Talk: Software Supply Chain Risk Now Runs Client-Side

Software Supply Chain Risk Now Runs Client-Side: What OWASP’s Top 10 Shift Means for CISOs



< Back to Webinars


When the 2025 update from OWASP elevated Software Supply Chain Failures to a top-three risk — with the strongest consensus in the project’s history — it signaled a structural shift in how applications are built, delivered, and exploited. Modern applications are no longer built. They are composed of open-source components, CI/CD pipelines, SaaS integrations, third-party scripts, marketing pixels, and increasingly AI-driven services. Many of these components execute not on your servers, but directly in your users’ browsers — where sensitive data is created and immediately exposed. 

In this session, Gareth Bowker, Head of Security Research at Jscrambler, examines what OWASP’s shift means for CISOs and application security leaders. Drawing on newly released third-party script research, Gareth reveals not only the security risks of client-side dependencies, but also the data governance implications — including how third-party scripts gain real-time access to user inputs, behavioral signals, and sensitive session data. While organizations have invested heavily in SBOMs, dependency scanning, and build pipeline integrity, runtime client-side exposure remains largely unmonitored.

As PCI DSS introduced mandatory controls for payment pages, OWASP has now reinforced that supply chain risk extends across the entire application surface. Attendees will leave with a clear framework for extending supply chain security beyond the edge — to the browser layer where data is born — and for turning OWASP’s signal into operational action.



Watch now!

Speakers

Gareth Bowker

Jscrambler, Head of Security Research

Related Resources

Client-Side Protection: Specialists or Platforms?
On-Demand Webinar

Client-Side Protection: Specialists or Platforms?

Marriott Vacations Worldwide Secures the Browser with Jscrambler
Case Study

Marriott Vacations Worldwide Secures the Browser with Jscrambler

Client-Side Protection: Effectiveness or Consolidation
Blog

Client-Side Protection: Effectiveness or Consolidation

Client-Side Security Tools to Comply with PCI DSS v4
Blog

Client-Side Security Tools to Comply with PCI DSS v4

The Essential Guide to Data Privacy Compliance
Blog

The Essential Guide to Data Privacy Compliance

Client-Side Exposed: Exploring Third-Party Tracking Technologies
On-Demand Webinar

Client-Side Exposed: Exploring Third-Party Tracking Technologies

Navigating the Third-Party Code Minefield: Data Leakage Risks
Blog

Navigating the Third-Party Code Minefield: Data Leakage Risks

Managing Third-Party Tags in the Hospitality Industry
Blog

Managing Third-Party Tags in the Hospitality Industry