New Platform Delivers Increased Scale While New Features Add Efficiency in the Software Development Life Cycle and The SOC
Austin, TX - August 5, 2025 - NetRise, the leader in software supply chain security — building software asset inventories that enable enterprises to identify and manage risk in software that actually runs on devices across global organizations — announced a significant update to its core product platform. This update makes users' time more efficient and effective in prioritizing, mitigating, and remediating vulnerabilities found in the software they produce and reducing risk in the environments in which that software runs.
Key features introduced into the NetRise platform include:
"When we analyze systems and artifacts, we typically find hundreds or even thousands of vulnerabilities, but the vast majority are in components that never actually execute. This creates a dangerous signal-to-noise problem - security teams waste precious time investigating CVEs in dormant libraries while missing the critical vulnerabilities in applications that run," said Michael Scott, co-founder and CTO of NetRise. "By mapping the execution chain from autostart entries through scripts to the actual vulnerable components, we can reduce vulnerability noise drastically and help teams focus on what actually matters: the vulnerabilities that can actually be exploited when the asset powers on or loads. This is the difference between theoretical risk and real attack surface."
In its Supply Chain Visibility & Risk Study, published in Q4 2024, NetRise reported that on networking devices whose compiled software NetRise analyzed, an average of 1,120 CVEs were found per device. The report showed how to prioritize those CVEs to focus on those that were network accessible, greatly reducing the work required of a manufacturer's development team or of an enterprise's third-party risk management team.
"Today's announcement, giving those teams visibility into components that autorun on startup, reduces that work even further," said Pace. "This allows software developers to remediate the most critical vulnerabilities, reducing the time to deliver secure software. And for buyers of networking and other connected devices, third-party risk teams and their partners in procurement now have the tools to negotiate more effectively with their vendors to further reduce risk in the enterprise."
Resources
About NetRise
Based in Austin, Texas, NetRise protects organizations from cybersecurity risk with a revolutionary approach to software supply chain security. By analyzing compiled code rather than source code, its category-redefining platform creates a software asset inventory that identifies risk within the software actually installed on the systems critical to enterprise infrastructure. With NetRise, software producers and device manufacturers alike build a more accurate view of the software composition of their products. Likewise, cybersecurity professionals within the enterprise and federal government can quickly identify vulnerabilities and other software supply chain risks in the assets that run their organization. NetRise provides both groups with the means to respond quickly to threats identified by the NetRise platform. When unforeseen software vulnerabilities are exploited by bad actors,NetRise enables rapid identification, prioritization, mitigation, and policy updates, reducing materialrisk to the business. https://www.netrise.io/
Media Contact for NetRise:
Danielle Ostrovsky
Hi-Touch PR
410-302-9459
ostrovsky@hi-touchpr.com