Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Independently Verified SBOMs: Why Trust Is No Longer Enough

Solution Category Security Operations
Type Webinar
Organization ReversingLabs
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Explores why vendor attestations and security questionnaires no longer provide adequate assurance for third-party software risk
  • Examines binary-first analysis and deep artifact forensics as methods for independently verifying software integrity
  • Addresses limitations of vendor-provided SBOMs and manifest-level scanning approaches
  • Relevant for security professionals, release managers, compliance officers and IT risk managers across regulated industries
  • Includes live demonstration of independent software verification techniques

Introduction

The webinar “Independently Verified SBOMs: Why Trust Is No Longer Enough” examines a fundamental shift occurring in software supply chain security. Designed for security professionals, release managers and IT risk managers responsible for third-party software procurement and deployment, the session addresses why traditional trust-based approaches to vendor assessment are proving insufficient in the current threat landscape. As software supply chain attacks continue to increase in frequency and sophistication, organisations are reconsidering whether vendor attestations alone can provide the assurance they require.

The Limitations of Trust-Based Security Models

For years, organisations have relied on security questionnaires, vendor attestations and contractual assurances when evaluating third-party software. This trust-based model assumes that vendors accurately represent the security posture of their products and that the software delivered matches what was described during procurement. However, high-profile supply chain compromises have demonstrated that even well-intentioned vendors may lack complete visibility into their own software components, and that malicious code can be introduced at various points in the development and distribution pipeline.

The webinar explores why this traditional approach creates blind spots. Vendor-provided Software Bills of Materials, while valuable, represent only what the vendor believes is present in their software. Manifest-level scanning, which examines declared dependencies rather than actual binary contents, may miss undeclared components, embedded libraries or modifications introduced after the manifest was generated. These gaps leave organisations exposed to risks they cannot see or measure.

Binary-First Analysis and Artifact Forensics

The session presents binary-first analysis as an alternative approach that examines shipped software artifacts directly rather than relying on vendor documentation. This method involves analysing the actual binaries, executables and packages that will be deployed in production environments. Deep artifact forensics extends this concept by examining software at a granular level to identify components, detect anomalies and verify integrity.

By generating SBOMs independently—both before release and before deployment—organisations can compare their findings against vendor-provided information and identify discrepancies. This evidence-based approach shifts the verification burden from accepting vendor claims to validating them through technical analysis. The distinction matters particularly for organisations in regulated industries where demonstrable due diligence is increasingly expected.

Building Verification-Based Software Acceptance Policies

Beyond technical analysis methods, the webinar addresses the policy frameworks needed to operationalise independent verification. Software acceptance policies grounded in verification rather than trust establish clear criteria for what evidence must be gathered before third-party software enters an environment. These policies define acceptable risk thresholds, specify which verification steps are mandatory and create audit trails that demonstrate compliance with internal standards and external regulations.

This approach aligns with broader industry movements toward software supply chain security governance. Regulatory frameworks and industry standards increasingly expect organisations to demonstrate visibility into their software dependencies and to maintain evidence of security assessments performed on third-party components.

Who Should Attend

The webinar is designed for professionals involved in software security, procurement and risk management. Security teams responsible for evaluating third-party software will find the technical content on binary analysis directly applicable to their assessment processes. Release managers and DevSecOps practitioners can apply the verification concepts to their deployment pipelines. Compliance officers and IT governance professionals will benefit from understanding how evidence-based verification supports regulatory requirements and audit readiness.

Organisations in technology, financial services, healthcare, energy and the public sector—where software supply chain risks carry significant operational and regulatory implications—represent the primary audience for this content.

Practical Demonstration

The session includes a live demonstration of independent software verification, providing attendees with a practical view of how these concepts translate into operational workflows. This component moves beyond theoretical discussion to show how binary analysis and SBOM generation function in practice when applied to real software artifacts.