Southern Company Builds SBOM for Electric Power Substation
ID: 999cd242-7f82-509f-a37c-d50328af44df
STIX ID: report--999cd242-7f82-509f-a37c-d50328af44df
Feed Name: Dark Reading
Date Published: 2024-03-06
Date Updated: 2026-04-21
Author: Kelly Jackson Higgins, Editor-in-Chief, Dark Reading
Southern Company presented a case study from S4x24 on building and validating SBOMs for an OT substation, detailing on-site asset inventory, challenges in acquiring SBOMs from 17 vendors, and verification that uncovered missing components and refined thousands of reported issues to a handful of truly exploitable vulnerabilities. The effort demonstrated security and operational value for NERC CIP compliance, vulnerability management, and patch prioritization, and revealed contractual and process gaps in SBOM sharing. Next steps include operationalizing the program and joining a DOE-funded initiative with Schneider Electric, MITRE, Ameren, EPRI, Scythe, and Finite State to automate inventory, SBOM collection, verification, and exploitability analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
