Breakpoint Security Podcast

Chat with Neelu

2025/11/02

Guest: Anant Srivastava, Chief researcher & Founder @ Cyfinoid Research Pvt Ltd

Often, it’s not your code that gets breached, it’s the code you inherit. We expose the hidden dangers lurking in your Software Supply Chain and reveal the single document that can save you: the SBOM.

In this episode, Neelu and Anant delve into the concept of Software Bill of Materials (SBOM), its significance in the #cybersecurity landscape, and the challenges associated with its implementation. They discuss the limitations of current #sbom practices, the importance of understanding transitive #dependencies, and the need for a comprehensive approach to #supplychainsecurity. The conversation also touches on the static nature of #SBOMs, the debate over public versus private SBOMs, and the role of #vex and VDR in managing #vulnerabilities. Anant shares insights from his experiences in the field and emphasizes the importance of centralized dependency management in ensuring software security.

Recommended reading/viewing, Paper for practitioners

AI Generated Summary

This comprehensive discussion on Software Bill of Materials (SBOM) covers fundamental concepts, implementation challenges, and future directions in supply chain security.

Key Topics Discussed

SBOM Fundamentals:

Critical Gaps in Current SBOM Practices:

Public vs Private SBOM Debate:

VEX and VDR (Vulnerability Exploitability eXchange / Vulnerability Disclosure Report):

Software Asset Inventory:

Geopolitical and Compliance Challenges:

Shadow IT and AI:

Centralized Dependency Management:

Important Projects and Tools Mentioned

Key Insights and Quotes

Actionable Takeaways

  1. Create SBOMs at build time, not as afterthoughts
  2. Automate SBOM generation to avoid static document problems
  3. Use SBOMs to identify and consolidate commonly used libraries
  4. Security teams should provide vetted library packages to developers
  5. Consider VEX/VDR for vulnerability context beyond basic inventory
  6. Implement software asset inventory tools like OSQuery for comprehensive visibility
  7. Treat SBOMs as living documents that update with each build, not vendor onboarding checklists