Cyfinoid’s Shrivastava Calls for Greater Visibility Over Software Security Risks
Software supply chain security is all too often viewed through a narrow lens, focused mostly on code dependencies and SBOMs. But the devil remains in the details and can emerge from overlooked areas such as developer tools, browser extensions and cloud infrastructures, all of which play a role in how software is built, deployed and, in some cases, dismantled.
See Also: What Manufacturing Leaders Are Learning About Cloud Security – from Google’s Frontline
Yet most organizations lack overall visibility into these areas, said Anant Shrivastava, founder and chief researcher at Cyfinoid. While SBOMs provide a clear starting point, they can fail to account for deeper, interconnected systems or third-party services that are part of a company’s software lifecycle.
“SBOM is not a security solution. SBOM is an inventory. As an inventory, how can we leverage the inventory to solve problems, which are not just security-based?” Shrivastava said.
In this video interview with Information Security Media Group at Black Hat USA 2025, Shrivastava also discussed:
- Broader software supply chain risks;
- Challenges with tracking and software visibility;
- Tools to improve awareness and management.
Shrivastava is a highly experienced information security professional with over 15 years of corporate experience. He is a frequent speaker and trainer at international conferences, and is the founder and chief researcher at Cyfinoid Research.