Skip to main content

Posts

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem. A model found 1,596 unpatched vulnerabilities in open source projects last month. The industry’s answer was more infrastructure for finding problems. That was never the part that was broken. Anthropic, Google, OpenAI, Microsoft, and more than a dozen other organizations just did something companies rarely do voluntarily. They pooled money into a shared body, called Akrites and hosted by the Linux Foundation, because none of them could keep pace with open source vulnerability discovery and remediation on their own. Organizations build shared infrastructure at this speed for one reason. A risk got too expensive for any single balance sheet to absorb quietly. That is what a captive insurance pool is. A group of companies decides a risk is real and common enough that carrying it alone costs more than carrying it together. Nobody calls that admission a taskforce. They call it underwriting, and they usual...
Recent posts

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name.

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name. The US federal safety net that followed Log4j has thinned in the same window the EU Cyber Resilience Act wrote obligations for commercial users of open source software into law, with reporting requirements beginning September 2026. The accountability for what enters your products is moving toward the organizations that consume it, on someone else's timeline. Two things happened to open source software security in the same window, and together they change who is on the hook. The US federal effort that grew after the 2021 Log4j crisis has largely lapsed, with key personnel gone and the initiatives quiet. At the same time, the EU Cyber Resilience Act turned obligations for commercial users of open source software into law, with vulnerability and incident reporting requirements applying from September 2026. One backstop thinned. The other became a requirement with a date attached to it. If the plan was to wai...

The SBOM Just Became a Liability With a Date on It

The SBOM Just Became a Liability With a Date on It When a best practice becomes a product requirement, it stops being a security artifact and starts being a financial one. The question now is whether the document you are obligated to produce is true. The EU Cyber Resilience Act is moving the software bill of materials from a best practice to a product security requirement, with the law’s full application arriving in December 2027 . If your company ships software into the EU, the character of one of your obligations just changed. The software bill of materials you used to produce because it was responsible is becoming one you are legally required to produce because a regulator says so. That is not a procedural change. It moves the bill of materials off the security team’s task list and onto the company’s books, and most organizations have not adjusted to what that means. A best practice and a requirement are not the same liability Every CFO understands that an unmanaged liability is a ...

The EU CRA Doesn't Change What Good Open Source Governance Looks Like. It Just Makes the Accountability Visible.

The EU CRA Doesn't Change What Good Open Source Governance Looks Like. It Just Makes the Accountability Visible. By Jacqueline Winter, CISO & CFO, ActiveState The Linux Foundation's 2026 CRA Awareness and Readiness Report documents where the industry stands. CFOs and CISOs who have already built a defensible governance posture are not reading it as a warning. They are reading it as context. Due diligence is not a concept invented for cybersecurity regulation. It has governed every material decision in finance, M&A, and vendor risk management for decades. The question is not whether open source software risk requires due diligence. The question is why most organizations accepted a lower standard for it than they would for any other contractual commitment. The EU Cyber Resilience Act (EU CRA) provides the answer: because no one required otherwise. That changes in December 2027. The Linux Foundation's 2026 CRA Awareness and Readiness Report surveys 843 respondents on...

Your Policy Was Complete. Then Your Company Adopted AI.

Your Policy Was Complete. Then Your Company Adopted AI. By Jacqueline Winter, CISO & CFO, ActiveState Most organizations have a dependency governance policy. Somewhere inside it is an exception nobody signed off on. That exception is now material. At some point in the last few years, most security organizations made a governance decision about open source dependencies. They documented approved packages. They built a review process. They required SBOMs for production systems. The decision was real, the documentation was produced, and the policy looked complete. It is not complete. There is an exception built into nearly every one of these policies that nobody explicitly approved, because the policy was written before the exception existed. The exception is AI-suggested code. How the Gap Was Created Without Anyone Deciding When developers adopted AI coding assistants, the governance question was not raised at the executive level. It was not raised at the security team level. It was a...

Your Scanner Is Not a Governance Decision

Your Scanner Is Not a Governance Decision By Jacqueline Winter, Chief Financial and Operations Officer, ActiveState IBM just committed $5B to open source security. A cluster of software supply chain campaigns has stolen cloud credentials, SSH keys, and developer secrets across three registries. You have a scanner running. Here is the problem: none of those three things answer the question your organization will be asked when something goes wrong. Who decided what open source software was allowed in your environment? When did they decide it? Where is the record? Most organizations cannot answer that question. Not because they lack tools. Because they have never treated it as a question that required a decision. A scanner tells you what entered your environment after it entered. An SBOM documents what accumulated. A patch workflow closes the gap after a vulnerable component is already in production. None of those is a governance decision. None of them produces the documentation that a b...

Open Source Is Free. Until Someone Comes to Collect.

  Open Source Is Free. Until Someone Comes to Collect. By Jacqueline Winter, CFO & CISO, ActiveState Finance has a long history of discovering that the liabilities nobody tracked were the ones nobody paid for. Open source software is the current version of that story. Free is not the same as without obligation. Every finance leader knows this. The land that cost nothing to use accrued environmental remediation costs over decades. The infrastructure that was already paid for accumulated deferred maintenance until the deferred became immediate. The financial instruments that required no upfront payment carried contingent liabilities that materialized at the worst possible moment. The pattern is consistent across domains, and the mechanism is always the same: when something costs nothing to acquire, it goes through no acquisition review. No due diligence process triggers. No risk register entry is created. The obligation that attaches to the consumption never gets tracked, because...