Podcast
Watch Now: Understanding SBOMs with Thomas Pace of NetRise

If you care about nutrition, you check the ingredients of your food. If you care about your IT infrastructure, you check the Software Bill of Materials (SBOM) of the tech. At least that’s the future that Thomas Pace hopes for. Right now, SBOMs aren’t super common and software transparency is very low. Thomas walks us through what should be in an SBOM, who in an organization should care about it, and how it can be used for vulnerability management and incident response. He also talks about how wider demand for SBOMs could lead to a future of higher-quality software and more robust cybersecurity.
Key Takeaways
SBOM = “ingredients list” for software:
The episode frames an SBOM as a complete inventory of what’s inside a software product—aiming for everything that makes it up , not just a short list of dependencies.
Don’t ignore “known unknowns”:
A major point is that SBOMs should also document components you can see but can’t confidently identify (“known unknowns”), because otherwise you lose the ability to track and respond if one of those pieces becomes risky or compromised.
Operational value: vuln management + incident response:
The discussion links SBOMs to practical workflows while noting that wider demand for SBOMs could push the market toward better software quality and stronger security.
Stay up to date with the news
Sign up to get our free insights delivered to your inbox.
You might also like
Learn how we helped the customers to reach the next level





