# How Fortune 500s Are Using Procurement to Manage Vendor Software Supply Chain Security Page: https://stenobird.com/podcast/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873/how-fortune-500s-are-using-procurement-to-manage-vendor-software-supply-chain-security Text version: https://stenobird.com/podcast/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873/how-fortune-500s-are-using-procurement-to-manage-vendor-software-supply-chain-security.md Podcast: [Enterprise Tech with Fexingo: Fortune 500 Software, Procurement, and Large-Account Sales](https://stenobird.com/podcast/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873) Published: 2026-06-18T08:30:25+00:00 Episode link: https://audio.fexingo.com/business/enterprise-tech/episode-0058.mp3 Audio file: https://audio.fexingo.com/business/enterprise-tech/episode-0058.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873/episodes/how-fortune-500s-are-using-procurement-to-manage-vendor-software-supply-chain-security Duration seconds: 633 ## Resource In episode 58 of Enterprise Tech with Fexingo, Lucas and Luna dive into a critical but often overlooked area of enterprise software procurement: vendor software supply chain security. They explore how Fortune 500 companies are now requiring vendors to provide a software bill of materials, or SBOM, as part of the procurement process. Lucas explains why the SolarWinds attack was a turning point, and shares how a single vulnerability in a third-party component can cascade through the entire supply chain. They discuss real-world examples like the Log4j vulnerability and how it reshaped procurement checklists, including contractual clauses for patching SLAs. Luna challenges whether smaller vendors can realistically comply, and Lucas outlines the tiered approach large buyers are taking. The episode also touches on the rise of vulnerability disclosure requirements and how procurement teams are now coordinating with CISOs earlier in the vendor evaluation process. #SoftwareSupplyChainSecurity #SBOM #Procurement #Fortune500 #VendorRisk #SolarWinds #Log4j #CISO #EnterpriseTech #BusinessAndTechnology #VulnerabilityManagement #ThirdPartyRisk #Compliance #SecurityClauses #PatchManagement #FexingoBusiness #BusinessPodcast #EnterpriseSoftware Keep every episode free: buymeacoffee.com/fexingo ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873/episodes/how-fortune-500s-are-using-procurement-to-manage-vendor-software-supply-chain-security/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/enterprise-tech-with-fexingo-fortune-500-software-procurement-and-large-account-sales-7871873/how-fortune-500s-are-using-procurement-to-manage-vendor-software-supply-chain-security.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.