Security

Software Supply Chain — The New Cybersecurity Frontline

SBOM, CI/CD pipeline security, code signing, and continuous open source dependency management — how to structure a DevSecOps approach in the face of a fast-growing threat and an upcoming European regulatory deadline.

September 2026

According to Verizon's 2025 Data Breach Investigations Report, 30% of breaches involved a third party — double the 15% of the previous year, the sharpest year-over-year shift in the report's history.

A software supply chain compromise costs an average of $4.91 million and takes an average of 267 days to identify and contain — the longest detection time of any attack vector tracked.

The SBOM: from best practice to regulatory obligation

Europe's Cyber Resilience Act already imposes, since September 2026, a vulnerability notification obligation, with full compliance — SBOM, technical documentation, CE marking — required by December 2027.

The CRA applies to any company placing a digital product on the European market, regardless of where it is headquartered.

Signing and provenance: guaranteeing the integrity of deployed code

Every artifact produced by the CI/CD pipeline should be cryptographically signed, with a provenance attestation documenting how it was built.

No unsigned artifact, or one with unverified provenance, should be able to reach a production environment.

Key takeaways

  • Maintain an up-to-date SBOM for every critical application
  • Run software composition analysis (SCA) automatically on every build
  • Sign every deployed artifact and verify its signature before execution
  • Automate dependency security updates
  • Know whether the organization falls within the scope of the Cyber Resilience Act

YOUR GUIDE TO KEEP

Software Supply Chain — The New Cybersecurity Frontline

Get the complete guide to explore the topic further and share best practices with your team.

Download the PDF

Free PDF · Direct access

Ready to put it into practice?

Our experts help you move your cloud projects forward.

Go further

Securing LLMs in Production: Prompt Injection, RAG, and DefencesIA & Machine Learning

Securing LLMs in Production: Prompt Injection, RAG, and Defences

LLM applications introduce a new attack surface. Prompt injection, data leakage via RAG, jailbreaks: learn the attack vectors and the defences to put in place.

DevSecOps with GitHub Actions: Integrating Security into Your PipelinesCI/CD & GitOps

DevSecOps with GitHub Actions: Integrating Security into Your Pipelines

Security must be embedded from the first commit, not bolted on at the end. Here is how to build a complete DevSecOps pipeline with GitHub Actions.

Kering SRECase Study

Kering SRE

Build a tailored Well-Architected review framework that's technically rigorous and adopted across diverse teams.