1 related insight
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Browse Attomus insight related to software security, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Every organisation runs on software it did not write, built by people it has never met, assembled from components those people did not write either. The traditional governance answer to this uncomfortable arrangement is the supplier-assurance process: questionnaires, certifications, contractual flow-downs, and an annual review. Anyone who has sat on either side of it knows what it verifies – that somebody was able to fill in the questionnaire. The incidents of the past few years – build systems compromised to ship signed malware to thousands of organisations, popular open-source packages hijacked through maintainer accounts, a backdoor inserted into a compression library over years of patient, socially-engineered contribution – share a common feature. In each case the paperwork was in order. The supply chain failed precisely where assurance is thickest and verification thinnest: in the gap between what suppliers assert and what anyone can check.
Read article