clic para entrar
← back to blog
Software

Software supply chain security

Software supply chain security

Almost no software is written entirely from scratch. When your company uses a system —whether a billing platform, your online store, or a custom app— underneath there are dozens or hundreds of third-party components: libraries, frameworks, and packages that other people maintain. That way of working is healthy and speeds everything up, but it also means that the security of your software depends, in part, on pieces you didn’t write. In 2021, after several high-profile incidents that reached companies through those shared components, the topic jumped to the forefront, and with it a simple but powerful idea: the SBOM, or your software’s «list of ingredients».

An SBOM (Software Bill of Materials) is exactly that, an inventory of everything that makes up an application: which dependencies it uses, in what version, and where they come from. It sounds technical, but the analogy is everyday. Just as a nutrition label tells you what a product is made of, an SBOM tells you what your system is made of. And that visibility completely changes your ability to react: when a vulnerability appears in a well-known component, the question is no longer «does it affect us?» but «which of our systems has it, and in what version?».

Why this matters to a small business too

It’s easy to think that supply chain security is a topic only for large corporations. It isn’t. Small businesses tend to depend on MORE external software, not less: plugins, templates, integrations, and libraries installed long ago that almost no one has looked at again. The risk isn’t in using them —that’s normal and recommended—, but in not knowing what’s being used.

When you lack clarity about your components, a small problem becomes a big one:

  • You don’t know if it affects you. A security alert comes out and no one can confirm whether your system includes it.
  • You update blindly. Without an inventory, every update is a gamble: you don’t know what might break.
  • You carry «dead weight». Old dependencies that no one maintains anymore stay there, adding risk without contributing value.
  • You depend on one person’s memory. If that person leaves, the knowledge of how your system is put together leaves too.
Illustration of a list of ingredients or inventory of software components
An SBOM works like your software's ingredient label: it tells you what it's made of.

What your company gains by knowing its «ingredients»

Having visibility into your components isn’t an end in itself; it’s the foundation for making decisions with reliable information. With a clear inventory you can prioritize what to update first, plan maintenance without scares, and respond quickly when a problem arises. Instead of putting out fires, you work in an orderly way.

You can’t protect what you don’t know you have; the first step of security is visibility.

Moreover, this clarity gives you independence. When you know exactly what your software is made of, you stop being tied to a single provider or a single person who «knows how it works». You keep your data, your processes, and your history, and you can evolve the system with peace of mind.

How we approach it in custom solutions

In custom software, taking care of the supply chain is part of a job well done, not an extra. It means choosing components with a good reputation and active maintenance, keeping a record of what’s used and why, and establishing a healthy update rhythm. The goal isn’t to accumulate security tools, but to build on foundations you can understand and sustain over time.

The important thing is to start with something concrete and measurable: you don’t need to solve everything at once. Just by inventorying your most critical systems and reviewing their components you take an enormous leap over having no visibility at all.

Put your components in order

If you want to organize your software’s «list of ingredients», these first steps are very accessible:

  • Make an inventory of your critical systems. Start with what would hurt most to lose: billing, sales, daily operations.
  • Ask for the SBOM. From your team or provider, request the list of components and versions of those systems. If it doesn’t exist, that’s a sign it needs to be created.
  • Identify what no one maintains anymore. Flag old or abandoned dependencies to plan their replacement.
  • Define an update rhythm. Better a few orderly, tested updates than many improvised changes.
  • Document. Have the knowledge live in a record, not just in one person’s head.

Knowing what your software is made of is, in the end, a decision about peace of mind. At Normandia Web we build and maintain custom systems with that list of ingredients clear from the design stage, so you always know what you have installed and why. If you’d like, we can start with an inventory of your most critical systems and plan the next steps with you.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →