Exploring SBOMs and Software Escrow: Strategies for Securing OT Supply Chains | NCC Group

0
330

“Timely and secure information sharing can bridge the gap between vulnerability and security.”

This was a key message from a recent webinar on ICS & OT Supply Chain Risk Management presented by Information Security Media Group. The webinar discussed how Industrial Controls Systems (ICS) and Operational Technology (OT) can be particularly vulnerable to supply chain risks. In addition, it explained how today’s trend toward greater information sharing – including software-related information sharing – is especially relevant for critical infrastructure.

One way to mitigate these risks is by sharing information with a Software Bill of Materials (SBOM) to help navigate real-world attacks and the state of an organization’s operational security. We’ll look at SBOMs, and the closely related software escrow agreements, to understand how they can help lessen supply chain risk – protecting business-critical applications from both cyber risk and vendor failure or lack of support.

Supply chain risk and the ability to respond

Supply chain attacks were one of the top three types of cyberattacks to increase in the last half of 2021, according to recent NCC Group research….

Read More…