Software supply chain attacks have seen triple-digit increases, but few organizations have taken steps to evaluate the risks of these complex attacks. This research provides three practices security and risk management leaders can use to detect and prevent attacks, and protect their organizations.