had experienced an earlier attack but were seeing a stronger impact after Log4j,” says Kim Weins, senior vice president at Anchore.

Tech companies hit harder by software supply chain attacks

The survey also found more tech companies were significantly impacted by software supply chain attacks (15 per cent), compared to other industries (three per cent). 

“Tech companies potentially create ROI for the bad actors,” Wein says. “If an attacker can get into a software product and that software product is delivered to thousands of other people, they now have a foothold in thousands of other companies.”

Supply chain security also appears to be grabbing mindshare in many organisations, with 54 per cent of respondents pegging it as a top or significant area of focus. Interest among mature container users was even higher, with 70 per cent declaring supply chain security a top or significant focus for them.

Related posts

Streamlining the floral supply chain … one stem at a time – DC Velocity

scceu

SanMar digitises financial supply chain to drive growth | Apparel Industry News

scceu

Will coronavirus infect your supply chain?

scceu