#1682164: Supply Chain Cybersecurity Forum - 26 Jun 2025

Description: Beyond the Perimeter: Securing What You Don’t Control

As software and hardware supply chains grow more complex and globally interconnected, they have also become prime targets for attackers. From deeply embedded vulnerabilities in third-party components to subtle software compromises and counterfeit hardware, today’s supply chain threats are stealthy, sophisticated, and increasingly difficult to detect.

Join us for a focused 3-hour forum where experts and practitioners tackle one of cybersecurity’s most pressing challenges: how to secure the digital supply chain from code to component.

This forum brings together offensive and defensive insights from the field — grounded in hands-on experience — to equip you with practical strategies, tools, and frameworks to:

Identify and mitigate hidden risks introduced by third-party software and hardware
Conduct technical product security testing and risk analysis at scale
Perform static firmware analysis and deconstruct proprietary protocols
Evaluate vendors and technologies using SBOMs and modern risk methodologies
Build a mature, resilient supply chain risk management program
Engage with key stakeholders to align procurement, contracting, and security goals
Whether you’re in the trenches dissecting firmware or leading enterprise risk discussions with executives and suppliers, this forum is designed to help you enhance your supply chain security.

Agenda

9:00 AM – 9:10 AM - Welcome & Opening Remarks Doug McKee & Tony Turner

9:10 AM – 9:45 AM - Know Your AI: Scanning the Hidden Layers of Open Source Models with w/ Kasimir Schulz

9:45 AM – 10:20 AM - Agentic GRC in Practice w/ Cole Kennedy

10:20 AM – 10:30 AM - Break

10:30 AM – 11:05 AM - Title TBD w/ Steve Springett

11:05 AM – 11:40 AM - Unseen and Unsecured: Firmware Attacks Expanding the Enterprise Attack Surface w/ Paul Asadoorian

11:40 AM – 12:00 PM - Closing Remarks

Who Should Attend:
Security engineers, product security professionals, PSIRT teams, risk managers, incident responders, SOC analysts, and cybersecurity leaders responsible for securing their organization’s technology stack and third-party ecosystems.
More info: https://www.sans.org/webcasts/supply-chain-cybersecurity-forum/?utm_medium=Email&utm_source=HL-NA&utm_content=1479517_Supply_Chain_Cyber_Forum_Button&utm_campaign=SP_SupplyChain_2025&utm_rdetail=Global&utm_goal=Orders&utm_type=Global_Campaign&is=f98dd75aa766de9d5bc556ba99a6b3fa514ef1f5c1e897a93369d6cd82e77c7d

Date added May 20, 2025, 10:08 a.m.
Source SANS
Subjects
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Retail / Supply Chain Industry News
  • SANS
Venue June 26, 2025, midnight - June 26, 2025, midnight