Recovering from a “Supply Chain Attack”: How IT Teams Should Audit Third-Party Software Dependencies