Elbsides 2025

SBOMs – A Tragicomedy in Three Acts
2025-06-13 , Elbkuppel

Increasing supply chain attacks have highlighted the need for greater transparency in software. As a result, more regulations now require software vendors to provide SBOMs (Software Bills of Materials) for their products. In this talk, we’ll take you on a journey into the world of CISOs and managers who hope that SBOMs can solve many problems in the areas of cybersecurity and cyber resilience. Our brave architect will address questions such as: Do SBOMs actually make products more secure? Can they help mitigate situations like Log4Shell? What exactly do they need to contain? Along the way, they’ll debunk inflated expectations and outline the prerequisites for using SBOMs effectively.

Lukas Mika is the Lead Cyber Architect for Application Security at Maersk. He focuses on the strategic vision and architecture of a secure software supply chain that is seamlessly integrated into the company’s comprehensive secure software development lifecycle. With his extensive experience in solution development and enterprise architecture, as well as his passion for application security, he is deeply committed to the principles of “Secure by Design, by Default, and through Automation.”

Jasmin Mair is the Head of Application Security at E.ON Digital Technology. Prior to this, she held the role of Global Product Security Manager at Leica Microsystems and led the Data & Application Security Competency at IBM Security. She brings extensive experience in both application and product security. Throughout her career, she has collaborated with diverse stakeholders across multiple industries to implement security programs, foster DevSecOps practices, and strengthen the security of the software development lifecycle (SDLC). Her true passion lies in connecting interdisciplinary teams and driving more effective collaboration between security, development, and product management.