Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A Cloudsmith survey of 400 platform and security engineers in the United States and United Kingdom found that 73% were only moderately confident or not confident in their existing tools’ ability to prevent software supply chain attacks. That figure combines respondents who were moderately confident (58%) with those who were not confident (15%); it does not mean that 73% had no confidence at all. The results, reported by DevOps.com in September 2026, also point to gaps between generating security data and using it to block or contain risk.

What the survey measured—and what it does not establish

Cloudsmith surveyed 400 platform and security engineers in the U.S. and U.K. The figures below describe those respondents, not all organizations or security teams. Cloudsmith sponsored the survey and sells artifact management software, so its findings offer a view of reported practices rather than independent product benchmarking. DevOps.com’s coverage presents the survey’s confidence, response, SBOM, audit, and AI-related findings.

The official Cloudsmith report page uses a different confidence measure: 73% said they trusted their tools to stop an install-time attack before an advisory existed. That is not the same statistic as DevOps.com’s 73% who were moderately confident or not confident in their existing tools’ ability to prevent attacks. The two measures should not be combined.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confidence is not the same as response readiness

Even when teams can detect a problem, the next steps determine whether a suspicious dependency or artifact is contained quickly. In the DevOps.com report of the survey, 48% said intrusion detection still required manual effort to quarantine or resolve the issue. By contrast, 37% said they could automatically identify, block, and trace an intrusion within minutes. These are distinct reported response capabilities; the figures do not account for every respondent’s exact workflow.

For an organization assessing its own readiness, the practical distinction is whether controls can take an action and preserve a useful trail, not simply whether monitoring produces an alert. Useful questions include:

#1 Best Overall
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
  • Can a suspicious package be blocked or quarantined automatically, or must a person intervene?
  • Can the team identify which builds or deployed systems contain an affected artifact?
  • Does the process retain evidence of what was ingested, checked, blocked, or approved?

SBOM generation is common; automated enforcement is not

Ninety-five percent of respondents said they generated software bills of materials (SBOMs), but only 25% said they integrated and automated SBOM verification as part of security gatekeeping. The remaining reported practice highlights why producing an inventory is not, by itself, a control: 75% used SBOM data for ad hoc compliance only.

An SBOM can help establish what components are present. To make it part of prevention, teams also need a defined policy for checking that inventory and a workflow that can stop, quarantine, or escalate an artifact when it fails the policy. The survey figures distinguish those activities; they do not show that an SBOM alone prevents an attack.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

Audit readiness and changing compliance plans

Only 27% of respondents were very confident their organization could pass an unexpected audit. Separately, 45% were investigating a different compliance approach and 25% were evaluating a security framework. The report does not establish whether those two groups overlap, so their percentages should not be added to produce a total.

For teams preparing for an audit, a useful operational test is whether they can connect an artifact to its provenance, the checks applied to it, the policy decision, and any affected builds. The survey reports confidence levels, not audit outcomes, and it does not identify a single framework as the answer.

Rank #3
HORUSDY Tamper Proof Star Key Set (Folding) Security Torx Key Set Sizes Include T-6 to T-30
  • Tamper Resistant Star Key Set Crafted with premium chrome vanadium steel, and each star tool folds neatly into the handle for quick, easy access.
  • Details - The handle is engraved with size for quick identification with drilled tips to allow use.
  • Portable - Keys fold compact for easy storage, Drilled tips allow use on tamper resistant security screws.
  • Size:Full Size T-6, T-7, T-8, T-9, T-10, T-15 T-20, T-25, T-27 and T-30.
  • And with 10 total star sizes able to match nearly all standard tamper resistant security screws on the market.

AI coding tools add another assurance question

Sixty-one percent of respondents were at least moderately confident that AI coding tools were not adding vulnerabilities. Yet only 32% said they scanned AI models for specialized threats, while 41% checked basic integrity, such as checksums or provenance. These figures describe different levels of assurance and should not be treated as equivalent checks.

Teams evaluating AI-assisted development can separate the questions: whether the model or package is authentic and traceable, whether it has been screened for relevant threats, and whether generated code is reviewed and tested like other code. The survey does not establish that any one of these measures guarantees vulnerability-free output.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

Earlier controls: ingestion, provenance, and cooldowns

Half of respondents said they relied on provenance or attestation data to validate software builds. The official Cloudsmith report also says 38% scanned packages before ingestion and 24% automatically enforced cooldown policies. It reports that 73% trusted their tools to stop an install-time attack before an advisory existed—a specific measure of trust in this scenario, not the broader confidence result above.

These figures illustrate a useful way to evaluate a supply chain control: when it runs, what evidence it checks, and whether it can enforce a decision. A scan before ingestion can prevent an artifact from entering an internal repository; provenance checks can help establish where a build came from; a cooldown can delay use of a newly released dependency while early risk signals emerge. The report’s recommendations for these earlier controls come from the survey sponsor, not from an independent comparison of security products.

Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Cloudsmith’s supply chain security documentation describes platform capabilities including package signing, SBOM generation, artifact risk scanning, and policy-driven blocking, quarantine, or tagging. Those are vendor-described features, not independently established outcomes or proof that a particular configuration will prevent an attack.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to use these findings

The survey is most useful as a prompt for checking the difference between having security data and operationalizing it. A team can compare its controls across the stages where risk can be acted on:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Control question What to verify
Before ingestion Are packages scanned or checked before entering an internal repository, and can a failed check block ingestion?
At build time Are provenance or attestation signals checked, and can teams trace an artifact to its source and build?
At policy gates Are SBOMs verified against enforceable rules, rather than generated only for later reference or compliance?
During response Can teams quarantine or block affected artifacts automatically and trace where they are used?
For audit evidence Can the organization show the artifact, checks, decisions, and response actions in a consistent record?

The Cloudsmith survey does not rank vendors or prove that a specific tool closes these gaps. Its clearest signal is the difference between reported activity—such as generating an SBOM—and a control that verifies information and can enforce a decision.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.