VOOZH about

URL: https://thenewstack.io/software-security-imperative-forging-a-unified-standard-of-care/

⇱ Software Security Imperative: Forging a Unified Standard of Care - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-07-15 07:00:27
Software Security Imperative: Forging a Unified Standard of Care
sponsor-gitlab,sponsored-post-contributed,
Open Source / Operations / Security

Software Security Imperative: Forging a Unified Standard of Care

We must dispel the myth that security, speed and innovation are competing priorities. A balanced, integrated approach proves they are not.
Jul 15th, 2025 7:00am by Bob Stevens
👁 Featued image for: Software Security Imperative: Forging a Unified Standard of Care
Image from Omelchenko on Shutterstock.
GitLab sponsored this post.

The relentless pace of software development is on a collision course with an ever-escalating wave of sophisticated cyberthreats. The numbers are staggering; data breaches now cost an average of $9.3 million per incident in the United States. And, for the second consecutive year, supply chain compromise tops the list of cybersecurity threats, with vulnerabilities serving as attack vectors increasing by 180% year-over-year.

The technology sector must evolve from “making do” with fragmented security practices to upholding a unified standard of care that protects both innovation and end users.

A troubling disconnect pervades our digital landscape: Open source software, the backbone of modern innovation, often lacks consistent, comprehensive security oversight across the industry. This gap between our reliance on software and our accountability for its security demands an urgent, systemic overhaul in the way we approach software liability and cybersecurity standards.

Security leaders across the technology industry must collaborate to establish and enforce a unified cybersecurity standard of care, embracing principles such as Secure by Design This isn’t just about new mandates; it’s about refining existing practices, such as software bill of materials (SBOM) requirements for open source software, to foster an industrywide commitment to digital safety.

Establishing Baseline Security Requirements

Every stakeholder in the technology ecosystem, from tech vendors and their customers to partners and the broader industry, shares an implicit understanding of the need to uphold reasonable cybersecurity standards. This responsibility extends to creating and maintaining a cybersecurity standard of care that establishes baseline security requirements across the tech industry.

Establishing these standards represents more than regulatory compliance; it’s an investment in the long-term viability of the technology industry. With software now deeply embedded in critical infrastructure, healthcare, finance and national security, the consequences of inadequate security extend far beyond any single organization.

The development of these standards must be a collaborative endeavor involving input from security experts, legal professionals, regulatory bodies and industry practitioners. Only through this collective effort can we create standards that are both technically robust and universally applicable across diverse organizational contexts.

Navigating Innovation and Liability to Protect Open Source

The debate surrounding liability in the open source ecosystem requires careful consideration. Imposing direct liability on individual open source maintainers could stifle the very innovation that drives the industry forward. It risks dismantling the vast ecosystem that countless developers rely upon.

Instead, the primary responsibility for the overall security of software products should rest with the technology companies that commercialize them. While open source software is a foundational component for technological advancement, it inherently requires rigorous additional security practices. Organizations integrating these components into their projects must exercise thorough due diligence and implement comprehensive security scanning.

By establishing and enforcing industry-wide security standards through legal and regulatory measures, we can work toward creating a safer digital environment for all without undermining the collaborative essence of open source development.

SBOMs: A Critical Business Necessity

GitLab research found that 67% of developers reported that a quarter or more of the code they work on is derived from open source libraries, yet only 21% of organizations are currently using SBOMs to document the components that comprise their software.

The software bill of materials (SBOM) is rapidly transitioning from a nascent concept to an undeniable business necessity. As regulatory pressures intensify, driven by a growing awareness of software supply chain risks, a robust SBOM strategy is becoming critical for organizational survival in the tech landscape. But the value of SBOMs extends far beyond a single software development project.

While often considered for open source software, an SBOM provides visibility across the entire software ecosystem. It illuminates components from third-party commercial software, helps manage data across merged projects and validates code from external contributors or subcontractors — any code integrated into a larger system.

By proactively generating and meticulously maintaining SBOMs, organizations don’t just secure their own software supply chains, they contribute to fortifying the resilience of the entire technology ecosystem.

Building a Secure Digital Future

The path to a secure digital future requires commitment from all stakeholders. Technology companies must adopt comprehensive security practices, regulators must craft thoughtful policies that encourage innovation while holding organizations accountable and the broader ecosystem must support the collaborative development of practical and effective standards.

Crucially, we must dispel the myth that security, speed and innovation are competing priorities. A balanced, integrated approach proves they are not. Instead, robust security measures can coexist with, and even enhance, rapid development cycles, cultivating a more resilient and inherently trustworthy technology ecosystem.

By taking collective action now to establish and enforce a cybersecurity standard of care, the technology industry can build a foundation of trust that supports continued innovation while protecting the digital infrastructure on which society increasingly depends. The future of software liability is about embracing shared responsibility for a more secure digital world.

GitLab is the most comprehensive, intelligent DevSecOps platform for software innovation. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation.
Learn More
The latest from GitLab
TRENDING STORIES
Bob Stevens is vice president for the Americas and public sector at GitLab. With over 25 years of experience in the industry, Bob Stevens leads the public sector team by helping agencies fundamentally change the way their development, security and...
Read more from Bob Stevens
GitLab sponsored this post.
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.