Security & supply chain

Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent

Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent

Seventy-seven percent of surveyed organizations experienced a software supply chain incident in the twelve months before Omdia ran its 2026 survey, per a research report Docker sponsored and published August 4. For teams still hardening pipelines, that sets the base rate: assume an attempt will land in the next year, and staff for it.

The most common attack shape has not changed. Exploits against known vulnerabilities in third-party software were the top category at 38 percent. What has shifted is what respondents fear next. AI technology is now the top-ranked supply chain risk at 40 percent, edging past third-party and open-source code (39 percent) and software dependencies (38 percent). The consequences respondents reported: 46 percent saw unauthorized access to applications and data, 37 percent had SLAs impacted during remediation, and 35 percent had developer credentials, secrets or keys stolen. On code composition, 38 percent of organizations say more than half of their code already comes from third-party sources, and Omdia projects that share to hit 58 percent within twelve months.

The tool table rewards the sponsor's category

The effectiveness ranking has one clear winner. Fifty-one percent of respondents rated secure containers as "very effective" for securing third-party and open-source components, the only category, out of eleven, where a majority landed in the top rating. Docker's blog post foregrounds that finding and points readers to Docker Hardened Images and Docker Scout. That is worth reading with the sponsor list in view: the category the sponsor sells topped a ranking the sponsor commissioned. Not disqualifying, but not the number you cite in a boardroom without a second source.

The fix side, and the 45 percent

Ninety-eight percent of respondents called shifting security left a high priority for their program, and 32 percent named it their single top application-security priority. SBOM adoption is more mixed: 42 percent generate an SBOM for every application as mandatory practice, and 55 percent do it case by case. The most cited SBOM payoffs, per respondents, were quicker vulnerability mitigation (73 percent), better security controls (72 percent), and compliance (68 percent). Sixty-two percent of teams expect to spend heavily on supply-chain security in the coming budget cycle.

The number without a footnote is 45 percent. That is the share of respondents who do not rate their own supply chain security as solid today, and it is the constituency the report, and every vendor sponsoring one, is competing for.

Source: Docker Blog (docker.com)

Related
Security & supply chain

CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS

The 2026 Minimum Elements guidance from CISA replaces the 2021 NTIA baseline, adds required hash, license and generation-context fields to every SBOM, renames Supplier Name to Component Producer, and extends the floor to open-source software, AI systems and software-as-a-service. For platform teams the practical consequence is that SBOM work stops living inside the build step and starts spilling into vendor contracts and runtime re-validation.

August 2, 2026
Security & supply chain

GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams

Google's Threat Intelligence Group and Mandiant have released a joint guide on defending against software supply chain compromise, mapping four control categories onto the concrete pipeline levers most teams already own: short-lived tokens, ephemeral runners, package cooldowns and dependency verification.

July 30, 2026
Security & supply chain

OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

OpenAI has released the Codex Security CLI and SDK under Apache 2.0, wiring pre-commit and CI scanning into the merge path with configurable severity gates. The scanning backend and the agent that produces threat models and patches remain proprietary and available only to a limited-beta allowlist.

July 30, 2026

Turn this into your pipeline. Build it on Buddy.

Start free