Fragile by Design: Large-Scale Evidence of Software Supply Chain Risk
NetRise CEO Tom Pace explores why source code and manifests reflect intent, while compiled binaries expose reality, and what that means for developers, enterprises, and policymakers trying to manage software supply chain risk.
Webinar
Fragile by Design: Large-Scale Evidence of Software Supply Chain Risk
Learn why visibility into compiled code is the key to building true software assurance — and how NetRise is helping organizations uncover and address hidden vulnerabilities before they become front-page news.
Key Takeaways
Large-scale proof the supply chain is brittle:
Drawing on millions of analysed binaries, firmware images, and software artefacts, the keynote argues systemic risk is widespread—and often missed by traditional AppSec tooling.
The numbers show “blind trust” is failing:
Findings include 88% of firmware images with 100+ known vulnerabilities, 50%+ with hardcoded credentials, and 60%+ using outdated/unsupported components—signals of ecosystem-level weakness, not edge cases.
Binaries reveal reality—and visibility enables assurance:
Pace contrasts source code/manifests (intent) with compiled binaries (truth), making the case that compiled-code visibility is foundational to real software assurance and to finding hidden issues before they become incidents.
Stay up to date with the news
Sign up to get our free insights delivered to your inbox.
You might also like
Learn how we helped the customers to reach the next level
Webinar
The Dependency Mirage: Hidden Vulnerabilities in Compiled Binaries
Webinar
Keeping the Pace: Innovation Insights - Vulnerability Prioritization
White Paper
Your Security Scans Are Missing Critical Vulnerabilities