ONEKEY WEBINAR: From Firmware to SBOM: Building Evidence-Based Software Inventories

READY TO UPGRADE YOUR RISK MANAGEMENT?
Make cybersecurity and compliance efficient and effective with ONEKEY.
.avif)
Tanja Sommer
tanja.sommer@onekey.com
Join us for an exclusive ONEKEY webinar on September 10, 2026, at 11:00 a.m. (CEST)!
What if the firmware is all you have? Learn how binary analysis can help identify software components directly from firmware and turn the results into an evidence-based, actionable SBOM.
From Firmware to SBOM: Building Evidence-Based Software Inventories
Having an SBOM is only useful if the information inside it is accurate, relevant, and suitable for the task at hand.
In embedded software environments, manufacturers and resellers do not always receive a complete SBOM from their suppliers. In some cases, the only artifact available is the firmware itself.
This creates a practical challenge: How can you identify the software components in the final firmware and build an SBOM that is useful internally and can also be shared with customers, partners, and other stakeholders?
This is where binary analysis can help.
By analyzing the firmware itself, organizations can identify software components, build a software inventory, review the evidence behind the identified components, and create an SBOM that can support further product security and compliance processes.
What You’ll Learn
In this 45-minute webinar, we focus on the firmware-only scenario and show how binary analysis can help identify software components, build a usable software inventory, and review and enrich the available component information.
You’ll learn:
- How to generate an SBOM when only the firmware binary is available
- How binary analysis can identify software components in embedded firmware
- How to review component evidence and improve the resulting software inventory
- How to turn firmware analysis results into a usable and actionable SBOM
- How to export and share the resulting SBOM using standard formats such as CycloneDX and SPDX
- How the complete process works in practice with a live demo of the ONEKEY platform
The session will include a live demonstration of the ONEKEY platform, showing the complete journey from firmware analysis to component visibility and SBOM export.
Who Should Attend?
This webinar is designed for professionals working in:
- Product Cybersecurity
- Product Security
- Software Supply Chain Security
- SBOM Management
- Vulnerability Management
- Compliance
- Embedded Software Development
Whether you already work with SBOMs or are facing the challenge of gaining visibility into products for which no complete supplier SBOM is available, this webinar provides a practical look at how firmware analysis can help build reliable software inventories.
Go Beyond SBOM Generation
A missing supplier SBOM does not have to be a dead end.
Join us on September 10 and see how you can go from firmware binaries to component visibility and an evidence-based software inventory that you can actually use.
Can’t join live? Register anyway and you’ll receive the on-demand recording after the webinar.
Meet us there

SPEAKERS
ON-SITE TEAM

Jen Chih-lo
Jen-Chih has years of experience with customers within semi-conductor industry and industrial automation specifically in East Asia. His expertise helps customer understanding how to increase ROI by reducing repetitive monitoring tasks.

Tushar Bhanage
Tushar has several years of experience in product marketing across the automotive, manufacturing, and IoT sectors. At ONEKEY, he helps customers navigate complex topics such as firmware security, SBOM, and vulnerability management, translating technical capabilities into clear business value.
RELATED Events

ONEKEY Webinar: PSIRT – Start Small, but Start | CRA Implications on Notification Obligations
Prepare for CRA reporting obligations from 11. 09. 2026. Learn how to structure & mature your PSIRT for effective vulnerability handling. Register Now!
About Onekey
ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann
Senior Marketing Manager
sara.fortmann@onekey.com
euromarcom public relations GmbH
team@euromarcom.de
Ready to automate your Product Cybersecurity & Compliance?
Make cybersecurity and compliance efficient and effective with ONEKEY.


