Eric Gallagher | SecuringTheBackbone.com's Avatar

Eric Gallagher | SecuringTheBackbone.com

@ericgallagher.bsky.social

πŸ’ͺ Author of "Securing the Backbone" newsletter | Challenging the status quo in software supply chain security | πŸƒTrying to make running a habit | 🎾Tennis and ♠️poker nerd | WV

24 Followers  |  60 Following  |  44 Posts  |  Joined: 24.02.2025  |  1.8202

Latest posts by ericgallagher.bsky.social on Bluesky

Preview
EXECUTIVE BRIEF | Why CVE Backlogs Shrink While Costs Keep Rising EXECUTIVE BRIEF | Why CVE Backlogs Shrink While Costs Keep Rising How apparent security progress can mask growing operational spend Prepared for Executive Leadership (CEO / CFO / CIO / CTO) Prepared b...

Full executive brief:
securingthebackbone.com/blog/stb-exe...

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The organization didn’t eliminate the work.
It made the work continuous.

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That’s not failure.
That’s a shift from deferred cost to recurring cost.

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

If teams close issues faster but new ones keep flowing in at the same rate, the system looks cleaner while labor demand stays flat β€” or rises.

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Backlog metrics measure inventory.
Cost reflects throughput.
You can reduce the pile…
while the conveyor belt keeps running just as fast.

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Your vulnerability backlog is shrinking.
Your remediation costs aren’t.
Both can be true at the same time.

02.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Issue #42: Why "Verify Everything" Is Not an Operating Model Date: January 12, 2026 Last week, I argued that trust is dead, and that enforcement is what replaces it. Enforcement in the form of curated catalogs, golden repositories, well-lit paths, whatever you ...

securingthebackbone.com/blog/securin...

12.01.2026 15:14 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
The Hidden Labor Cost of β€œJust Patch It” SECURING THE BACKBONE | Executive Brief Title: The Hidden Labor Cost of β€œJust Patch It” Prepared For: Executive Leadership (CEO / CIO / CISO / CTO) Prepared By: Eric Gallagher Date: December 29, 2025 ...

securingthebackbone.com/blog/stb-exe...

08.01.2026 19:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
2025 State of Vulnerability Management and Remediation Report Download the State of Vulnerability Management & Remediation report for insights on DevSecOps challenges and strategies to overcome them.

πŸ‘‰ Get the full report from ActiveState to see the complete findings and benchmarks.
www.activestate.com/resources/20...

06.01.2026 14:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If container security and compliance are part of your 2026 priorities, the full 2026 State of Vulnerability Management & Remediation Report: Container Security Edition breaks down exactly where organizations are falling behind, and what’s replacing broken approaches.

06.01.2026 14:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

The real failure point is remediation:
❌ Outdated base images
❌ Inherited CVEs
❌ Manual fixes that can’t keep up with ephemeral containers

The report shows that container adoption has outpaced security maturity, turning audits into a recurring risk event instead of a checkpoint.

06.01.2026 14:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

🚨 78% of organizations have likely failed a compliance audit due to CVEs in container images.

Not because teams aren’t scanning.
Not because they don’t care about security.
But because finding vulnerabilities is no longer the hard part.

06.01.2026 14:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

When compromise propagates inside the ecosystem itself, there is no clear breach moment and often nothing to β€œpatch.”

This shift is explored further in a recent STB Executive Brief written for executive leadership. Reach out if you want a copy.

05.01.2026 14:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Some of the most disruptive software supply-chain attacks no longer exploit vulnerabilities.

They exploit trust, automation, and legitimate access β€” spreading through authorized workflows rather than breaking in.

05.01.2026 14:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Issue #41: If Trust Is Gone, What Replaces It? Date: January 4, 2026 We've spent years talking about Zero Trust. Never trust, always verify. It's on the slides. It's in the frameworks. It's embedded in every RFP you've ever read. But here's the un...

securingthebackbone.com/blog/securin...

04.01.2026 17:33 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I don’t know you, just found your feed, but don’t stop. Decline or not, you’re running, and that’s a win. β€œThe best run is the run you CAN do now”

01.01.2026 14:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image 31.12.2025 23:14 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Here’s a little glimpse into the future. Go @sanfrancisco49ers.bsky.social !

31.12.2025 15:12 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Solutions like @ActiveState focus on preventing untrusted code from entering the pipeline in the first place, not just reacting after the fact.

Because when software can infect software, β€œjust patch it” stops being a strategy.

It becomes a liability.

31.12.2025 14:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The real fix is control:
βœ”οΈ controlling which open-source packages enter the organization
βœ”οΈ controlling how builds are composed
βœ”οΈ controlling who can publish, pull, and promote artifacts

This is where curated catalogs, immutable builds, and hardened base images matter.

31.12.2025 14:11 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This new class of supply-chain attack spreads inside trusted developer workflows:
β€’ no zero-days
β€’ no obvious malware
β€’ no CVEs to patch

Just automation + trust + public dependencies.

That’s why detection alone won’t stop it.

31.12.2025 14:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Shai Hulud isn’t scary because it’s sophisticated.
It’s scary because it’s allowed.

31.12.2025 14:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

If you're in those boardroom conversations talking about CVE's, I expand on this further in this month's STB Executive Brief.

30.12.2025 01:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

As scanning improves, numbers rise, remediation effort compounds, and leadership confidence can move in the wrong direction.

That gap rarely makes it into board conversations.

30.12.2025 01:24 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

CVE counts are often treated as a proxy for security risk.

In reality, they measure visibility, not exposure β€” and say little about the labor required to manage that risk over time.

30.12.2025 01:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Securing the Backbone β€” 2025 Finale - The Year That Trust Broke A Year-End Reality Check Every year in cybersecurity gets labeled β€œa turning point.” Most aren’t. 2025 was different. Not because of one catastrophic breach. Not because of one new regulation. Not bec...

securingthebackbone.com/blog/securin...

29.12.2025 13:38 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Deepest Thoughts - Cyber Security Edition - August 8, 2025
YouTube video by Securing the Backbone Deepest Thoughts - Cyber Security Edition - August 8, 2025

youtube.com/shorts/3DTXM...

08.08.2025 13:17 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Securing the Backbone – Issue #24: AI Is In Your Supply Chain. And It’s Already Being Breached. πŸ—“ August 4, 2025 ✍️ Eric Gallagher πŸ”’ Securing Software Supply Chains | πŸŽ™ Host of Securing the Backbone | πŸ“˜ Author of The No-Nonsense Guide to Software Supply Chain Security We’re officially in the era...

www.linkedin.com/pulse/securi...

04.08.2025 13:56 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

🚨 Python devs targeted in phishing scam spoofing PyPI!

Emails urge you to β€œverify” your account via pypj[.]orgβ€”a fake site stealing credentials.

βœ… Don’t click links
βœ… Use MFA
βœ… Go directly to pypi.org

Stay sharp.

01.08.2025 12:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail
31.07.2025 14:50 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@ericgallagher is following 20 prominent accounts