{"id":5562,"date":"2023-04-27T12:42:01","date_gmt":"2023-04-27T12:42:01","guid":{"rendered":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?p=5562"},"modified":"2023-08-04T20:15:58","modified_gmt":"2023-08-04T20:15:58","slug":"software-supply-chain-security-is-going-mainstream-in-2023","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/","title":{"rendered":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How."},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5563\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg\" alt=\"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg 800w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-300x150.jpg 300w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-768x384.jpg 768w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-540x270.jpg 540w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-162x81.jpg 162w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-360x180.jpg 360w, https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How-400x200.jpg 400w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><em><strong>As part of Solutions Review\u2019s\u00a0<a href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noopener\">Contributed Content Series<\/a>\u2014a collection of articles written by industry thought leaders in maturing software categories\u2014Tomislav Peri\u010din, the co-founder and Chief Software Architect at <span class=\"TextRun SCXW182976612 BCX0\" lang=\"EN\" xml:lang=\"EN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW182976612 BCX0\"><a href=\"https:\/\/www.reversinglabs.com\/\" target=\"_blank\" rel=\"noopener\">ReversingLabs<\/a>, <span class=\"TextRun SCXW100874411 BCX0\" lang=\"EN\" xml:lang=\"EN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW100874411 BCX0\">outlines some of the reasons software supply chain security is going &#8220;mainstream&#8221; in 2023. <\/span><\/span><span class=\"EOP SCXW100874411 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:80,&quot;335559740&quot;:276}\">\u00a0<\/span><\/span><\/span><\/strong><\/em><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Recent history is littered with tragedies that trace their roots to compromised or faulty supply chains. Whether it be the <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Chicago_Tylenol_murders\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Tylenol tragedy<\/span><\/a><span data-contrast=\"auto\"> in 1982, the <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Space_Shuttle_Challenger_disaster\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">1986 Challenger Disaster<\/span><\/a>,<span data-contrast=\"auto\"> or the (much) more recent <\/span><a href=\"https:\/\/www.cbsnews.com\/news\/eye-drop-recalls-2023-bacteria-infection-brands-cbs-news-explains\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">recall in the U.S. of over-the-counter eye drops<\/span><\/a><span data-contrast=\"auto\"> tainted with bacteria. <\/span><i><span data-contrast=\"auto\">Software<\/span><\/i><span data-contrast=\"auto\"> supply chain risk is an entirely different matter. The dangers posed by compromised or substandard software modules have maintained a low profile within many organizations, even as those organizations&#8217; reliance on software and cloud-based services through so-called &#8220;digital transformation&#8221; mushroomed in the last two decades. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">However, things have changed. SolarStorm, <\/span><a href=\"https:\/\/www.reversinglabs.com\/blog\/sunburst-the-next-level-of-stealth\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">the 2020 attack that compromised<\/span><\/a><span data-contrast=\"auto\"> the software maker SolarWinds&#8217; Orion software as well as other high-profile targets, led to an urgent reassessment of software supply chain risk by software development firms, their customers, as well as federal officials, and regulators. Attackers, be they cyber-criminal groups or nation-state actors, took note, as well. More than two years later, we are starting to see the byproducts of that shift in focus as software supply chain security emerges as a top area of concern and investment. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">How do we know? Here are four signs that software supply chain security is going &#8220;mainstream&#8221; in 2023: <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Software Supply Chain Attacks are Spreading\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The continuing drumbeat of supply chain attacks and compromises is the most obvious sign that focusing on software supply chain security is no distraction.\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Since the beginning of 2023, several high-profile incidents stemming from supply chain compromises have occurred. Most recently, we witnessed <\/span><a href=\"https:\/\/www.crowdstrike.com\/blog\/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">an attack on VOIP provider 3CX<\/span><\/a><span data-contrast=\"auto\">, which saw malicious code pushed to the company&#8217;s customers via a signed update for the 3CX desktop client application. Then there was <\/span><span data-contrast=\"none\">the attack on CircleCI<\/span><span data-contrast=\"auto\">, a continuous integration platform vendor that exposed private code repositories hosted on the platform to malicious actors.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Other incidents, like the <\/span><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/exposed-travis-ci-api-leaves-all-free-tier-users-open-to-attack\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">accidental disclosure<\/span><\/a><span data-contrast=\"auto\"> of stored secrets by the continuous integration platform TravisCI or <\/span><a href=\"https:\/\/securityledger.com\/2023\/01\/ces-overlooks-new-report-that-finds-auto-cyber-is-a-dumpster-fire\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">successful red team attacks on application infrastructure used by automakers<\/span><\/a>,<span data-contrast=\"auto\"> revealed how public and private code repositories and their secrets had become stepping stones to damaging attacks on applications and data. