The SolarWinds Lessons Still Unlearned
SolarWinds: 2020. Assessment Checklist: Same Questions as 2019. Build Pipeline: Not Asked About.
4 min read · 23 June 2026 · Third-party oversight
The SolarWinds supply chain attack , disclosed in December 2020 , remains the most consequential supply chain security event of the recent era. Attackers associated with the Russian SVR gained access to SolarWinds' build infrastructure and inserted malicious code into the Orion IT monitoring platform's build process. The malicious code was compiled into legitimate Orion software updates, signed with SolarWinds' authentic code signing key, and distributed through SolarWinds' legitimate software update mechanism to approximately 18,000 customers, including US federal agencies, defence contractors, and major enterprises. The attack dwelled in the build infrastructure for approximately fourteen months before discovery. In those fourteen months, the attackers had full access to the networks of thousands of organisations through the trusted software update channel.
The lessons that SolarWinds were supposed to teach are specific and directly applicable to TPRM: build pipeline security matters as much as production environment security; code signing provides limited assurance if the signing infrastructure is compromised; software update mechanisms are high-value attack targets; and the fourteen-month dwell time was possible because no monitoring was pointed at the build infrastructure. These lessons were widely published, widely discussed, and have largely not been incorporated into standard TPRM assessment checklists, which continue to focus on production environment security, SOC 2 controls, and operational security posture while leaving build pipeline security, signing key protection, update mechanism governance, and supply chain monitoring absent from assessment scope.
The systemic failure is the assessment framework lag. Security assessment frameworks update to address new threat categories over time, but the update cycle is slow and incremental. Standard questionnaires and assessment frameworks that were designed before SolarWinds reflect a threat model that excludes the attack vector SolarWinds demonstrated. Practitioners who use standard frameworks without augmenting them for post-SolarWinds supply chain security requirements are assessing against a pre-SolarWinds threat model , confirming that vendors are secure against the attacks of 2019 while leaving the attacks of 2020 and beyond unaddressed.
Why this matters
The unlearned SolarWinds lessons matter for TPRM because they represent a systematic gap between current supply chain attack capabilities and the assessment questions that most TPRM programmes ask. A software vendor who passes every standard security assessment while having a build pipeline with no monitoring, a signing key stored in a file on a server, and an update mechanism with no anomaly detection is a vendor that is vulnerable to a SolarWinds-style attack , regardless of their SOC 2 status.
- Build pipeline security absent from assessment , SolarWinds entry point not addressed
- Signing key protection not assessed , file storage vs HSM not asked
- Update mechanism security not assessed , SolarWinds distribution vector not addressed
- Supply chain monitoring not assessed , fourteen-month dwell possible without it
- Assessment framework not updated post-SolarWinds for build-layer risk
What good looks like
Post-SolarWinds assessment frameworks add build pipeline security, signing key protection, update mechanism governance, and supply chain monitoring to the standard assessment scope , specifically addressing the four control gaps that SolarWinds demonstrated were insufficient.
- Build pipeline security in assessment scope , third-party integrations, credentials, isolation
- Signing key protection in assessment , HSM vs file storage, rotation policy
- Update mechanism security in assessment , authenticity, integrity, enterprise control
- Supply chain monitoring in assessment , build pipeline logs, artifact registry monitoring
- Assessment framework updated to reflect post-SolarWinds supply chain threat model
Tooling
SolarWinds Lesson Reference , CISA's SolarWinds guidance; NIST SP 800-161 Rev. 1 supply chain-specific controls updated post-SolarWinds
CISA published specific guidance following the SolarWinds disclosure that addresses the technical controls relevant to build pipeline compromise and supply chain attack detection. NIST SP 800-161 Rev. 1 was updated to specifically address software supply chain security in response to the SolarWinds attack and executive orders. These documents provide the post-SolarWinds assessment framework updates that standard questionnaires have not yet incorporated.
Governance challenges
The governance challenge with the unlearned SolarWinds lessons is the assessment framework inertia. Standard questionnaires are updated by committees on multi-year cycles. Practitioners who wait for standard frameworks to incorporate post-SolarWinds supply chain security questions will continue to assess against a pre-SolarWinds threat model. The governance resolution is augmenting standard frameworks with supply chain-specific questions that address the SolarWinds attack vector explicitly.
- Augment standard assessment frameworks with build pipeline security questions
- Add signing key protection to standard assessment scope
- Add update mechanism security to standard assessment scope
- Add supply chain monitoring to standard assessment scope
- Reference SolarWinds attack model explicitly in supply chain security requirements
If you are a small team
Add four questions to your next software vendor assessment that are not in your current questionnaire: (1) How is your build pipeline isolated from your production environment? (2) How are your code signing private keys protected against extraction? (3) How do you detect anomalous access to your build pipeline and artifact registry? (4) How do you govern your software update mechanism to ensure only legitimate updates are distributed? Those four questions directly address the four SolarWinds control gaps and take five minutes to add to any assessment framework.
- Add build pipeline isolation question to assessment
- Add signing key protection question to assessment
- Add supply chain monitoring question to assessment
- Add update mechanism security question to assessment
What to require
Ask directly:
"Given the SolarWinds attack model , build pipeline compromise, signing key access, and distribution through legitimate update channels , what specific controls do you have for each of these three attack vectors, and how do you monitor for anomalous activity in your build and distribution infrastructure?"
Expect as evidence
- Build pipeline isolation and monitoring controls
- Signing key protection , HSM or equivalent
- Update mechanism security and enterprise governance
- Supply chain monitoring scope and detection capability
A vendor who passes a standard security assessment should be asked the four post-SolarWinds questions. Standard assessments assess against the 2019 threat model. Post-SolarWinds questions assess against the 2020 threat model that the standard frameworks have not yet incorporated.
How to evidence it
- Post-SolarWinds assessment augmentation
- Build pipeline security assessment records
- Signing key protection assessment
- Supply chain monitoring scope verification
Key Takeaway
SolarWinds: 2020. Build pipeline compromised. Signing key accessed. 18,000 organisations reached through legitimate update channel. Fourteen months undetected. Assessment checklists four years later: same questions as 2019. The four control gaps SolarWinds demonstrated , build pipeline isolation, signing key protection, update mechanism security, supply chain monitoring , are absent from most standard assessment frameworks. Adding four specific questions to the next software vendor assessment takes five minutes and directly addresses the attack vector that the standard questionnaire was designed before and has not been updated to address.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association