S3C2 SICP Summit 2025-06: Vulnerability Response Summit

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Rotthaler, Anna Lena, Oberthür, Simon, Somorovsky, Juraj, Thommes, Kirsten, Trang, Simon, Acar, Yasemin, Cukier, Michel, Enck, William, Kapravelos, Alexandros, Kästner, Christian, Wermke, Dominik, Williams, Laurie
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908687352725504
author Rotthaler, Anna Lena
Oberthür, Simon
Somorovsky, Juraj
Thommes, Kirsten
Trang, Simon
Acar, Yasemin
Cukier, Michel
Enck, William
Kapravelos, Alexandros
Kästner, Christian
Wermke, Dominik
Williams, Laurie
author_facet Rotthaler, Anna Lena
Oberthür, Simon
Somorovsky, Juraj
Thommes, Kirsten
Trang, Simon
Acar, Yasemin
Cukier, Michel
Enck, William
Kapravelos, Alexandros
Kästner, Christian
Wermke, Dominik
Williams, Laurie
contents Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing significant damage to businesses and organizations. The US and EU governments and industry are equally interested in enhancing software security, including supply chain and vulnerability response. On June 26, 2025, researchers from the NSF-supported Secure Software Supply Chain Center (S3C2) and the Software Innovation Campus Paderborn (SICP) conducted a Vulnerability Response Summit with a diverse set of 9 practitioners from 9 companies. The goal of the Summit is to enable sharing between industry practitioners having practical experiences and challenges with software supply chain security, including vulnerability response, and helping to form new collaborations. We conducted five panel discussions based on open-ended questions regarding experiences with vulnerability reports, tools used for vulnerability discovery and management, organizational structures to report vulnerability response and management, preparedness and implementations for Cyber Resilience Act1 (CRA) and NIS22, and bug bounties. The open discussions enabled mutual sharing and shed light on common challenges that industry practitioners with practical experience face when securing their software supply chain, including vulnerability response. In this paper, we provide a summary of the Summit. Full panel questions can be found in the appendix.
format Preprint
id arxiv_https___arxiv_org_abs_2512_02600
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle S3C2 SICP Summit 2025-06: Vulnerability Response Summit
Rotthaler, Anna Lena
Oberthür, Simon
Somorovsky, Juraj
Thommes, Kirsten
Trang, Simon
Acar, Yasemin
Cukier, Michel
Enck, William
Kapravelos, Alexandros
Kästner, Christian
Wermke, Dominik
Williams, Laurie
Cryptography and Security
Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing significant damage to businesses and organizations. The US and EU governments and industry are equally interested in enhancing software security, including supply chain and vulnerability response. On June 26, 2025, researchers from the NSF-supported Secure Software Supply Chain Center (S3C2) and the Software Innovation Campus Paderborn (SICP) conducted a Vulnerability Response Summit with a diverse set of 9 practitioners from 9 companies. The goal of the Summit is to enable sharing between industry practitioners having practical experiences and challenges with software supply chain security, including vulnerability response, and helping to form new collaborations. We conducted five panel discussions based on open-ended questions regarding experiences with vulnerability reports, tools used for vulnerability discovery and management, organizational structures to report vulnerability response and management, preparedness and implementations for Cyber Resilience Act1 (CRA) and NIS22, and bug bounties. The open discussions enabled mutual sharing and shed light on common challenges that industry practitioners with practical experience face when securing their software supply chain, including vulnerability response. In this paper, we provide a summary of the Summit. Full panel questions can be found in the appendix.
title S3C2 SICP Summit 2025-06: Vulnerability Response Summit
topic Cryptography and Security
url https://arxiv.org/abs/2512.02600