eric.gallagher Software Supply Chain Risk & Defense
For Engineering & Security Leaders // Score it or Defend it

How exposed is your software supply chain —
and could you actually defend it?

Two ways to find out. Take the free diagnostic for a scored view of your real posture, or step into the pipeline yourself and see exactly where detection stops working.

// Diagnostic
Take the Assessment

A free 22-question diagnostic scoring your risk across seven dimensions — sourcing, build integrity, vulnerability posture, governance, and more. Every respondent gets a live 1:1 debrief with me.

// 8–12 min  ·  Free  ·  No pitch, just findings
Take the Assessment
// Free Browser Game
Play Defenders of the Code
Secure the Pipeline. Trust Nothing.

A tower-defense game where you defend a real build pipeline against real attacks — XZ Utils, SolarWinds, Shai-Hulud, TanStack. Learn firsthand why detection fails and only curated catalogs scale.

// 30 waves  ·  Free  ·  No install, runs in browser
Play the Game
// Pick one, or do both — they teach the same lesson from opposite directions
01
Your Risk Score
An overall maturity score out of 100, benchmarked across four tiers from Reactive to Optimized. See exactly where you land.
02
Dimension Breakdown
Individual scores across all seven dimensions so you know which areas are carrying the most risk — and which are already strengths.
03
Top Gap Analysis
Your three highest-priority risk areas, ranked by score. A clear starting point for your next 90 days of remediation work.
04
Live Debrief with Eric
Every respondent gets a personal follow-up. Not a sales pitch — a real conversation about your findings and what they mean for your organization.
01Visibility & SBOM
02Sourcing & Provenance
03Build Integrity
04Vulnerability & CVE Posture
05Tooling Strategy
06Governance & Policy
07Incident Response
// Questions are weighted by dimension. Scoring reflects real-world risk exposure, not checkbox compliance.
Reactive 0–39 Ad hoc responses. Significant exposure across most dimensions.
Maturing 40–64 Some controls in place. Key gaps remain in governance and visibility.
Proactive 65–84 Solid foundation. Optimization opportunities in tooling and policy.
Optimized 85–100 Leading posture. Supply chain risk is a managed, strategic discipline.
Scanners feel like security. Then Act 3 happens.

Defenders of the Code is a tower-defense game set inside a software build pipeline. You place real security controls — SBOM scanners, policy gates, curated catalogs — across seven lanes to stop real attack types before they reach production. Every wave escalates: what stopped Act 1 fails by Act 3. By Act 4 you'll understand why the question isn't "is this threat known?" — it's "was this component pre-approved?"

Registries
Sourcing
Build
Scan
Catalog
Deploy
Production
// Seven lanes, left to right — open source registries to production. You defend all of them at once.
01
Real Incidents
Enemies are drawn from actual attacks — XZ Utils, SolarWinds, axios/TeamPCP, Shai-Hulud, TanStack namespace attacks.
02
30 Waves, 4 Acts
A full campaign from scrappy startup to critical infrastructure, each act raising the stakes technically and narratively.
03
The Catalog Doctrine
Learn — by losing, not by reading — why detection stops scaling and prevention through curation is the only thing that does.
04
Free, No Install
Runs entirely in your browser. No signup, no download, no build step. Just open it and start defending.
Act 1Scanners feel like security. Tier 1 towers win easily.
Act 2Controls feel like security. Tier 1 fails; Tier 2 buys time.
Act 3Nothing works. Nation-state enemies overwhelm every reactive control.
Act 4The catalog is the moat. Lanes covered by Curated Catalog towers go dark — no spawns enter.
Play Defenders of the Code
Eric Gallagher
Enterprise Security · Software Supply Chain Risk

Modern organizations run on a software supply chain that is fragile, opaque, and increasingly dangerous — and far too many leaders are operating under comforting illusions. I challenge those illusions.

I work with CISOs, security leaders, and engineering executives who are no longer satisfied with the industry's shallow explanations, vendor gloss, or false sense of security. My approach is simple: brutal clarity, strategic truth, zero bullshit. The assessment gives you the score. The game gives you the feeling. I built both because some lessons land better scored, and some land better lost.

// The illusions I hear most often — and spend my time dismantling:

"Secure containers" are only as secure as the application layer beneath them
SBOMs without curation produce false confidence, not real visibility
"Shift left" is a myth in enterprise reality — the risk doesn't move with it
Dependency sprawl is becoming an existential risk, not a hygiene problem
Most supply chain attacks succeed long before runtime
Security is no longer a tooling problem — it's a governance problem

Through Securing the Backbone and five books on supply chain risk, I help security leaders get past the dashboards and noise — toward better assurance, better visibility, and better control of the code their enterprises depend on.

ActiveState Securing the Backbone 5x Author Defenders of the Code Parkersburg, WV
Know your number.
Then let's talk about what it means.

The assessment takes under 12 minutes. Your score is immediate. The debrief is personal — I read every response before we connect.

Start the Assessment
// Free · 8–12 min · Personalized debrief included
Think you'd catch it?
Defend the pipeline and find out.

Free, browser-based, no install. Thirty waves stand between a scrappy startup and critical infrastructure — and only one doctrine gets you through all of them.

Play Defenders of the Code
// Free · Runs in browser · 4-act campaign