Innovation’s greatest ally and its weakest link

Innovation’s greatest ally and its weakest link

Peter Lees, VP & Head of Solutions, Asia Pacific at SUSE, discusses why enterprises can’t abandon open source, but why blind trust in community-maintained code is no longer good enough.

Open-source software is the tap water of the digital age. It flows into almost every enterprise system, sustaining the applications we depend on every day. But like tap water, it isn’t always safe to consume straight from the source. Unless it’s filtered, treated and checked, the very thing keeping us alive can just as easily make us sick.

The brilliance of open source lies in its openness. Anyone can contribute, audit and improve the code. But that same openness gives attackers an unrestricted view of the blueprints.

Publicly available code lets both researchers and cybercriminals find flaws; this community-driven maintenance, another strength of open source, can unfortunately turn into a liability, especially for smaller or abandoned projects that can wait weeks or months for patches. Enterprises frequently run outdated versions of libraries, leaving known vulnerabilities exposed simply because upgrades are inconvenient.

Modern software also rarely runs on a single component. It’s built on sprawling dependency chains, where a forgotten or unobtrusive package buried many layers deep can provide the weak point an attacker needs: we’ve already seen malicious actors intentionally inject compromised packages into public repositories, planting digital landmines for enterprises that blindly pull them in.

The result is a paradoxical picture; open source accelerates innovation while simultaneously making organisations more vulnerable. It’s important to acknowledge that the openness of the source makes discovery of vulnerabilities – intentional or otherwise – much easier than if closed-source code is compromised, but the rise of AI-powered code analysers has meant that openness can be exploited much faster than ever before.

Yet abandoning open source is impossible. Its ubiquity is exactly why it’s indispensable. Developers lean on it to move fast, avoid reinventing the wheel and tap into the collective expertise of global communities. Enterprises rely on it for flexibility, interoperability and avoidance of lock-in.

Without open source, digital transformation would grind to a halt. The challenge is not whether to use it, but how to use it responsibly. Treating OSS as a commodity, like tap water, means acknowledging both its necessity and its risks.

Enterprises need to filter their open-source supply before drinking deeply. The most effective way to start is with enterprise-grade distributions, curated, secured and patched OSS maintained by vendors with the expertise to guarantee integrity. Just as no one would pipe unfiltered river water into a hospital, critical workloads should never run on unverified community code.

But distributions alone aren’t enough. Security demands constant vigilance. Continuous scanning and observability give teams a live picture of what’s happening inside their systems, flagging known vulnerabilities at build time and catching unexpected behaviour in production before it spirals into a breach.

At the same time, organisations need to take a harder look at the plumbing beneath their applications – dependency hygiene, knowing exactly what’s in the stack, retiring abandoned packages and tightening up chains of libraries. Provenance frameworks like SLSA (Supply-chain Levels for Software Artifacts) are beginning to formalise this discipline, giving enterprises a roadmap for what ‘trusted’ OSS should look like.

AI complicates the picture even further. Generative code is flowing into production environments at speed, but accountability is lagging behind. Too often, AI-written code is deployed without proper validation, or worse, ‘checked’ by another AI model. That’s blind trust by another name.

For too long, open source has been treated as ‘free’ and therefore ‘safe’. But open source is infrastructure and like any infrastructure, it needs governance, maintenance and accountability.

That means shifting from blind trust to informed trust. Trust the community but verify the code. Trust the innovation but secure the distribution. Trust the openness but monitor the runtime. In practical terms, this means repeatable builds, auditable pipelines, enterprise-grade distributions and a commitment to observability at scale.

Open source is innovation’s greatest ally. But without filtration, verification and governance, it risks becoming its weakest link. The open-source paradox won’t be solved by abandoning openness, nor by clinging to the illusion of perfect security. It will be solved by filtering what flows into our systems, balancing speed with safety and building innovation on solid ground.

Browse our latest issue

Intelligent CIO APAC

View Magazine Archive