Breaking Trust – Confronting Insecurity in the Software Supply Chain

Tuesday, February 02, 2021 - 10:20 am10:50 am

Trey Herr, Ph.D., Atlantic Council


Society has a software problem. Since Ada Lovelace deployed the first computer program on an early mechanical device in the 1840s, software has spread to every corner of human experience. With that software come security flaws and a long tail of updates from vendors and developers. Unlike a physical system that is little modified once it has left the factory, software is subject to continual revision through updates and patches. Software supply chain security remains an underappreciated domain of national security policymaking. This talk explores 115 software supply chain attacks and vulnerability disclosures from the past decade to sum up where we are and how far we still have to go. Software supply chain attacks are popular, they are impactful, and are used to great effect by states, especially China and Russia. The implications for the technology industry and cybersecurity policymaking community are a crisis in waiting. The solution is not panic nor is it a moonshot, but rather a renewed focus on software supply chain security practices, new investment from public and private sectors, and revisions to public policy that emphasize raising the lowest common denominator of security behavior while countering the most impactful attacks.

Dr. Trey Herr is the Director of the Cyber Statecraft Initiative at the Atlantic Council. His team works on the role of the technology industry in geopolitics, cyber conflict, the security of the internet, and cyber safety. Previously, he was a Senior Security Strategist with Microsoft handling cloud computing and supply chain security policy as well as a fellow with the Belfer Cybersecurity Project at Harvard Kennedy School and a non-resident fellow with the Hoover Institution. He holds a Ph.D. in Political Science and BS in Musical Theatre and Political Science.

