Webinar: Webinar: From SBOMs to Decisions: Prioritizing Supply Chain Risk in Time-Bound M&A Reviews – Prashanth Chandrasekar (English)

Software supply chain risk assessments increasingly rely on Software Bill of Materials (SBOMs), yet their practical value is often tested under severe time constraints. In Mergers and Acquisitions (M&A) due diligence, Application Security (AppSec) teams are frequently required to assess large codebases and their third-party dependencies within days or weeks, where the goal is informed risk visibility rather than exhaustive remediation. This talk presents a practitioner’s perspective on using SBOMs to prioritize software supply chain risk under tight M&A timelines. Drawing from real-world due-diligence engagements, it explores how AppSec teams analyze SBOMs to identify high-impact dependencies, assess transitive risk, and correlate vulnerability intelligence with open-source license obligations that may influence post-acquisition risk. The session also addresses common challenges such as incomplete SBOMs, noisy vulnerability data, unclear license declarations, and limited exploit or usage context. The emphasis is on practical, risk-based prioritization techniques and legal-safe framing of findings.

Ludwig_Van_Beethoven
From_SBOMs_to Decisions_Prioritizing_Supply_Chain_Risk_in_Time-Bound_M&A_Reviews
SBOM_or_Bust:_Automating_Compliance_for_EU_CRA_&_Beyond
BSI_Vortrag:_Praxis_CRA-Compliance:_Wie_offene_Werkzeuge_KMU_bei_der_Absicherung_von_Software-Lieferketten_unterstützen
FOSS Backstage 2026_Dr. Andreas Kotulla und Chan-jo Jun
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
Image
Webinarbild mit Text: A Global Outlook - Mitigating Risks in Open Source and Software Supply Chains
Revenera_Webinar_Das_Supply_Chain_Risiko_dass_Sie_nicht_ignorieren_dürfen: Ein_Leitfaden _für_kritische_Branchen
OpenChain Webinar: Project OCCTET.eu - Why, What and How
Modern Open Source Risk Management - What you should be doing now
Vortrag_Lizenzverletzungen_Bei_KI_generierten_Code
OpenChain_Webinar: Eine_Diskussionsrunde_zu_den_Risiken_und_dem_ Management_generativer_KI
Vortrag_Lizenzverletzungen_Bei_KI_generierten_Code
Anyone_who_still_puts_AI-generated_code_into_circulation_today_has_conditional_intent_to_infringe_the_law_how_to_limit_or_at_least_defer_the_risk
Flexera_Webinar_Regulations_Roundup_Navigating_SBOM_and_OSS_Compliance_Across_the_US_India_and_Europe