-

Global C-Suite Survey Conducted by CloudBees Reveals Supply Chain Security Concerns

64% of executives don’t know who to call if their supply chains were attacked

SAN JOSE, Calif.--(BUSINESS WIRE)--DEVOPS WORLD 2021 – A new global survey of C-level executives released today by CloudBees, the enterprise software delivery company, reveals high confidence levels in software supply chain security but a limited understanding of the essential components that make a software supply chain secure. The survey also reveals that among nearly all companies, supply chain security is a higher priority than just two years ago.

According to the CloudBees Global C-Suite Security Survey, executives overwhelmingly claim their software supply chains are secure (95%) or very secure (55%), and 93% say they are prepared to deal with an issue such as ransomware or a cyberattack on their supply chain. However, when asked additional questions about the security of their supply chains, the responses uncover vulnerabilities. More than two in five (45%) executives admit that initiatives to secure their software supply chains are halfway complete or less, and 64% say they are not sure who they would turn to first if their supply chain was attacked.

“It’s critical that software supply chains operate in the most secure and compliant manner possible. These findings show that while leaders are confident on the surface, they are also aware of security and planning gaps that could expose companies to significant business disruption, regulator and customer concerns and negative brand impact,” said Prakash Sethuraman, chief information security officer, CloudBees. “For a software supply chain to be secure, it must be continuously verified throughout the entire lifecycle in real time – from commit all the way through to production. We’re encouraged to see that companies are focused on the development piece, but they need to look holistically end to end.”

The survey also reveals that many companies are not prepared to respond quickly when an attack or breach happens. Among executive respondents, 64% say it would take more than four days to fix the problem if they did experience an issue. For a Fortune 500 company, this could result in the loss of millions in revenue and create significant reputational harm. And, while 93% of executives say they routinely practice dealing with a supply chain production vulnerability, 58% say that if they experienced one they have no idea what their company would do.

As companies rely even more heavily on software to drive mission-critical business needs, trends show an increasing number of attacks pushing this issue to be top of mind in boardrooms. Almost all C-level executives (95%) say they think more about securing the supply chain now than they did just two years ago, and 92% said a security issue would impact their brand. The results of the survey of 500 C-suite leaders in the United States, United Kingdom, Germany and France reflect a growing concern over the security of the world’s delivery and distribution of software.

The survey also found:

  • Disruptions impact employees and innovation: More than four in five (83%) C-suite executives say having security issues causes their developers to drop everything to review code, which in turn causes other business disruptions. By dealing with security issues, 82% of executives say they are losing time employees could be spending on innovation.
  • Responses vary by size and locale: Smaller companies are more confident in their ability to deal with supply chain issues than larger companies. Between countries, C-suites in the U.S. are most confident about the security of their software supply chains and those from France are the least confident.
  • Technical issues are on the agenda: Almost all executives say container images are checked for high or critical vulnerabilities (95%) and their automation access keys are set to expire automatically (95%), while 92% say their company only accepts commits signed with a developer GPG key. Nine in ten C-suite executives say dependencies to trusted registries are limited at their organization (90%) and that administrative access to CI/CD tools is restricted (89%).

Additional Resources

About CloudBees

CloudBees, the enterprise software delivery company, provides the industry’s leading DevOps technology platform. CloudBees enables developers to focus on what they do best – build great software – while providing peace of mind to management with powerful risk mitigation, compliance and governance tools. Used by many of the Fortune 100, CloudBees is helping thousands of companies harness the power of continuous everything, setting them on the fastest path from a great idea, to great software, to amazing customer experiences, to being a business that changes lives.

Backed by Matrix Partners, Lightspeed Venture Partners, Verizon Ventures, Delta-v Capital, Golub Capital and Unusual Ventures, CloudBees was founded in 2010 by former JBoss CTO Sacha Labourey and an elite team of continuous integration, continuous delivery and DevOps professionals. Follow CloudBees on Twitter, LinkedIn and Facebook.

Contacts

Media
Sydney Mueller
PAN Communications
CloudBees@pancomm.com
+1.407.734.7327

CloudBees


Release Versions

Contacts

Media
Sydney Mueller
PAN Communications
CloudBees@pancomm.com
+1.407.734.7327

More News From CloudBees

CloudBees Integration with Argo Rollouts Enables Advanced Deployment Strategies to Kubernetes

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today announced the integration of CloudBees’ continuous delivery and release orchestration solution, CloudBees CD/RO, with Argo Rollouts. The integration will enhance customers' ability to deliver software faster, with higher quality, and at scale in cloud-native environments. This latest integration for CloudBees furthers its ability to support customers to deploy applications with confidence...

CloudBees Welcomes ThoughtSpot Chief Development Officer Sumeet Arora to Board of Directors

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today announced the appointment of Sumeet Arora, chief development officer at ThoughtSpot, the leader in AI-powered analytics, to its board of directors. With a background in engineering, product strategy, and security, Arora brings more than 25 years of leadership experience to the board of directors. “We are pleased to have Sumeet join the board at CloudBees. He will bring valuable experience...

CloudBees Names Marc Gemassmer as Chief Revenue Officer

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today named a new chief revenue officer (CRO), Marc Gemassmer. Gemassmer will lead the company’s global go-to-market and customer success efforts, partner and channel group, as well as the professional services organization. “With Marc’s experience and proven track record of building high-growth sales organizations at a global scale, he is the experienced partner we need to drive the company fo...
Back to Newsroom