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Then there are the commodity attacks on <a href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/top-free-and-open-source-erp-solutions\/\" target=\"_blank\" rel=\"noopener\">open-source platforms<\/a>, including npm, PyPI, and NUGet, in which malicious actors plant thousands of malicious packages, many designed to sow confusion among developers. ReversingLabs has compiled data showing a nearly 300 percent increase in supply chain attacks on platforms like npm and PyPI over the last four years. Recent events show those <\/span><a href=\"https:\/\/www.darkreading.com\/application-security\/net-devs-targeted-with-malicious-nuget-packages\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">attacks spread<\/span><\/a><span data-contrast=\"auto\"> to smaller, less frequented repositories like NUGet for .Net developers.\u00a0\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Platform Operators Boost Supply Chain Defenses\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Threats and attacks on software supply chains are also driving investment by platform vendors in securing developers and code. Among the advances in recent months: GitHub introduced<\/span><a href=\"https:\/\/github.blog\/2023-01-09-default-setup-a-new-way-to-enable-github-code-scanning\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\"> automated vulnerability scanning<\/span><\/a><span data-contrast=\"auto\"> for code hosted on their repository. Recently, GitHub owner Microsoft <\/span><a href=\"https:\/\/www.theverge.com\/2023\/3\/22\/23651456\/github-copilot-x-gpt-4-code-chat-voice-support\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">integrated the OpenAi ChatGPT technology into CoPilot,<\/span><\/a><span data-contrast=\"auto\"> a code-focused AI chatbot that can speed development and help developers accelerate growth and avoid common coding mistakes. A r<\/span><a href=\"https:\/\/news.microsoft.com\/2023\/03\/28\/with-security-copilot-microsoft-brings-the-power-of-ai-to-cyberdefense\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">ecently unveiled<\/span><\/a><span data-contrast=\"auto\"> Security CoPilot will help security teams spot emerging threats by helping make sense of threat intelligence, correlate threat activity, and make decisions &#8220;at machine speed,&#8221; Microsoft said. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Beyond that, GitHub has <\/span><a href=\"https:\/\/thenewstack.io\/github-now-enables-you-to-find-and-fix-code-for-free\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">made its secrets scanning and detection feature available for free <\/span><\/a><span data-contrast=\"auto\">to public repositories hosted on the platform and strengthened account security for GitHub and npm account holders in ways that make it easier to implement two-factor authentication to protect developer accounts. By the end of 2023, GitHub will <\/span><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/github-to-require-all-users-to-enable-2fa-by-the-end-of-2023\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">mandate two-factor authentication (2FA)<\/span><\/a><span data-contrast=\"auto\"> for developer accounts.\u00a0\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Given the deep reliance on open-source code and robust coding and code-hosting platforms, including GitHub, npm, and PyPI, the steps taken by significant platform operators in recent months will have huge impacts on developer practices and behaviors as they offer evidence that the scourge of software supply chain threats and attacks prompt actions and investments from major players. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>The Federal Government is Looking to Regulate Software Quality\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">As much as the private sector drives innovation, the most salient moves to shore up the security of the software ecosystem and <a href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-supply-chain-erp-guide\/\" target=\"_blank\" rel=\"noopener\">supply chains<\/a> in recent months have come from the federal government. There, a series of orders and regulations have turned up the heat on software producers who do business with the federal government to fortify the security of developed code and the software supply chains that support it. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">First, there was the Biden Administration&#8217;s <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Executive Order 14028<\/span><\/a><span data-contrast=\"auto\">, issued in early 2021, and subsequent guidance, including the September memorandum <\/span><a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/09\/M-22-18.pdf\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">M-22-18<\/span><\/a><span data-contrast=\"auto\"> and <\/span><a href=\"https:\/\/media.defense.gov\/2022\/Sep\/01\/2003068942\/-1\/-1\/0\/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDF\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Enduring Security Framework practice guidelines<\/span><\/a><span data-contrast=\"auto\"> issued by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Office for the Director of National Intelligence. The federal guidance outlines specific goals and requirements for federal agencies and their software suppliers regarding software supply chain security. Those include using Software Bills of Materials (SBOMs) and adherence to <\/span><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-218\/final\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">NIST Special Publication 800-218<\/span><\/a><span data-contrast=\"auto\"> on developing a secure software development framework and subsequent NIST guidance on software supply chain security.