Securing the Software Supply Chain: A C-Suite Imperative
Updated
In our latest Research Report, Securing Your Software Supply Chain: A Boardroom and C-Suite Imperative , completed in partnership with Sonatype, The Futurum Group examines how the software security conversation is shifting from technical teams to the boardroom.
Futurum's Mitch Ashley and Daniel Newman,
Cite this
Mitch Ashley and Daniel Newman, The Futurum Group, "Securing the Software Supply Chain: A C-Suite Imperative," April 3, 2025. https://preview.erikbethke.com/research-reports/securing-the-software-supply-chain-a-c-suite-imperative/

As software becomes the foundation of modern business, organizations face rising threats from vulnerabilities and malicious code embedded deep within their development pipelines. With open-source components comprising up to 90% of software today, the software supply chain has emerged as a target-rich environment for threat actors—and a new area of strategic risk for business leaders.
To combat these risks, enterprises must implement robust governance and security practices that span the entire development lifecycle. Software Bill of Materials (SBOMs), Software Composition Analysis (SCA), repository firewalls, and continuous testing are no longer optional. But securing the software supply chain isn’t just a technical challenge—it’s a leadership issue that requires executive oversight, board-level conversations, and strategic alignment.
In our latest Research Report, Securing Your Software Supply Chain: A Boardroom and C-Suite Imperative, completed in partnership with Sonatype, The Futurum Group examines how the software security conversation is shifting from technical teams to the boardroom. The report provides practical guidance on compliance, risk management, and technology investments needed to secure software across modern enterprises.
In this research report, you will learn:
- Why software supply chain attacks are rising and where your vulnerabilities may lie
- What current and upcoming regulations (like SBOM requirements) mean for your organization
- Five key questions executives and board members should be asking now
- Which technologies—SBOMs, SCA, repo firewalls—are essential to protecting your organization
If you are interested in learning more, be sure to download your copy of Securing Your Software Supply Chain: A Boardroom and C-Suite Imperative today.
In partnership with:

Published by Futurum.
More from Mitch Ashley
Okta Q2 FY 2027 Earnings Beat and Raise on Core Identity Strength
Mitch Ashley, VP and Practice Lead, CIO & Technology Buyers at The Futurum Group, reviews Okta’s Q2 FY 2027 earnings, where core identity strength and new products drove a beat and raise while agentic identity stayed an early, forward-looking driver.
AI Implementation Is the New Account Control Point
Mitch Ashley, VP & Practice Lead at Futurum, shares insights on how AI implementation is the new account control point. Read more on how hyperscalers are reorganizing to capture distributed AI buying authority in 2026.
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
Fernando Montenegro and Mitch Ashley of Futurum unpack Black Hat and DEF CON 2026: an agentic-AI wave on every booth, a record funding surge, a widening capability gap, and what a board will actually fund.