Skip to content

SBOM and Software Supply Chain Visibility

Knowing what is in your software, so the next critical vulnerability is a query rather than a week.

Editorial team 2 min read

When a critical vulnerability lands in a widely used library, the first question is "where do we run this?" Organisations that can answer in minutes have an inventory; the rest spend a week asking teams.

What an SBOM is

A software bill of materials lists the components in a build — direct and transitive dependencies, versions and licences — in a standard format (CycloneDX or SPDX). Generated at build time, stored with the artefact, and queryable across the estate.

What it does not do

An SBOM does not tell you whether you are exploitable. A vulnerable function may never be called, or the component may be unreachable. It narrows "which of our 400 services might be affected" to a list you can triage; reachability analysis and context do the rest.

Making it useful

  • Generate on every build, not on request.
  • Store centrally and make it searchable by component and version.
  • Include container base images and operating system packages, which is where most of the count comes from.
  • Track provenance: who built it, from which source, with what signature.

The adjacent controls

Pinned dependency versions, a review step for new dependencies, build systems that cannot be modified by a pull request, and signed artefacts. Most supply chain incidents begin with a compromised build or a typo-squatted package, both of which an SBOM records after the fact and provenance controls prevent.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025