Benchmarks the 30% prevalence and 267-day containment time for supply chain breaches while documenting the 1,300% growth in open-source malware threats.
Supply chain breaches doubled in 2025 to account for 30% of all data breaches, while the average global cost of a breach hit $4.44 million ($10.22 million in the U.S.). Supply chain incidents are uniquely damaging, taking an average of 267 days to identify and contain—a full week longer than malicious insider attacks—allowing for prolonged data exfiltration. Open-source malware has exploded, with malicious threats in repositories growing by 1,300% since 2020 and over 704,000 malicious packages logged since 2019. High-profile cases like SolarWinds and 3CX demonstrate that attackers are increasingly weaponizing trusted build systems and digital signatures to bypass Strong perimeter defenses, pushing the projected global annual cost of supply chain attacks to $60 billion in 2025.
The report documents a 1,300% growth in malicious threats in open source repositories, with over 704,000 packages logged since 2019.
inclusion of intentionally malicious code that exfiltrates data or provides unauthorized remote access
the explosive growth in malicious package volume validates that active malware detection is a baseline requirement for software supply chain security.
Supply chain breaches take an average of 267 days to identify and contain, the longest dwell time of any initial attack vector.
prolonged exposure and escalating data loss due to a failure to rapidly detect and respond to third-party compromises
measuring the delta between vulnerability disclosure and containment is the only way to mitigate the $4.44M average cost of these long-dwell-time breaches.
Supply chain cases cost more + last longer... taking an average of 267 days to identify and contain... breaches from the supply chain are uniquely damaging.
Risk Guard reports technical scores but does not estimate the 'Containment Time Risk' (dwell time) associated with a specific complex dependency.
Risk Guard would be better if it provided an 'Estimated Containment Difficulty' score to help security teams prioritize vulnerabilities that are historically hard to detect (high dwell time).