BSides Bristol 2024

Navigating the SBOM landscape: Formats, relevance, and tooling in 2024
08-30, 09:50–10:30 (Europe/Lisbon), Track 2

Discover the latest advancements in Software Bill of Materials (SBOMs), their critical relevance driven by the US executive order, and dive into key SBOM formats like SPDX and CycloneDX. Explore the current landscape of SBOM tooling and understand how to enhance software security and compliance.


Discover the transformative impact of Software Bill of Materials (SBOMs) in today's cybersecurity framework, propelled by the US executive order on enhancing national cybersecurity, along similar pushes the UK in Code of Practice for Software Vendors. This talk offers a deep dive into SBOMs, underscoring their necessity for software transparency and risk mitigation.

We will explore the primary SBOM formats, SPDX and CycloneDX, providing detailed insights into their features and benefits. Additionally, we will assess the current landscape of SBOM tools, showcasing the technologies that enable effective SBOM management and utilization.

This session will empower attendees with a thorough understanding of the significance of SBOMs, the intricacies of leading formats, and the state-of-the-art tools available. It is designed for developers, security professionals, and decision-makers committed to advancing software security and regulatory compliance through effective SBOM practices.

Viktor, a seasoned entrepreneur, initiated his journey in the business world during his college years. His first venture, YippieMove, emerged as a pioneering email migration service, setting the stage for his future successes. Demonstrating a keen sense for uncharted territories, Viktor then co-created Blotter, a productivity app for macOS that not only was bootstrapped but also climbed to the top 10 in the Mac App Store before its discontinuation.

Prior to the widespread adoption of remote work spurred by the COVID-19 pandemic, Viktor had already recognized the transformative potential of a decentralized workforce. He leveraged this insight to lead his early ventures, particularly Blotter, towards prosperity as bootstrapped operations, embracing remote-only models long before they became a global norm.

Following these successes, Viktor co-founded Screenly, where he currently leads as a visionary. Screenly, also a bootstrapped venture, was created with the ambition of developing the world’s first developer-friendly digital signage product. Under Viktor’s stewardship, the company has introduced revolutionary products like Anthias, the top-ranked open source digital signage solution, and Screenly’s flagship offering, which now powers over 10,000 screens globally. Viktor’s innovative mindset and relentless entrepreneurial spirit continue to propel the digital signage industry into the future.

Viktor is currently working on the SBOM management platform sbomify.

@vpetersson