Back to timeline



Beyond Dependencies: The Real Picture of Software Supply Chain Security

Supply Chain Microsummit @ BlackHat USA 2025

2025/08/07

Presentation

Beyond Dependencies: The Real Picture of Software Supply Chain Security

Anant Shrivastava | Founder, Cyfinoid Research

Date: Thursday, August 7 | 10:50am-11:30am ( Business Hall Theater C )

Format: 40-Minute Summit Session

Track: Supply Chain Micro Summit

Software Supply Chain Security has been a buzzword for the past few years, but as the initial hype settles, it’s time to ask: what’s actually working—and what’s being overlooked?

In response to rising threats, many organizations have rushed to implement SCA tools or generate SBOMs and called it a day. But security is rarely that simple. Is generating a BOM of your code dependencies truly enough? What about the unsigned binaries your devs download during prototyping, the Docker images pulled from random GitHub issues, or the low-friction APIs that newer technologies—like AI platforms—introduce into trusted environments?

This talk takes a 360-degree view of supply chain security—beyond just dependencies—to highlight the broader risks involved in how modern software is developed, integrated, deployed, and consumed. We’ll explore:

Whether you’re building software or just using it, this session will challenge assumptions, offer practical mental models, and leave you with a grounded understanding of where your supply chain security posture actually stands—and where the gaps may lie.