More than half of global organizations (54%) suffered a software supply chain attack over the past year, and most are unable to keep up with the growing risk landscape. This is according to ‘The State of Software Supply Chain Security Risk’ report, released by Synopsys, Inc. and the Ponemon Institute, which also found that 50% of organizations took more than a month to respond to an attack. One in five say that their organization is not effective in its ability to detect and respond to these attacks.
The data also shows that AI is becoming ubiquitous across the software development life cycle. The majority of security professionals (52%) say their development teams leverage AI tools to generate code, specifically, OpenAI Codex (50%), ChatGPT (45%) and GitHub Copilot (43%). While the use of AI creates efficiencies by automating decision-making, findings indicate that few protections are put in place. Only a third (32%) of organizations have processes to evaluate AI-generated code for license, security, and quality risks.
Survey respondents also cited a concerning lack of commitment from decision-makers when mitigating these issues. Only 39% say their organization’s leaders are highly committed to reducing the risk of malware in software supply chains. Even though 45% of security professionals say supply chain compromises have led to increased investment in software supply chain security, only 38% say resources dedicated to securing the supply chain are sufficient or very sufficient.
Methodology
The survey collected responses from 1,278 IT and IT security practitioners who are in organizations that are committed to achieving a secure software supply chain and have some level of responsibility for their organizations’ software supply chain security strategy. The regions and countries in this research are North America (613 respondents), EMEA (362 respondents), and Japan (303 respondents).






