Software supply chain

August 7, 2026 | Jack Burnham |

Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program

July 1, 2026 | Georgianna Shea, Stephen Thursby

Quantum Computers Are Coming. Washington Is Finally Paying Attention.

Encryption protects your data from prying eyes. The complex math problems that underpin encryption, however, may soon no longer keep your data safe. Quantum computers test multiple answers simultaneously,...

April 9, 2026 | Georgianna Shea |

From Static Inventory to Real-Time Defense: Why the SBOM conversation has to change now

When the next widely exploitable vulnerability appears, your organization will have far less time to respond than the processes you have built were designed to handle. That is not a prediction. It is what...

March 23, 2026 | Chuck Brooks, Georgianna Shea

Cryptography Bill of Materials (CBOM): Why Every Encryption Ecosystem Needs One – and Fast

We’ve learned the hard way that knowing what’s in your software supply chain matters. The Software Bill of Materials (SBOM) progressed from a niche best practice to government regulation  codified...

May 7, 2025 | Georgianna Shea |

Artificial Intelligence Infrastructure on DOE Lands

April 29, 2025 | Georgianna Shea |

The Pentagon must balance speed with safety as it modernizes software

The Department of Defense is at grave risk of being caught flat-footed by the next software vulnerability. When an adversary discovers it, the Pentagon may not know which systems are exposed until substantial...

February 24, 2025 | Georgianna Shea |

The Three Pillars of U.S. Technological Leadership

The United States stands at a pivotal moment in the global technological race, facing an increasingly assertive China that leverages state-backed investments to dominate key industries.

October 21, 2024 | Georgianna Shea, Zachary Daher

How to Manage AI Big-Data Risks

Establishing a taxonomy for AI risks would enable researchers, policymakers, and industries to communicate effectively and coordinate their efforts.

March 4, 2024 | Georgianna Shea |

The Power of SBOMs: Building Resilience in Our Critical Infrastructure

As a member of the PCAST Working Group on Cyber-Physical Resilience, I was involved in crafting the recent report outlining crucial steps to fortify the intricate systems that underpin our daily lives....

January 25, 2024 | Michael Sugden |

The Missing Middle

Addressing the Absence of Firmware Security

November 17, 2023 | Georgianna Shea |

Charting FDA’s Course: SBOM as the North Star in Cybersecurity

Supply chain security has undergone a profound transformation after pivotal events such as the SolarWinds compromise in 2020 and the subsequent Log4j incident.  Central to this evolution is the emergence...

September 5, 2023 | Georgianna Shea |

Unlocking the Potential: How SBOM Practices Revolutionize Tech Industries

Following the SolarWinds compromise, the focus on the Software Bill of Materials (SBOM) has surged remarkably. In the tech ecosystem, the SBOM offers a comprehensive overview of software components...

June 1, 2023 | Georgianna Shea |

Unlock Compliance Excellence: Harness the Power of an SBOM to Conquer Import and Export Controls, Including OFAC Regulations.

Last month I wrote about using a Software Bill of Material (SBOM) as a valuable tool for managing cybersecurity risk. This month I am expanding that conversation from cybersecurity risk to legal trouble....

May 18, 2023 | Georgianna Shea, Logan Weber

Four Steps to Mix SBOMs—Softwares’ Recipe—Into Risk Management

Software bills of materials, the ingredient lists for software, are important elements to companies’ cybersecurity strategies, but only if they use SBOMs effectively to manage risk.

October 24, 2022 | Georgianna Shea, Annie Fixler

‘SBOM’ disclosure rules loom for federal software procurement

The Software Bill of Materials, or SBOM, disclosure requirement is coming for federal agencies and their contractors. Are managers and executives ready? An SBOM is a formal, machine-readable inventory...

July 22, 2022 | Annie Fixler, Erik Thomas

Cyber Vulnerabilities in Medical Devices Put Patients at Risk

The Food and Drug Administration (FDA) closed the public comment period earlier this month on draft cybersecurity guidance for new medical devices after receiving more than a thousand comments from patients,...

June 24, 2022 | Georgianna Shea |

A Tool to Manage Cyber Risk: SBOMs and Security Through Transparency

October 29, 2021 | Trevor Logan |

Russian Hackers Continue Targeting the Software Supply Chain

The Russian state-sponsored hacker group responsible for last year’s massive SolarWinds breach has continued targeting managed service providers (MSPs) in an effort to piggyback into other victim networks,...

September 29, 2021 | Georgianna Shea |

A Software Bill of Materials Is Critical for Comprehensive Risk Management