Open Source

IBM's Blueprint for Enterprise Open Source Stewardship

Jamie Thomas, IBM's Enterprise Security Executive and OpenSSF Governing Board member, explains how large organizations can turn their dependence on open source into strategic participation that strengthens both business and careers.

6 min read

Participating meaningfully in open source projects can align with corporate strategy, shape security decisions, and cultivate leaders within an organization. By working through the OpenSSF, companies bring their enterprise expertise to communities dedicated to securing the software infrastructure that underpins modern technology. For Jamie Thomas, this engagement carries an obligation: organizations must comprehend the software they rely on and contribute to its long-term viability.

In a June 16, 2026 conversation with CRob for Big Thoughts, Open Sources, Thomas recounted how IBM's involvement with Java, Linux, and Red Hat shaped its philosophy on enterprise engagement. As an IBM Enterprise Security Executive and current OpenSSF Governing Board member who previously chaired the board, Thomas connects that history to a fundamental question: how do companies transform their reliance on open source into deliberate, sustained stewardship?

If you are a direct consumer of open source, do it with intent.

Jamie Thomas, IBM

What Does Open Source Commitment Look Like at Scale?

IBM's track record illustrates how strategic investment in open source reflects broader business priorities. The OpenSSF, meanwhile, furnishes concrete tools that help enterprises manage their open source dependencies responsibly.

What Challenge Did IBM Need to Solve?

The company faced a dual imperative: mobilize developers across its ecosystem while ensuring enterprise customers could deploy open source with confidence and security.

Thomas recounted IBM's realization that fostering a robust Java community required rethinking how software development worked. IBM backed Linux contributors and made its Java development tools available through Eclipse, establishing a common platform for developers to collaborate on.

This shift sparked genuine disagreement. Some IBM customers questioned whether Linux made sense on IBM mainframes. The payoff, however, proved significant: applications built on Linux could operate across multiple hardware architectures, giving customers greater flexibility.

As the technology spread, customer concerns evolved. Enterprise buyers began asking who would maintain the software, operate it reliably, and handle security vulnerabilities. Experimenting with an open source project differed fundamentally from running it in production, where continuity and support became essential.

Why Does IBM Participate in OpenSSF?

The foundation offers IBM a venue to exchange knowledge with peer organizations, contribute its security expertise, and help establish shared standards for securing open source.

Thomas joined OpenSSF's Governing Board when the organization was founded. During the interview, she referenced the SolarWinds and Log4j incidents as pivotal moments in her transition to enterprise security work, highlighting how critical it is to understand vulnerabilities throughout the software supply chain.

For IBM, involvement keeps the company attuned to shifting security threats. It also creates channels to raise enterprise concerns alongside perspectives from startups, project maintainers, and other organizations consuming open source.

Thomas stressed that software transcends any single organization's boundaries. Participation enables companies to articulate their needs, grasp competing viewpoints, and shape choices that affect the projects they depend on.

How Does IBM Connect Open Source Contribution to Business Value?

IBM bridges community-driven innovation with developer engagement, platform expansion, and commercial support services.

Thomas noted that IBM's backing of Linux expanded its reach across IBM's own infrastructure, delivering customers more portability and choice. The company's acquisition of Red Hat strengthened its ties to open source communities and broadened its access to developers.

Red Hat exemplifies how open source can fuel a commercial enterprise through careful curation, ongoing maintenance, and professional support. These services help organizations progress from testing software to deploying it as mission-critical infrastructure.

Other large enterprises can apply the same logic: pinpoint where community involvement aligns with business objectives, then invest in the talent and partnerships necessary to make that involvement count.

How Does Open Source Participation Help Employees Become Leaders?

Working in open source communities offers staff a chance to hone their ability to persuade, communicate, and navigate disagreement across different organizations.

Thomas views open source work as one avenue for engineers to advance their careers. Those who contribute learn to articulate their thinking, appreciate competing interests, and guide teams toward consensus.

Thomas values the collective wisdom that emerges from OpenSSF's community. Employees gain that broader perspective and can apply it when talking with customers or shaping internal strategy.

IBM also makes community contributions visible within the company. Thomas described an annual Open Innovation Award that honors exceptional work in open communities, recognizing both individual contributors and managers. She highlights award recipients during her all-hands meetings.

This practice establishes a tangible link between community participation and organizational recognition.

What Can Employees Contribute Beyond Code?

Security knowledge, test infrastructure, deployment automation, technical writing, and project coordination all strengthen open source initiatives.

Thomas identified a persistent gap: building security tools and publishing guidance matters, but projects also require help putting those tools to work. Efforts like Akrites tackle this by mobilizing industry partners around coordinated vulnerability response and disclosure for essential software.

Automated testing and continuous integration and delivery represent areas where seasoned professionals can deliver substantial value. Thomas recalled IBM's experience with WebSphere, where scaling up automation proved transformative for her team.

That background shapes her thinking on AI-powered vulnerability detection. Discovering bugs is only the beginning; teams must then fix them and validate those fixes without disrupting downstream systems.

Contributors who help projects navigate that transition bring critical capabilities, regardless of whether writing application code is their main function.

How Can Enterprises Put "Consuming With Intent" Into Practice?

Organizations should map which open source projects they depend on, identify the people maintaining them, and establish a strategy for supporting their continued growth.

Thomas noted that participation takes many forms: submitting code, testing new versions, sharing security knowledge, or bringing enterprise perspectives into community working groups. The OpenSSF provides a framework for organizations to share their experience, learn from other enterprises, and help projects strengthen their security posture.

How Can Your Organization Get Started?

Select a project or community aligned with your business and establish a specific, measurable way to contribute.

Thomas concluded with a question applicable to any enterprise: participation might involve supporting developers' work upstream, offering security expertise, testing releases, or bringing an enterprise voice to a working group.

A straightforward first step is to identify one critical dependency, reach out to its community to ask where support is most needed, and allocate resources for a meaningful contribution. Acknowledge that work within your organization and share what your team discovers.

Joining the OpenSSF enables your organization to connect its capabilities with the global effort to secure open source.

Source: OpenSSF · Reporting supplemented by The Silicon Ledger staff.