A Cloudsmith survey of 400 platform and security engineers in the United States and United Kingdom shows a steep decline in confidence in the tools used to manage software artifacts, with 73 % of respondents only moderately confident (58 %) or not confident (15 %) that their current solutions can stop supply‑chain attacks. Practitioners who build, deploy, or secure AI‑enabled applications, cloud platforms, or DevOps pipelines need to treat this as a warning sign that manual processes dominate and automation, provenance, and SBOM enforcement are still immature.
What Changed in Practitioner Confidence
The survey highlights three concrete shifts:
- Only 37 % of engineers can automatically identify, block, and trace an intrusion within minutes; the majority still rely on manual quarantine steps after detecting a breach.
- While 95 % generate a software bill of materials (SBOM), just 25 % have integrated automated SBOM verification into security gatekeeping, leaving 75 % to use the data only for ad‑hoc compliance.
- Confidence in passing an unexpected audit is low—only 27 % feel very confident—while 61 % are at least moderately sure that AI coding tools are not adding new vulnerabilities, yet only 32 % scan those AI models for specialized threats.
These numbers indicate that existing artifact‑management platforms are not delivering the end‑to‑end automation many teams expect, and that responsibility for securing binaries remains unclear.
Implications for Architecture and Operations
From an architectural perspective, the findings suggest several practical considerations:
- Automation gaps: Teams should evaluate whether their CI/CD pipelines can automatically enforce quarantine, block malicious artifacts, and record provenance without human intervention.
- SBOM integration: Generating SBOMs is insufficient; embedding verification steps—such as checksum validation or provenance checks—into build and release gates can move the practice from ad‑hoc to systematic.
- Binary‑centric security: The survey notes a shift toward protecting binaries after deployment, implying that runtime monitoring and attestation data (currently used by 50 % of respondents) may need to be expanded into continuous verification loops.
- AI model scrutiny: Although 61 % feel AI coding tools are not a major risk, only a minority scan those models for specialized threats, indicating a potential blind spot that could be addressed with dedicated model‑integrity checks.
- Responsibility allocation: With 39 % placing trust decisions for open‑source dependencies on a centralized security or governance team and 37 % opting for shared responsibility with developers, organizations should formalize ownership to avoid gaps.
Areas to Evaluate Next
Practitioners should focus on the following evaluation points:
- Identify automation opportunities in artifact scanning, quarantine, and remediation to reduce reliance on manual effort.
- Assess current SBOM workflows and prioritize the integration of automated verification into CI/CD gate checks.
- Review the use of provenance and attestation data, expanding its role from validation to continuous compliance monitoring.
- Determine whether AI‑generated code is being scanned for both basic integrity (e.g., checksum) and specialized threats, and consider adding model‑specific scanning where missing.
- Clarify governance models for dependency trust decisions, ensuring that either a centralized team or a shared responsibility framework is documented and enforced.
Related CloudNinjas coverage: security.
What This Means For Practitioners
In short, the survey signals that many organizations are still operating with manual, fragmented defenses against supply‑chain risk. Engineers should prioritize building automated detection and quarantine capabilities, embed SBOM verification into release pipelines, and establish clear ownership for binary security and AI model integrity. Doing so will close the confidence gap and prepare teams for the faster, AI‑driven attack vectors highlighted by the respondents.


