PodcastProduct Security

When VEX Becomes a Bureaucratic Shield

Your SBOM is probably useless, and it is time we talked about why.

Cybersecurity Under Pressure podcast artworkPodcast episode
Episode brief
Listen here

Listen to the full episode.

What this episode examines

Your SBOM is probably useless, and it is time we talked about why.

In this episode, we look past the hype of vulnerability scanning to the uncomfortable reality of the software-defined vehicle. We walk through how suppliers are using VEX as a bureaucratic shield to dodge patches and why your security program is likely just a mountain of expensive noise.

We argue that if you are not prepared to challenge a supplier's claim with technical evidence, you are not doing security—you are just doing paperwork. This conversation is about moving from a flood of findings to actual, defensible risk management that protects the driver, not just the budget.

Subscribe and share this with a security lead who is tired of chasing ghosts in their supply chain.

Read the technical analysis

The companion Analysis develops the sourced technical argument, trust boundary and operational decision in a durable written reference.

Related analysisA VEX Statement Is a Claim That Needs EvidenceRead analysis →