Katie Norton

IDC, Research Manager, DevSecOps and Software Supply Chain Security

Katie Norton is a Research Manager for IDC’s DevSecOps and Software Supply Chain Security research practice. She is responsible for researching, writing, and advising clients on the fast-evolving DevSecOps and software supply chain security markets. With her background in research administration and data analytics, Katie takes a data-first approach in her market analysis.

Katie’s core research areas include the integration of security into the software development lifecycle, development team ownership of security and collaboration with AppSec teams, and examining the drivers of DevSecOps adoption. She also explores buying patterns and trends for DevSecOps and software supply chain security tooling. Katie’s industry-leading research defines the software supply chain security market and helps end users understand software factory security. Other topics include ASPM and application vulnerability management, securing AI applications, AI use cases in DevSecOps, and SBOM generation and management.

The Latest From Katie Norton

  • The Dependency Dilemma: Balancing Innovation Speed with Supply Chain Resilience

    | 7 min read

    Sponsored by JFrog ~  Development teams are shipping faster than ever. Generative AI coding assistants, early agentic workflows, and increasingly modular architectures have compressed the distance between concept and deployment. AI-enabled innovation has become an executive mandate, and teams are expected to deliver at speed without sacrificing security or compliance. At the same time, modern…

    Read More