5 ways APIs can be the weak link in supply chain security

5 ways APIs can be the weak link in supply chain security

Application programming interfaces (APIs) have become indispensable to the modern enterprise. They're the glue that allows organizations to connect their partners and customers — and the go-to tool that empowers developers to ...
NIST supply chain security guidance for CI/CD environments: What you need to know

NIST supply chain security guidance for CI/CD environments: What you need to know

The National Institute of Standards and Technology's new proposed guidelines for integrating software supply chain security into CI/CD pipelines have arrived at an opportune time for security teams, with attacks on the ...
EPSS vs. CVSS: Exploit prediction could change the game on software risk management

EPSS vs. CVSS: Exploit prediction could change the game on software risk management

Security teams are faced with more alerts than they can handle. SecurityScorecard and the Cyentia Institute estimate that organizations fix only 10% of the vulnerabilities in their software each month. That's not ...
Threat modeling and the supply chain: An essential tool for managing risk across the SDLC

Threat modeling and the supply chain: An essential tool for managing risk across the SDLC

As organizations seek better ways to establish secure-by-design software, threat modeling can play a huge role in anticipating, avoiding, and planning for potential risks in software across all phases of the software ...
The art of security chaos engineering

The art of security chaos engineering

One truism of the cybersecurity world is that attackers have a much easier job than defenders. Malicious cyber actors only need to find a single weak point in the IT armor defending ...
NIST CSF 2.0: What it means for modern software supply chain risk management

NIST CSF 2.0: What it means for modern software supply chain risk management

The latest draft of the cybersecurity framework proposed by the National Institute of Standards and Technology is receiving kudos from information security professionals ...

How ASPM Can Help with Software Supply Chain Security

Application security posture management (ASPM) aims to change the conversation and strategy around software supply chain security. Application portfolios are growing significantly, which is creating headaches for security teams that are responsible ...