> Markdown version of [/events/world-congress-2025/sessions/876-better-safe-than](https://www.wearedevelopers.com/events/world-congress-2025/sessions/876-better-safe-than). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Better Safe Than Sorry: Preparing for the Next Supply Chain Attack with SBOMs - **Date:** Friday, Jul 11, 2025 - **Time:** 14:40–14:50 (10 min) - **Room:** Airstream 1 - **Event:** World Congress 2025 - **Tags:** ai, cybersecurity, llms ## Description Software supply chains are prime targets for cyberattacks, as seen in incidents like Log4J, SolarWinds, and NotPetya, where vulnerabilities in widely used components caused global disruptions. This talk explores how Software Bill of Materials (SBOM) serves as a critical tool in identifying and mitigating security risks across the software lifecycle. By providing transparency into the components of your software, SBOMs enable faster detection and response to emerging threats. We will cover what SBOMs are, their growing importance in cybersecurity, and how they support regulatory compliance and security frameworks. Additionally, we'll discuss how integrating SBOMs into your DevSecOps pipeline can streamline vulnerability management, reduce response times, and enhance overall software supply chain security. Whether you’re in IT security, software development, or leading strategic initiatives, this talk will offer actionable insights to help you stay ahead of the next supply chain attack. ## Speaker ### [Julia Gätjens](https://www.wearedevelopers.com/@julia-gatjens) Solutions Architect @GitLab ## Related talks at this congress - [Supply Chain Security and the Real World: Lessons From Incidents](https://www.wearedevelopers.com/events/world-congress-2025/sessions/685-supply-chain) — Adrian Mouat - [Code Red: When Your Tools Turn Against You ](https://www.wearedevelopers.com/events/world-congress-2025/sessions/510-code-red-when-your) — Aaron Bray, Julian Totzek-Hallhuber - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/events/world-congress-2025/sessions/844-why-security-first) — Michael Wildpaner - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/events/world-congress-2025/sessions/570-get-security-done) — Mia Neethling