BlueVoyant adds SBOM to its cyber risk management solution (Image Credit: behnam-norouzi-eDUKZFYY1K4-unsplash)BlueVoyant has added Software Bill of Materials (SBOM) capabilities to its third-party cyber risk management solution. It will allow customers to now import SBOM data from software vendors. The solution is part of BlueVoyant’s partnership with Manifest.

Joel Milinoff, Global Head of Supply Chain Defence, BlueVoyant (Image Credit: LinkedIn)
Joel Milinoff, Global Head of Supply Chain Defence, BlueVoyant

Joel Molinoff, global head of Supply Chain Defence at BlueVoyant, said, “Organisations in the private and public sectors are realising that SBOM visibility is a crucial part of a proactive third-party cyber risk management programme.

“By enhancing BlueVoyant’s Supply Chain Defence with Manifest’s SBOM capabilities, our clients are expanding their risk visibility deeper into the software supply chain and ensuring continuous monitoring and remediation of critical threats.”

Why is BlueVoyant adding SBOM to its risk management tools?

According to the Open Source Software Risk Analysis (OSSRA) Report, 85% of applications contain at least one software vulnerability. That is likely to be an underestimate.

The growth in the usage of open source software has been significant over recent years. Developers use it to speed up the creation of corporate software and to reduce the costs of coding. After all, why reinvent the wheel when someone else has already done so.

The problem this creates is that few developers document where the code comes from in terms of the library, API or even just the open source project name and version. It results in unpatched vulnerabilities in the source code going undetected. BlueVoyant is removing that risk with this partnership with Manifest.

They can import the SBOM for the commercial software they use and the software they create. That can then be compared to known vulnerabilities. That will enable them to identify what needs patching and determine how urgent that patching is.

BlueVoyant lists four key benefits of using SBOM for third-party risk. They are:

  • Vendor risk management: Automatically solicit SBOMs from vendors, see intuitive risk levels for vendor products, and incorporate them into comprehensive third-party cyber risk management
  • Smarter vulnerability management: Prioritise vulnerabilities quickly, and triage issues to reduce false positives and avoid unnecessary mitigation work
  • Open Source Software (OSS) risk management: Create an enterprise-wide inventory of OSS across first and third-party products, and scan OSS repositories to assess risk before implementing them.
  • Simplified compliance: Easily demonstrate compliance and provide evidence for international regulations and standards such as R155, Executive Order 14028, Section 524B, the European Cyber Resilience Act, and the EU’s NIS2 and DORA.

Enterprise Times: What does this mean?

This is an overdue announcement from BlueVoyant. The lack of visibility of open-source code, APIs and other libraries and the risk it creates is well accepted. Other vendors with risk solutions, such as Qualys, already have solutions in this space. Manifest strengthens BlueVoyant’s portfolio, and this will be welcomed by customers.

This will also play well with BlueVoyant’s US government and large enterprise customers. US Executive Order 14028 requires vendors to submit SBOMs as part of any government contract. BlueVoyant’s customers can now take advantage of those SBOMs as part of their risk management programmes.

Previous articleSecurity news from the week beginning June 2nd 2025
Next articleBreaking Through: How Mid-Sized Staffing Firms Can Overcome Growth Plateaus
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here