S3C2 SICP Summit 2025-06: Vulnerability Response Summit
Anna Lena Rotthaler, Simon Oberth\"ur, Juraj Somorovsky, Kirsten Thommes, Simon Trang, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian K\"astner, Dominik Wermke, Laurie Williams

TL;DR
This paper summarizes a summit where industry practitioners shared experiences and challenges in software supply chain security and vulnerability response, aiming to foster collaboration and improve practices.
Contribution
It provides a detailed account of industry challenges and collaborative discussions on vulnerability management in software supply chains, based on a multi-company summit.
Findings
Shared practical challenges in vulnerability response
Identified tools and organizational structures used in industry
Highlighted need for improved collaboration and standards
Abstract
Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing significant damage to businesses and organizations. The US and EU governments and industry are equally interested in enhancing software security, including supply chain and vulnerability response. On June 26, 2025, researchers from the NSF-supported Secure Software Supply Chain Center (S3C2) and the Software Innovation Campus Paderborn (SICP) conducted a Vulnerability Response Summit with a diverse set of 9 practitioners from 9 companies. The goal of the Summit is to enable sharing between industry practitioners having practical experiences and challenges with software supply chain security, including vulnerability response, and helping to form new collaborations. We conducted five panel discussions based on open-ended questions regarding experiences with vulnerability…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Techniques and Practices · Supply Chain Resilience and Risk Management
