• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Transparent Software Supply Chains Will Usher in Healthcare Cyber Quality
HEALTHCARE

Transparent Software Supply Chains Will Usher in Healthcare Cyber Quality

February 5, 2024
JC Herz, Senior Vice President, Cyber Supply Chain, Exiger and Shannon Lantzy, President, Shannon Lantzy LLC

Exiger-Herz.pngExiger-Lantzy.pngAnalyst Insight: Now that software bills of materials (SBOMs) are an FDA requirement, the medical device market can achieve software supply chain transparency, which means more and better information on cybersecurity risk. As SBOM analysis yields business-relevant risk information, customers will use it to make more informed decisions about what to buy and how to price risk transfers. This allows resilience to be priced into the product. 

As transparency illuminates the value of risk reduction, suppliers also can compete on software quality, and can quantify the value of maintenance packages that keep software risk at acceptable levels. While customers and regulators often talk about holding suppliers “accountable,” many of those same customers have historically been unwilling to pay a premium for higher levels of cybersecurity quality. SBOMs add a dimension to the trade space between cost, functionality, and quality — trading security for affordability is no longer an invisible choice.

Now, customers may be willing to cede control to increase the affordability of security maintenance. For example, it used to be standard to require human “sneakernet” service calls to update medical device firmware in hospitals. But now hospitals may allow medtech manufacturers direct connectivity to devices in exchange for over-the-air patches.

In the absence of transparency, security is a cost center which rational actors will minimize. As a mechanism for transparency, SBOMs create a more informed mode of contract negotiation, where customers can be explicit about expected cybersecurity quality, and suppliers can gauge security return on investment both in the absolute and relative to competitors. 

Software quality degrades over time, new vulnerabilities must be patched, and maintenance should be as frequent as possible to keep weaknesses from entering the healthcare software ecosystem. As SBOMs allow customers to gauge both quality and risk, the best companies aim to demonstrate high-quality software and will insist on subscription or other frequent update models (heretofore rare in medtech). 

Leading companies will implement software development processes that prevent vulnerabilities from ever reaching the market, and they’ll use their SBOMs to prove it. Customers and suppliers will gravitate toward using leading risk indicators that allow them to remediate risk on a non-emergency basis, in advance of lagging risk indicators like common vulnerabilities and exposures (CVEs). 

We’ll also see medtech compete on software assurance, with claims that their products are resilient in a supply chain attack — because now they’ll have an unbiased market mechanism to demonstrate those claims. As a more transparent marketplace matures, the financial value of higher quality can be audited over time. 

Suppliers and customers will shift from a “once-and-done” model for vendor qualification and product approval to an “always-on” assessment that keeps software within acceptable thresholds on a continuous basis. Monitoring becomes the norm, and contractual service-level agreements (SLAs) can be defined based on response times that are quantifiable and can be associated with remedies, including financial. These terms and conditions, like all contractual agreements, are negotiations between suppliers and customers, and the relative leverage of those entities will dictate where negotiations come to rest.  

Outlook: How fast we see these changes happening will depend on the market’s ability to rapidly intake, process and make use of the information in SBOMs. This includes cybersecurity and supply chain technology vendors who help the healthcare industry derive insight from SBOMs. This nascent field is poised for growth. 

Resource Link:

www.exiger.com

    RELATED CONTENT

    RELATED VIDEOS

    Logistics Technology Cloud & On-Demand Systems Data Management (Big Data/IoT/Blockchain) Global Trade Management Supply Chain Visibility Business Strategy Alignment Sourcing/Procurement/SRM Supply Chain Security & Risk Mgmt
    • Related Articles

      How Redesigning Healthcare Supply Chains Will Drive Value-Based Care

      How Ethical Supply Chains Will Survive the Pandemic

      IDC Predicts Half of Worldwide Supply Chains Will Use AI by 2020

    • Related Directories

      ProcureAbility

    JC Herz, Senior Vice President, Cyber Supply Chain, Exiger

    More from this author
    Shannon Lantzy, President, Shannon Lantzy LLC

    More from this author

    Subscribe to our Daily Newsletter!

    Timely, incisive articles delivered directly to your inbox.

    Featured Product

    Popular Stories

    • GIST-webinar-DecisionPoint.png

      From Fragmented Tools to Unified Workflows: How to Transform Field Operations

    • A LARGE AIRCRAFT BEARING THE LUFTHANSA LOG FLIES ABOVE FLUFFLY CLOUDS

      787-9 Dreamliner’s Nose Collapses on Runway

      Air Cargo
    • Close-up hands of unrecognizable man holding and using smartphone standing on city street.

      Five Supply Chain Security Risks Hiding Inside Your Mobile Apps

      Supply Chain Visibility
    • A KIT KAT CHOCOLATE BAR IS PARTIALLY UNWRAPPED.

      The Gap Between Tracking and Execution

      Technology
    • AN AERIAL VIEW OF A LARGE SHIP APPROACHING A LOCK SYSTEM ON A CANAL

      Panama Canal Considers Water Limits to Thwart El Niño Impacts

      Global Gateways

    Digital Edition

    2026 esg cover main scb q2 2026 cover

    SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

    VIEW THE LATEST ISSUE

    Case Studies

    • Recycled Tagging Fasteners: Small Changes Make a Big Impact

    • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

      Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

    • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

      Moving Robots Site-to-Site

    • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

    • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

    Visit Our Sponsors

    4flow Arkieva Blue Yonder
    Carton Cloud CoEnterprise Dassault
    Duravant E2Open General Logistics Systems
    Hy-Tek iGPS Korber
    Lyngsoe Procurability Quinyx
    SAP Sikick Systech
    S&P Global Mobility TADA TransImpact
    US Bank Werner Enterprises WSI
    • More From SCB
      • Featured Content
      • Video Library
      • Think Tank Blog
      • SupplyChainBrain Podcast
      • Whitepapers
      • On-Demand Webinars
      • Upcoming Webinars
    • Digital Offerings
      • Digital Issue
      • Subscribe
      • Manage Email Preferences
      • Newsletters
    • Resources
      • Events Calendar
      • 2026 Event Coverage
      • SCB's Great Supply Chain Partners
      • Supplier Directory
      • Case Study Showcase
      • Supply Chain Innovation Awards
      • 100 Great Partners Form
    • SCB Corporate
      • Advertise on SCB.COM
      • About Us
      • Privacy Policy
      • Contact Us
      • Data Sharing Opt-Out

    All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

    Design, CMS, Hosting & Web Development :: ePublishing