Back to Schedule

From beer to cyber security: How secured supply chains create more resilient products

Christoph Raaflaub

Raphaela Seeger

11:30 - 12:15

Uptown

Over the past few years, security efforts have focused primarily on cloud infrastructure and on preventing or remediating misconfigurations. In modern software development, however, the security of container images is often treated as a secondary concern, with speed of development and convenience taking precedence. Existing components, from libraries to base images, are reused and sourced through complex and opaque supply chains. Following prominent security incidents such as Log4j and xz, supply chain security has increasingly moved into the spotlight. In 2025, supply chain failures ranked third in the OWASP Top 10 Critical Security Risks to Web Applications. Just as the brewing of beer relies on its ingredients (Purity Law), building software requires a similar commitment to integrity. We will find out the similarities together. In this session, we will explore solutions for making software supply chains more secure while simultaneously meeting the requirements of the EU’s Cyber Resilience Act (CRA). This also includes frameworks like "Supply-chain Levels for Software Artifacts" (SLSA).