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Finally, the recent publication of the Biden Administration&#8217;s National Cybersecurity Strategy began to shift the focus for securing software from end-users and individuals to software publishers, putting the onus for security on prominent players, the public and private sector, rather than continuing to blame the victims for breaches and adverse events. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Pushing software publishers to improve the security of their wares is a crucial part of all of these measures. Beyond handing down mandates, the Federal Government is taking steps to ensure those mandates turn into improved practices. For example, CISA has <\/span><a href=\"https:\/\/www.reversinglabs.com\/blog\/how-cisas-c-scrm-could-fill-the-gaps-on-software-supply-chain-security-policy-and-process\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">created a Supply Chain Risk Management Office<\/span><\/a><span data-contrast=\"auto\"> to operationalize software supply chain best practices in federal agencies. Meanwhile, another federal department, Federal Acquisition Security Council, is developing a standard scorecard for federal agencies to assess their supply chain risk based on federal guidelines from NIST and others.\u00a0 <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Development Teams are Wising Up\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Finally, developers and development organizations are coping with the threats of sophisticated cyber-criminals and nation-state groups. They are bolstering their defenses and skills to counter that threat. Development teams spent years <\/span><span data-contrast=\"none\">focusing on identifying and fixing software vulnerabilities to<\/span><span data-contrast=\"auto\"> the exclusion of all else. Meanwhile, the use of open-source code and public code repositories continued to grow unchecked, with little thought given to its underlying security.\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Development organizations are becoming more aware and wary of the risks lurking in their code and broader software supply chains. Free, powerful, and ubiquitous software modules like Core-JS are suddenly <\/span><span data-contrast=\"none\">viewed differently<\/span><span data-contrast=\"auto\">: as a cash-strapped, single-developer project runs out of a sanctioned country. Development organizations across the globe are increasingly asking not just &#8220;What is in our supply chain,&#8221; but also &#8220;Who is in our supply chain?&#8221;\u00a0 <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">At the same time, the parade of security incidents at significant platforms, and the resulting attention they receive, is raising developer awareness of long-recognized security risks. Platforms like npm and GitHub, long promoted as safe developer playgrounds, are now viewed as more ambiguous environments in which malicious actors troll for leaked credentials and threats lurk in the form of typo-squatted or corrupted packages, which can compromise entire development environments.\u00a0 <\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">That, in turn, is shifting developer behavior towards safer practices\u2014abandoning &#8220;hard-coded credentials&#8221; while embracing the scanning and analysis of third-party packages, compiled binaries, and more. <\/span><span data-contrast=\"auto\">This should pay big dividends. For example, our analysis of the 3CX r<\/span><span data-contrast=\"none\">evealed clear warning signs<\/span><span data-contrast=\"auto\"> in the compromised updates the company shipped to customers. More scrutiny of software artifacts post-build will surely derail some emerging supply chain attacks.\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Improving the quality and security of the software and services upon which our economy relies is truly a &#8220;boil the ocean&#8221; undertaking. The journey to a safer, more secure, more resilient software ecosystem has to start somewhere. Looking back, we may well decide that 2023 was an inflection point in that journey, when both the government and industry became serious about improving software security when the impact of that change in mindset finally began to show.\u00a0<\/span><\/p>\n<hr \/>\n<p style=\"text-align: justify;\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"third-1\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"ERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/erp-third.jpg\" alt=\"Download Link to ERP Buyer's Guide\" \/><\/a> <a class=\"third-2\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-manufacturing-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"MERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/merp-third.jpg\" alt=\"Download Link to MERP Buyer's Guide\" \/><\/a> <a class=\"third-3\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/free-distribution-erp-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"DERP Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2019\/06\/derp-third.jpg\" alt=\"Download Link to DERP Buyer's Guide\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of Solutions Review\u2019s\u00a0Contributed Content Series\u2014a collection of articles written by industry thought leaders in maturing software categories\u2014Tomislav Peri\u010din, the co-founder and Chief Software Architect at ReversingLabs, outlines some of the reasons software supply chain security is going &#8220;mainstream&#8221; in 2023. \u00a0 Recent history is littered with tragedies that trace their roots to compromised [&hellip;]<\/p>\n","protected":false},"author":635,"featured_media":5563,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[2963,2813,2184,2814,2811,2812],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.<\/title>\n<meta name=\"description\" content=\"As part of Solutions Review&#039;s Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.