Don't make it easy for them: The four software risks you need to cover
Want more insights like this?
Subscribe Here!
October means one thing in security circles. Cybersecurity Awareness Month is here, and this year the National Cybersecurity Alliance puts forward four practical habits for building security into the way you work every day.
-
Use long, unique passphrases, stored in a password manager.
-
Turn on multi-factor authentication everywhere.
-
Recognize and report phishing instead of deleting it.
-
Keep software updated so known holes close quickly.
In this post, we'll look at what those four habits do for you, and how they ultimately fall short of building software security measures that really "don't make it easy for them."
Don't make it easy for them
This year marks an important milestone in the United States, which celebrates the 250th anniversary of its founding. And so the month's secondary theme, set by the Cybersecurity and Infrastructure Security Agency, is "Securing the Next 250".
Two and a half centuries is a lofty goal for a security plan, but it touches on a really important point: your cybersecurity plan needs to be future-proof.
That's why the Alliance runs this year's theme under a blunt line: don't make it easy for them. The idea is that the harder you make it for cyber attackers to get in, the more resilient you'll be over the long term.
But cyber attacks aren't the only issue your software faces. You also run the risk of spontaneous software failure when a service you depend on goes under or discontinues support, non-compliance that can cost you your business or your next enterprise deal, and broken code that takes your systems down from the inside.
Since making it difficult for attackers to get in builds stronger software resilience, making it difficult for software failure, non-compliance, and broken code to threaten your business covers all your bases.
Securing the next 250 only sticks if critical software relationships still have a way back when Attack, Failure, Non-compliance, or Broken show up, so don't make it easy for them.
The cybersecurity habits protect what you already control
Every habit on the Alliance list is solid advice worth adopting, since together they do close off some of the most common routes attackers use. They are not, however, foolproof; each works on a belief about where the danger comes from. Let's take a look at the proposed habits for building stronger cybersecurity:
-
Use strong passphrases and a password manager. Credentials are how a large share of intrusions begin, so a different long passphrase behind every account removes the easiest way in. This only covers one entry point, though. Much of the software you rely on comes from third-party providers, and their build pipeline, repositories, and admin accounts still offer viable paths into your systems. An attacker pulled a credential out of Codecov's Docker build process in 2021, altered a script its customers ran, and collected keys and tokens from their systems for two months.
-
Turn on multi-factor authentication. A second factor means a stolen passphrase isn't enough to provide unauthorized access on its own, which nullifies credential stuffing and most password-oriented attacks. Plenty of attacks get past it regardless. Adversary-in-the-middle phishing puts a convincing copy of a login page between you and the real one, then takes the session token once you've authenticated properly. Microsoft tracked one such campaign over three days in April 2026 that reached more than 35 000 users at over 13 000 organizations.
-
Recognize and report phishing. Teaching your team to slow down on an unexpected request catches a good share of what lands in their inbox, and reporting it warns everyone else. However, human error never truly reaches zero. In 2022, someone talked their way into the FBI's own InfraGard portal, used by more than 80 000 vetted members, by applying under a financial services CEO's identity. The FBI approved it.
-
Keep software updated. Patching closes published vulnerabilities before anyone gets around to using them against you, which makes fast updates one of the highest-value habits on the list. But updates break things too. A faulty CrowdStrike update in July 2024 crashed 8.5 million Windows machines, grounded thousands of flights, and took emergency response lines offline, with no attacker involved anywhere.
Each of these does make it difficult for attackers to get in, though never impossible, and none of them really counters the other threats your software faces. They secure what you hold in your own hands, meanwhile the software carrying your operations often lives inside a relationship with another company.
To truly secure your business's future, as the 250 theme calls for, you have to manage your software risk across every relationship your operations run through, not only the systems you administer yourself.
The four risks that you leave unguarded
At Codekeeper, we've spent over a decade building software resilience for the companies that buy software and the ones that build it, and in that time we've identified the four biggest threats to your software's longevity. It doesn't matter how much you harden your cybersecurity, whether through awareness habits, stronger firewalls, or regular penetration testing. These four can still bring your operations to a complete stop:
-
Attack. Attackers have routes in through connected services, supporting platforms, and the data you keep in other companies' systems, none of which your own defenses cover. If you're "only as strong as your weakest link", that means your own strength counts for nothing when a service you depend on doesn't hold the same standard.
-
Failure. Your operations run on software somebody else owns, whether that's a license for something installed on your own servers, a SaaS platform, or an AI tool your team has built processes around. When those services shut down, get acquired, or hit an outage somewhere in their own supply chain, everything built on top crashes with it.
-
Non-compliance. Compliance doesn't look like a threat to your software until it stops you using it. In a regulated industry, processes that fall short bring fines, exclusion from the market, and enough lost deals to bleed a company out. None of that crashes a system, but it will put an end to your operations all the same, and no amount of security work produces the evidence a regulator asks for.
-
Broken. Unvetted AI code carries logic errors nobody checked. Corrupted updates inject bugs into production data. Technical debt piles up faster than anyone can clear it. Any of the three can bring your systems down from the inside, whether the fault sits in your own code, in the code you ship to clients, or in a service connected to your systems.
When you take a step back and look at every threat your software is exposed to, and every way it can shut down outside your control, cyber hygiene habits start to look thin. Protecting your systems against all four means putting resilience practices in place that don't make it easy for any of them to affect you.
» Read our State of Software Resilience research report to see how each of these four threats affects your industry.
Software resilience closes the gap
So what does software resilience look like? The ultimate goal is to stay operational regardless of what happens to your software or somebody else's. If an attacker locked you out of your systems, if a supporting service shut down overnight, or if an update broke everything and deleted your data, you could hit reset and carry on as though none of it happened.
That's not wishful thinking.
Software escrow sits at the top of resilience solutions, because it secures continued software access. It stores live copies of critical software with your configurations and data intact. If a software provider is compromised, goes bankrupt, or stops supporting the product, those copies are held independently by a third party and released to you, so you can rebuild the software you rely on exactly as you use it today.
It also protects the other side of the software relationship — the vendor builds a reputation of trustworthiness and reliability that helps them close more deals.
It doesn't matter what caused your software to break. Your continued use of it is secured.
Reframing your perspective away from daily habits that keep you secure, which are valuable up to a point, and toward protocols that allow total recovery regardless of what goes wrong, is how you build software resilience.
Start where continuity is thin
Start with the relationships where you can't honestly say continuity holds. An external service whose stability you have no way to check, a dependency running in production with nothing deposited behind it, a backup nobody has opened since the day it was made, or hosting and third-party services that stay up only while somebody else keeps paying for them.
Once you've identified where your software access is most vulnerable, set up a resilience solution for it ahead of time. Software security habits can be adopted at any time, but resilience takes a measure of foresight. You want something like a software escrow agreement in place while the developers behind the software you depend on are still around to sign it. The same holds if you're the one selling software, since you want to prove reliability and continuity before a client questions it.
Keep an eye out for the rest of our Cybersecurity Awareness Month posts, where we take each of the big four threats in turn and show you how to cover all your bases, make it difficult for them, and secure your next 250.
» Start a continuity check with Codekeeper to find out how you can secure your operational continuity for decades to come.