Webinar Description
Key Takeaways
- Explores why binary analysis is emerging as a more reliable approach to third-party software risk assessment than traditional metadata-based methods
- Addresses detection gaps in vendor-supplied manifests, SBOMs and attestations
- Includes real-world attack case studies and a live demonstration of binary analysis techniques
- Designed for security professionals, CISOs, application security engineers and DevSecOps teams
- Particularly relevant for organisations in regulated industries including finance, healthcare and the public sector
Introduction
The webinar “Why Binary Analysis Is Becoming the Standard for Third-Party Software Risk” examines a fundamental shift in how organisations approach software supply chain security. Hosted by ReversingLabs, the session targets security professionals and decision-makers responsible for evaluating third-party software before deployment. As supply chain attacks grow more sophisticated and regulatory scrutiny intensifies, the limitations of traditional verification methods have become increasingly apparent, making this topic particularly timely for enterprises managing complex software ecosystems.
About This Event
This virtual webinar combines educational content with practical demonstration, offering attendees both conceptual understanding and hands-on insight into binary analysis methodologies. The session features real-world attack examples that illustrate how threat actors exploit gaps in conventional security approaches, followed by a live demonstration of binary analysis applied to commercial software. ReversingLabs, the hosting organisation, provides context through its Spectra Assure platform, with additional industry perspective drawn from Gartner research.
The Limitations of Metadata-Based Security
Traditional approaches to third-party software risk assessment rely heavily on vendor-supplied information: manifests, software bills of materials and attestations. While these artefacts provide valuable transparency into declared components, they represent what vendors claim about their software rather than what the software actually contains. This distinction matters because sophisticated attacks increasingly target the gap between source code and deployed binaries.
Post-build tampering, build manipulation and the injection of hidden dependencies can all occur after source code review and before software reaches production environments. These modifications may not appear in any manifest or SBOM, leaving organisations with incomplete visibility into what they are actually deploying. The webinar addresses this blind spot directly, arguing that security decisions should be grounded in examination of the actual software artefact rather than metadata about it.
Binary-First Analysis as an Alternative Approach
Binary analysis involves direct examination of compiled software artefacts to identify components, behaviours and potential risks that may not be visible through other methods. Unlike source code review, which analyses what developers wrote, binary analysis examines what will actually execute in production. This approach can detect tampering that occurs during build processes, identify undeclared dependencies and uncover malicious code that was never present in source repositories.
The methodology complements rather than replaces existing security practices. Organisations can continue using SBOMs and vendor attestations while adding binary verification as an independent validation layer. This defence-in-depth approach addresses the reality that no single security control provides complete protection against supply chain compromise.
Industry Context and Regulatory Pressure
Software supply chain security has moved from a specialist concern to a board-level priority following high-profile incidents that demonstrated how compromised third-party software can provide attackers with access to thousands of downstream organisations. Regulatory frameworks increasingly require organisations to demonstrate due diligence in evaluating software they deploy, particularly in sectors handling sensitive data or critical infrastructure.
For organisations in finance, healthcare and the public sector, the ability to independently verify software integrity is becoming a compliance consideration as well as a security one. Binary analysis offers a mechanism for demonstrating that verification extends beyond accepting vendor claims at face value.
Who Should Attend
The webinar is designed for security teams evaluating their approach to third-party software risk, including application security engineers, security architects and CISOs. DevSecOps practitioners responsible for integrating security into software delivery pipelines will find the technical demonstration relevant to their workflows. Risk managers in regulated industries may benefit from understanding how binary analysis supports compliance and audit requirements.