\" \/>\n<meta property=\"og:description\" content=\"As part of Solutions Review&#039;s Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/\" \/>\n<meta property=\"og:site_name\" content=\"Best ERP Software, Vendors, News and Reviews\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-27T12:42:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-04T20:15:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tomislav Peri\u010din\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ap0x\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tomislav Peri\u010din\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/\",\"name\":\"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg\",\"datePublished\":\"2023-04-27T12:42:01+00:00\",\"dateModified\":\"2023-08-04T20:15:58+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/6b853e55f92b2f1ff9d1f38e0ee619ce\"},\"description\":\"As part of Solutions Review's Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg\",\"width\":800,\"height\":400,\"caption\":\"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/\",\"name\":\"Best ERP Software, Vendors, News and Reviews\",\"description\":\"Buyer&#039;s Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/6b853e55f92b2f1ff9d1f38e0ee619ce\",\"name\":\"Tomislav Peri\u010din\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/08\/tomislav_pericin.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/08\/tomislav_pericin.jpg\",\"caption\":\"Tomislav Peri\u010din\"},\"description\":\"Tomislav founded ReversingLabs in 2009 and serves as Chief Architect leading all aspects of the company's product and services strategy and implementation. He has been analyzing and developing software packing and protection methods for over 17 years. As Chief Software Architect, he has conceived and driven the development of such projects as TiCore, TitanEngine, NyxEngine, and RLPack. Recently, he spoke at BlackHat, ReCon, CARO Workshop, SAS, and TechnoSecurity conferences.\",\"sameAs\":[\"https:\/\/www.reversinglabs.com\/\",\"https:\/\/www.linkedin.com\/in\/tomislav-periin-746064286\/\",\"https:\/\/x.com\/ap0x\"],\"url\":\"https:\/\/solutionsreview.com\/enterprise-resource-planning\/author\/tpericin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.","description":"As part of Solutions Review's Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/","og_locale":"en_US","og_type":"article","og_title":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.","og_description":"As part of Solutions Review's Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.","og_url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/","og_site_name":"Best ERP Software, Vendors, News and Reviews","article_published_time":"2023-04-27T12:42:01+00:00","article_modified_time":"2023-08-04T20:15:58+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg","type":"image\/jpeg"}],"author":"Tomislav Peri\u010din","twitter_card":"summary_large_image","twitter_creator":"@ap0x","twitter_misc":{"Written by":"Tomislav Peri\u010din","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/","name":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How.","isPartOf":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg","datePublished":"2023-04-27T12:42:01+00:00","dateModified":"2023-08-04T20:15:58+00:00","author":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/6b853e55f92b2f1ff9d1f38e0ee619ce"},"description":"As part of Solutions Review's Contributed Content Series, Tomislav Peri\u010din of ReversingLabs explains why supply chain security is mainstream.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#primaryimage","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg","contentUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/04\/Software-Supply-Chain-Security-Is-Going-Mainstream-in-2023.-Heres-How.jpg","width":800,"height":400,"caption":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/software-supply-chain-security-is-going-mainstream-in-2023\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/"},{"@type":"ListItem","position":2,"name":"Software Supply Chain Security Is Going Mainstream in 2023. Here\u2019s How."}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#website","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/","name":"Best ERP Software, Vendors, News and Reviews","description":"Buyer&#039;s Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/6b853e55f92b2f1ff9d1f38e0ee619ce","name":"Tomislav Peri\u010din","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/08\/tomislav_pericin.jpg","contentUrl":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/files\/2023\/08\/tomislav_pericin.jpg","caption":"Tomislav Peri\u010din"},"description":"Tomislav founded ReversingLabs in 2009 and serves as Chief Architect leading all aspects of the company's product and services strategy and implementation. He has been analyzing and developing software packing and protection methods for over 17 years. As Chief Software Architect, he has conceived and driven the development of such projects as TiCore, TitanEngine, NyxEngine, and RLPack. Recently, he spoke at BlackHat, ReCon, CARO Workshop, SAS, and TechnoSecurity conferences.","sameAs":["https:\/\/www.reversinglabs.com\/","https:\/\/www.linkedin.com\/in\/tomislav-periin-746064286\/","https:\/\/x.com\/ap0x"],"url":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/author\/tpericin\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts\/5562"}],"collection":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/users\/635"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/comments?post=5562"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/posts\/5562\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/media\/5563"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/media?parent=5562"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/categories?post=5562"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/enterprise-resource-planning\/wp-json\/wp\/v2\/tags?post=5562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}