CyLab Seminar: William Enck
February 16, 2026
12:00 p.m. ET
Zoom or Hamburg Hall, room A301
February 16, 2026
12:00 p.m. ET
Zoom or Hamburg Hall, room A301
*Please note: this CyLab seminar is open only to partners and Carnegie Mellon University faculty, students, and staff.
Speaker:
William Enck
Goodnight Distinguished Professor in Security Sciences
North Carolina State University
Talk Title:
Securing the Software Supply Chain
Abstract:
Open source software is an economic driving force behind nearly all software products. However, the past half decade has seen a surge of attacks targeting critical but often overlooked parts of this software supply chain. The response from industry and government has been a frenzy of frameworks, regulations, tools, and best practices. But where does academia fit in?
The term "software supply chain" does not capture the nuance of the space. For the vast majority of open source software, there is no formal "supplier" and the "chain" is a complex interconnected graph. Existing tools that help developers manage known vulnerabilities in their dependencies rely on imperfect and imprecise data. Build processes were created based on threat models that no longer hold. Development environments make it too easy for developers to make choices that open both their projects and their own workstations to attack. The problems that underlie these challenges are not foreign to computer security research, but they require a partnership with practitioners to solve. This talk will describe what we have learned through our research and our extensive interactions with >150 practitioners from >50 companies as part of the NSF-funded Secure Software Supply Chain Center (S3C2).
Bio:
William Enck is the Goodnight Distinguished Professor in Security Sciences in the Department of Computer Science at the North Carolina State University where he is co-director of the Secure Computing Institute (SCI) and member of the Secure Software Supply Chain Center (S3C2). His research spans the broad area of systems security, applying a range of systems design, program analysis, and empirical studies. He is Vice President of the USENIX Board of Directors and has previously co-chaired the program committees of flagship security conferences including USENIX Security and IEEE S&P.
February 23 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301
March 9 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301
March 16 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301
March 23 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301
March 30 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301
April 6 2026
12:00 PM ET
CyLab Security and Privacy Institute
Zoom or Hamburg Hall, room A301