Session 2.7a Expo Product Brief: Building Cyber Resilient Applications via SBOM Validation and Cross-domain Architecture
Tracks
ㅤ
| Wednesday, November 18, 2026 |
| 2:30 PM - 3:30 PM |
| Royal Theatre |
Sponsored by
Presentation Outline
The Australian Signals Directorate (ASD), in collaboration with its international partners, has updated its guidance on the minimum elements required within a Software Bill of Materials (SBOM). This guidance is particularly timely as software supply-chain compromises continue to expose vulnerabilities in third-party libraries, open-source packages and dependencies used across modern DevOps environments.
In this session, Adam Bradley, Solution Engineer at OPSWAT will share how organisations can scan source-code repositories, software dependencies and build artefacts while securely transferring pull requests, commits and approved software releases between environments operating at different security classifications. It will also explore how SBOM capabilities, automated security controls and cross-domain architectures can support a secure DevSecOps lifecycle.
Learning outcomes
Participants will gain an understanding of:
• Cybersecurity risks affecting software dependencies, libraries and packages
• Current guidance for defining the minimum elements of an SBOM
• How to generate, identify and validate SBOMs
• Security technologies used to create an inventory of software components, dependencies and packages
• Processes for identifying and remediating vulnerabilities during the DevSecOps lifecycle
• How to design a secure cross-domain architecture for software development and deployment
The attendees will gain practical guidance for strengthening the resilience, integrity, availability and security of critical applications and systems that support military operations.
Speaker
Mr Adam Bradley
Solutions Engineer
OPSWAT
ㅤ
Biography
Adam Bradley is a Solution Engineer at OPSWAT with more than 15 years of experience within the cybersecurity industry. He works with organisations operating critical infrastructure, sensitive networks and essential services to design resilient security architectures that protect the movement of data across IT, classified and operational technology environments. His expertise includes cyber resilience, exposure management, malware prevention, secure data transfer, software supply-chain security and cross-domain solutions. Adam holds the CISSP and CCSP certifications from ISC2, the SABSA Foundation certification in security architecture, and GIAC’s Cloud Security Automation certification.