Matt Linton 
Professional: DFIR / Incident Management lead
Volunteer: Search & Rescue specialist, CERT trainer, Parrot handler
Amateur: Cello & Guitar
(was: 0xMatt on twitter)
Given the big PyPI, Node and Github supply chain attacks in the last month or two I am *very* curious:
Orgs who have walked far down the SBOM path - are you feeling pretty good about that right now? Is it genuinely helping you respond to supply chain attacks?
Every time I get into a debate about Coordinated Vulnerability Disclosure and am trying to make someone understand a particular opinion that I strongly hold, I know I can look and find a video of a talk or blog post by @k8em0@infosec.exchange which makes that point more firmly and eloquently and with more data than I could possibly do so.
I really appreciate that, and y'all should too.