Skip to main content

The CEO Shift: Why Abby Kearns at ActiveState Signals a Turning Point for Enterprise Risk

 


The CEO Shift: Why Abby Kearns at ActiveState Signals a Turning Point for Enterprise Risk

The Software Supply Chain Is Now a Boardroom Problem

Abby Kearns has spent her career at the intersection of open source software and enterprise infrastructure. At Cloud Foundry Foundation, she watched the world's largest organizations bet their digital futures on open source. At Puppet, she saw firsthand how automation was the only viable path to managing infrastructure at scale. Her appointment as CEO of ActiveState isn't a standard leadership transition. It's a signal that the industry is moving from experimental growth to mature governance, and that the software supply chain has finally become a boardroom problem.

The 96% Problem Nobody Is Talking About

Here's a number that should get every CISO's attention: roughly 96% of modern applications contain open source components. That means the vast majority of proprietary software is built on code the organization didn't write and, in many cases, has not fully verified. The industry has been treating open source as a developer convenience for decades. It is now the primary engine of global business, and that changes the risk calculus entirely.

The old model, where developers download pre-compiled binaries from public repositories and trust that everything inside is clean, is no longer defensible. Those binaries are often black boxes. You don't know what compiler was used, what's buried in the dependency tree, or whether the code has been tampered with. For a CISO trying to meet increasingly stringent compliance requirements, that's not a security posture. It's a liability.

AI Is Accelerating the Problem

Just when the open source supply chain was already complex enough, generative AI arrived and turned up the velocity dial. Developers are shipping code faster than ever. LLMs are suggesting, generating, and assembling code that pulls in open source packages at a rate that manual security review simply cannot keep pace with.

This is the new velocity gap: engineering teams are moving at the speed of AI, while security and compliance teams are still working from spreadsheets and manual audits. Every CVE they chase is time not spent on work that actually moves the business forward.

Kearns has seen this pattern before. In the early days of cloud, enterprises were adopting new infrastructure technologies faster than they could manage them safely. The companies that came out ahead weren't the ones that slowed down adoption. They were the ones that built the right systems to govern it without killing developer velocity. That's exactly the problem ActiveState has spent two decades solving, and it's a core reason this appointment makes sense.

Building from Source Changes Everything

The approach at the core of ActiveState is straightforward in concept, but hard to execute at scale: build open source runtimes from the original source code, in a secure and isolated environment, with a full chain of custody. Not pre-compiled binaries from a public repo. Not a best-effort scan after the fact. Built, verified, and traceable from the start.

For a CISO, the practical impact is significant. Organizations can dramatically reduce their vulnerability surface area, eliminate the dependency sprawl that makes audits a nightmare, and meet federal and global software transparency requirements with confidence rather than hope. And critically, they can do all of this without creating a bottleneck that slows engineering teams down.

Why This Matters Now

The conversation about software supply chain security has been building for years, but recent high-profile breaches have moved it from the CISO's agenda to the board's agenda. That shift is permanent. With AI accelerating the ingestion of open source packages across every team and every project, the window for getting ahead of this problem is narrowing.

What ActiveState offers is something the market genuinely needs right now: a way to let developers move fast without the organization flying blind on what's actually inside the software they're shipping. Kearns brings the right combination of open source depth, infrastructure credibility, and enterprise scale experience to lead that charge. The timing is deliberate, and the opportunity is significant.

Comments

Popular posts from this blog

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name.

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name. The US federal safety net that followed Log4j has thinned in the same window the EU Cyber Resilience Act wrote obligations for commercial users of open source software into law, with reporting requirements beginning September 2026. The accountability for what enters your products is moving toward the organizations that consume it, on someone else's timeline. Two things happened to open source software security in the same window, and together they change who is on the hook. The US federal effort that grew after the 2021 Log4j crisis has largely lapsed, with key personnel gone and the initiatives quiet. At the same time, the EU Cyber Resilience Act turned obligations for commercial users of open source software into law, with vulnerability and incident reporting requirements applying from September 2026. One backstop thinned. The other became a requirement with a date attached to it. If the plan was to wai...

The SBOM Just Became a Liability With a Date on It

The SBOM Just Became a Liability With a Date on It When a best practice becomes a product requirement, it stops being a security artifact and starts being a financial one. The question now is whether the document you are obligated to produce is true. The EU Cyber Resilience Act is moving the software bill of materials from a best practice to a product security requirement, with the law’s full application arriving in December 2027 . If your company ships software into the EU, the character of one of your obligations just changed. The software bill of materials you used to produce because it was responsible is becoming one you are legally required to produce because a regulator says so. That is not a procedural change. It moves the bill of materials off the security team’s task list and onto the company’s books, and most organizations have not adjusted to what that means. A best practice and a requirement are not the same liability Every CFO understands that an unmanaged liability is a ...

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem. A model found 1,596 unpatched vulnerabilities in open source projects last month. The industry’s answer was more infrastructure for finding problems. That was never the part that was broken. Anthropic, Google, OpenAI, Microsoft, and more than a dozen other organizations just did something companies rarely do voluntarily. They pooled money into a shared body, called Akrites and hosted by the Linux Foundation, because none of them could keep pace with open source vulnerability discovery and remediation on their own. Organizations build shared infrastructure at this speed for one reason. A risk got too expensive for any single balance sheet to absorb quietly. That is what a captive insurance pool is. A group of companies decides a risk is real and common enough that carrying it alone costs more than carrying it together. Nobody calls that admission a taskforce. They call it underwriting, and they usual...