All work
Securing the Supply Chain
Hardware, software and everything in between: where most supply-chain risk actually lives.
Supply-chain security is usually told as two separate industries. Silicon on one side. Repositories on the other. The incidents happen in the seam: firmware, build systems, signed artifacts, the vendor who ships a library nobody owns.
This essay walks that seam without the costume of a threat report. It is a positioning piece for buyers who are tired of being handed a bill of materials and told that the paperwork is the control.
The through-line is operational. If you cannot explain the path from hardware root to running workload, you do not have a supply chain. You have a hope.
A bill of materials is not a control. It is a map. Someone still has to walk it.

