---
title: "CISO & CTO Guide to Supply Chain Security: Securing The Software Factory"
description: Learn about 15 critical risk areas to protect your entire software supply chain from threats. Download our CISO & CTO guide to secure your software factory.
image: https://org.boostsecurity.io/hubfs/CISO%20CTO%20Guide%20by%20Boost%20Security.png
---

# CISO & CTO Guide to Supply Chain Security: Securing The Software Factory

You’ve likely heard a lot about software supply chain security.   
We’ve simplified it while going deep into the real threats facing   
your software supply chain.

This guide, designed for CISOs and CTOs, is a crash course in understanding the categorical threats putting your software factory at risk. It intends to help you learn about the risks–both visible and hidden–to critical components of your supply chain, what you can do to protect your organization from these existing and emerging supply chain threats, and provides resources for extended learning.

![Defining the Software Supply Chain-2](https://org.boostsecurity.io/hubfs/Defining%20the%20Software%20Supply%20Chain-2.png "Defining the Software Supply Chain-2")

## Defining the Software Supply Chain

*The software supply chain is everyone and everything that is involved in the development, testing, and deployment of your software artifacts.*

*Note* that in this definition we excluded the entire consumer side of the supply chain. In the case of a SaaS service or API service, this would be the runtime environment. For brevity and focus we’re narrowing in on the software factory vs. the operational nature of running a software product.

# Pillars of Supply Chain Risk

##### There are a number of critical components of your supply chain and your supply chain security must address these interconnected areas.

![Developer Risks](https://org.boostsecurity.io/hs-fs/hubfs/Developer%20Risks.png?width=101&height=100&name=Developer%20Risks.png)

Developer Risks

Your developers are now your direct targets

- Developer Account Compromises
- Insider Threat
- IP Theft and Credential Theft

![First Party Code Risk](https://org.boostsecurity.io/hs-fs/hubfs/First%20Party%20Code%20Risk.png?width=100&height=100&name=First%20Party%20Code%20Risk.png)

First Party Code Risk

Your own code is a critical attack surface

- Writing Insecure Code, Designing Insecure Systems
- Inserting Malicious Code into a Project Intentionally
- IP Theft
- Credential Theft

![Third Party Code Risk](https://org.boostsecurity.io/hs-fs/hubfs/Third%20Party%20Code%20Risk.png?width=100&height=100&name=Third%20Party%20Code%20Risk.png)

Third Party Code Risk

Open source and third-party software can create security issues

- License Risk
- Known Vulnerabilities
- Unmaintained, End-of-Life or Poor Quality Software
- Malware in OSS Packages

![Development Infra Risk](https://org.boostsecurity.io/hs-fs/hubfs/Third%20Party%20Code%20Risk.png?width=100&height=100&name=Third%20Party%20Code%20Risk.png)

Development Infrastructure Risk

This maybe one of your biggest blindspots

- Compromising a misconfigured source control system
- Compromising the source control system through extensions
- Compromising the Build & Deployment Systems through extensions
- Compromising the Artifact Registry

[![How AI impacts your software supply chain-1](https://org.boostsecurity.io/hs-fs/hubfs/How%20AI%20impacts%20your%20software%20supply%20chain-1.png?width=600&height=716&name=How%20AI%20impacts%20your%20software%20supply%20chain-1.png "How AI impacts your software supply chain-1")](https://boostsecurity.io/appsec-testing?hsLang=io)

## How AI impacts your software supply chain

The use of coding assistants/copilots certainly increases the volume of code being produced, and, at least for now, produces less secure code. In fact, a recent Stanford University study found “participants who had access to [the] AI assistant were more likely to introduce security vulnerabilities for the majority of programming tasks, yet were also more likely to rate their insecure answers as secure compared to those in our control group.” 

When it comes to use of LLMs, they lack context about the overall application causing code snippets to incorporate bold assumptions and they often lack system threat model thinking in their design. Proprietary IP can also be placed into LLM’s, which raises questions about whether this IP can be served to other users, which [happened at Samsung in 2023](https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/). Taken together, higher volume of code + more security issues per line of code = more vulnerabilities overall.

[Download the Guide](https://org.boostsecurity.io/ciso-guide-to-supply-chain-security#Form) →

 

![AI Components 2-2](https://org.boostsecurity.io/hubfs/AI%20Components%202-2.png "AI Components 2-2")

## AI Components

If your application leverages AI technologies and services (be it Generative/LLM or Predictive/ML), then you will want to consider AI specific risks. There are many AI risk models out there, but commonly referenced ones would be the OWASP LLM Top 10 and OWASP ML Top 10. Risks vary from attackers inserting bad data into the model, to prompt injection, to supply chain attacks on these models, and much, much more.

# Real World Supply Chain Attack

![Codecov Attack-1](https://org.boostsecurity.io/hs-fs/hubfs/Codecov%20Attack-1.png?width=80&height=80&name=Codecov%20Attack-1.png)

Codecov Attack

Target: Build Tools

The Codecov supply chain attack from a few years ago. The Codecov bash uploader script was modified by attackers to exfiltrate CI environment variables which often contain secrets. This allowed attackers to steal secrets from Codecov customers.

<https://www.hubspot.com>

![Bybit Crypto Wallet Hack-1](https://org.boostsecurity.io/hs-fs/hubfs/Bybit%20Crypto%20Wallet%20Hack-1.png?width=80&height=80&name=Bybit%20Crypto%20Wallet%20Hack-1.png)

Bybit Crypto Wallet Hack

Developer Account Compromise

In February 2025, the Bybit crypto SAFE wallet hack resulted in a $1.4B loss, representing the biggest heist in history. This hack started with the compromise of a developer through a phishing or social engineering tactic. The hackers used the developer's compromised machine to inject malicious source code into the repository, conducted the attack, then removed the code.

<https://www.hubspot.com>

![XZ-Utils Near Miss-1](https://org.boostsecurity.io/hs-fs/hubfs/XZ-Utils%20Near%20Miss-1.png?width=80&height=80&name=XZ-Utils%20Near%20Miss-1.png)

XZ-Utils Near Miss

Trusted Contributor Attack

The near miss of xz-utils which could have been the biggest cyber breach in history had it gone unnoticed. Jia Tan, the "name" of the developer (that was never caught) - spent 2 years working positively on an important, and widely used project, before inserting malicious code into it.

<https://www.hubspot.com>

![Banner Graphic 3](https://org.boostsecurity.io/hs-fs/hubfs/Banner%20Graphic%203.png?width=244&height=223&name=Banner%20Graphic%203.png) 

✦

 

 

## Secure Your Supply Chain

The software supply chain is complex. This guide breaks it down into fifteen distinct risk areas to be aware of and how they can be compromised. Knowing what needs protecting is the first step in securing your software factory.   

[ Download the Guide → ](https://org.boostsecurity.io/ciso-guide-to-supply-chain-security#Form)