Few people will know that Wendy Nather worked in Switzerland before she became one of the most influental CISOs in the world. Wendy is a voice of sense and reason in the industry. In her keynote at Swiss Cyber Storm, she will start with an overview of the problems around supply chain security. Afterwards, she will take a closer look at the troubles that one of the proposed solutions - a Software Bill of Materials - brings about: As we get better at collecting supply chain data, the challenge grows about how to manage it all. As an example, take the Software Bill of Materials (SBOM), which is finally gaining traction as a concept and practice. It’s clear that the potential volume of data generated by SBOMs needs to be standardized, distributed, and managed, ideally in machine-readable formats. But that’s only part of the battle: now organizations must create processes to make use of that data in business and security risk decisions. They can do this by taking lessons learned from threat intelligence and vulnerability management data. “Okay, somebody set us up the SBOM … now what?”