IBM, Red Hat, and Deloitte collaborate on Lightwell to secure open source
IBM, Red Hat, and Deloitte have formed a collaboration to enhance open source software supply chain security through the Lightwell initiative. Announced on June 26, 2026, the partnership aims to decouple security remediation from software upgrade cycles by delivering validated patches to production environments. The initiative leverages a $5 billion commitment from IBM and Red Hat and integrates Deloitte's cyber risk services to provide machine-speed vulnerability detection, prioritization, and remediation.

*this image is generated using AI for illustrative purposes only.
IBM, Red Hat, and Deloitte have announced a collaboration to strengthen the security of open source software supply chains against automated cyber threats. Announced on June 26, 2026, the partnership integrates Deloitte as an integration collaborator for Lightwell, an initiative designed to decouple open source security remediation from traditional software upgrade cycles. The collaboration aims to deploy validated patches directly to pinned software versions running in production environments, protecting critical systems without forcing disruptive upgrades.
Lightwell combines an enterprise open source security model with an active engineering force to address operational pressure caused by frontier AI models accelerating the discovery of zero-day flaws. The initiative coordinates upstream threat disclosures with independent maintainers while developing, testing, and backporting patches. This builds on the $5 billion commitment from IBM and Red Hat to support Project Lightwell, which previously focused on combining an enterprise security clearinghouse with a global force of engineers.
Operational Coordination
The three organizations will coordinate across the software lifecycle to manage security threats through four key areas:
- Continuous Visibility & Discovery: Continuously mapping and scanning first-party, open source, and third-party software to identify code location and business function support.
- Contextual Prioritization: Separating active threats from noise by analyzing severity, exposure, threat-chaining, and exploitability.
- Machine-Speed Remediation: Combining Red Hat and IBM’s automated patch validation with Deloitte’s orchestration services to rapidly deploy fixes. Deloitte will maintain a bench of Forward Deployed Engineers (FDEs) for ongoing remediation.
- Ecosystem Trust & Compliance: Managing upstream open source and vendor relationships, including pre-disclosure vulnerability handovers, and delivering evidence-based reporting for regulators.
Strategic Integration
This collaboration extends the capabilities of the OpenAI Daybreak Cyber Partner Program, which IBM joined on June 22, 2026, to integrate advanced frontier AI into enterprise security operations. The new application security service launched by IBM, powered by IBM Consulting Advantage, utilizes OpenAI's cyber capabilities to identify and validate software vulnerabilities. Deloitte's involvement brings its broader secured software supply chain architecture and cyber risk services to this large-scale enterprise model.
| Key Initiative Details | |
|---|---|
| Program Name | OpenAI Daybreak Cyber Partner Program |
| New Service | Application Security Service |
| Supporting Platform | IBM Consulting Advantage |
| Strategic Project | Project Lightwell |
| Financial Commitment | $5 billion from IBM and Red Hat |
Executive Perspectives
"Exploits don't wait for manual patching processes, and neither can enterprise response," said Adnan Amjad, Deloitte’s US Cyber leader. "Together, we're enabling clients to operate at machine speed to identify, validate, and remediate vulnerabilities. This collaboration is about building the operational resilience needed to maintain trust across increasingly complex software ecosystems."
"Lightwell was created to address the growing challenge of securing open source software in an AI-driven threat landscape," said Savio Rodrigues, Vice President, Service Partners at IBM. "We’re excited to collaborate with Deloitte and leverage their capabilities in cyber risk management to extend this model to more organizations."
"Open source drives innovation, but the volume of AI-generated threats requires engineering capacity that matches the speed of the attacker," said Kevin Kennedy, Vice President, Global Partner Ecosystem at Red Hat. "Our work with Deloitte will bring the remediation capabilities we developed with IBM with Lightwell directly to enterprise application environments."
How will the integration of OpenAI's frontier AI models within the Application Security Service influence the accuracy of contextual prioritization compared to traditional methods?
What are the potential regulatory implications for enterprises utilizing automated backporting of patches instead of full software upgrades for compliance reporting?
How might this collaboration pressure other major cloud providers and consulting firms to develop similar machine-speed remediation capabilities?

































