Mark L Profile

Mark Lechner

CISO, Docker

Mark Lechner is the Chief Security Officer at Docker

More by Mark

Jul 24, 2026

Agentic AI Needs Guardrails, Not Guesswork

Docker brought together enterprise security leaders to tackle agentic AI’s biggest challenge: how to govern AI agents without slowing developers down. Here’s what they said.

Mark L Profile
Mark Lechner
Apr 2, 2026

Defending Your Software Supply Chain: What Every Engineering Team Should Do Now

The latest supply chain attack wave is not a single incident to respond to. It is a permanent shift in the threat landscape. In this blog by the Docker CISO Mark Lechner, we share the recommended best practice we use to protect ourselves.

Mark L Profile
Mark Lechner
Mar 23, 2026

Trivy supply chain compromise: What Docker Hub users should know

On March 19, 2026, threat actors compromised Aqua Security’s CI/CD pipeline and used stolen credentials to push backdoored versions of the aquasec/trivy vulnerability scanner to Docker Hub. A second wave of compromised images followed on March 22. The malicious images contained an infostealer targeting CI/CD secrets, cloud credentials, SSH keys, and Docker configurations. This post summarizes what happened, what Docker did in response, and what you should do if you use Trivy.

Mark L Profile
Mark Lechner
Feb 10, 2026

Hardened Images Are Free. Now What?

Docker Hardened Images are now free. Learn the waterline model, supply chain isolation, VEX, and policy automation to cut CVE noise and meet compliance.

Mark L Profile
Mark Lechner
Nov 19, 2025

Why I joined Docker: security at the center of the software supply chain

Mark Lechner, Docker’s CISO, shares his vision for a future where Docker not only powers the software supply chain, but actively safeguards it.

Mark L Profile
Mark Lechner
Jul 24, 2026

Agentic AI Needs Guardrails, Not Guesswork

Docker brought together enterprise security leaders to tackle agentic AI’s biggest challenge: how to govern AI agents without slowing developers down. Here’s what they said.

Mark L Profile
Mark Lechner
Apr 2, 2026

Defending Your Software Supply Chain: What Every Engineering Team Should Do Now

The latest supply chain attack wave is not a single incident to respond to. It is a permanent shift in the threat landscape. In this blog by the Docker CISO Mark Lechner, we share the recommended best practice we use to protect ourselves.

Mark L Profile
Mark Lechner
Mar 23, 2026

Trivy supply chain compromise: What Docker Hub users should know

On March 19, 2026, threat actors compromised Aqua Security’s CI/CD pipeline and used stolen credentials to push backdoored versions of the aquasec/trivy vulnerability scanner to Docker Hub. A second wave of compromised images followed on March 22. The malicious images contained an infostealer targeting CI/CD secrets, cloud credentials, SSH keys, and Docker configurations. This post summarizes what happened, what Docker did in response, and what you should do if you use Trivy.

Mark L Profile
Mark Lechner
Feb 10, 2026

Hardened Images Are Free. Now What?

Docker Hardened Images are now free. Learn the waterline model, supply chain isolation, VEX, and policy automation to cut CVE noise and meet compliance.

Mark L Profile
Mark Lechner
Nov 19, 2025

Why I joined Docker: security at the center of the software supply chain

Mark Lechner, Docker’s CISO, shares his vision for a future where Docker not only powers the software supply chain, but actively safeguards it.

Mark L Profile
Mark Lechner