The risks of an insufficiently secured software supply chain have been known to industry experts for decades, but it took a series of high-profile attacks like Solarwinds or Log4Shell to bring them to the attention of much wider audiences. Now everyone finally seems to realize how catastrophic the consequences of such an attack could be, but still, many organizations are struggling to understand the scope of the security measures that are needed to prevent them from happening.