State-sponsored Russian hackers broke into the networks of US federal agencies and numerous companies in December. The SolarWinds attack has brought widespread attention to the security of the software supply chain. Security leaders and experts say CISOs need to be able to answer the most important questions CISOs can ask following a software suppy chain breach like this. The question is: Are we at risk even if we’re not using the backdoored software, or any of our partners, contractors, or suppliers?”]

