Protecting Customers Through Smarter OSS Management @FIRSTdotorg
Protecting Customers Through Smarter OSS Management  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 4 hours ago
Lisa Bradley (Dell Technologies, US), Patricia Tarro (Dell Technologies, US)

As organizations increasingly rely on Open Source Software (OSS) to drive innovation, strong security practices are critical to safeguarding customers. This session provides a practical roadmap for building a mature OSS security strategy — from defining trusted OSS and maintaining secure repositories to generating Software Bills of Materials (SBOMs) for visibility, dependency tracking, incident response, and end‑of‑life planning.

Drawing on real‑world lessons from Dell Technologies’ OSS security journey, we’ll share challenges faced, strategies implemented, and actionable insights for creating a scalable, resilient framework. Attendees will learn how to select trustworthy OSS, proactively address vulnerabilities, and stay current with secure versions — transforming OSS management from a compliance task into a strategic advantage.

Whether you’re starting your OSS program or looking to strengthen it, this talk equips you with the tools to protect customers and secure your open‑source future.

---

Dr. Lisa Bradley is a distinguished cybersecurity expert and visionary leader, currently serving as the Senior Director of Product & Application Security at Dell Technologies. With over two decades of experience in enterprise-class engineering, including 13 years in product security leadership, Dr. Bradley has established herself as a trailblazer in the field of cybersecurity and vulnerability management.

In her current role, she leads Dell’s Product Security Remediation efforts, driving initiatives such as Vulnerability Response/PSIRT, post-GA security findings remediation, the Bug Bounty Program, Product 360 Risk, and Dependency Management. She also plays a pivotal role in supporting Dell’s Software Bill of Materials (SBOM) initiative, ensuring transparency and security across the product lifecycle.

Her commitment to advancing the cybersecurity industry extends beyond her corporate responsibilities. She is a frequent speaker at industry events and podcasts, and a proud co-author of the FIRST PSIRT Services Framework, contributing to global standards in incident response. Outside of her professional endeavors, Dr. Bradley enjoys spending quality time with her three children and friends. Her unwavering dedication to cybersecurity, combined with her leadership and advocacy, continues to inspire innovation and build trust in the ever-evolving landscape of technology and cyber defense.

Patricia Tarro is the Product Manager for Dependency Management at Dell Technologies. In this role, she is responsible for building and maintaining a platform that modernizes and adds efficiency to existing Dell processes related to the assessment of internal and external component security risk in product releases. Tricia has over 30 years of Information Technology experience, having spent the most recent years in Dell’s Product and Applications Security team.

In 2020, she earned a master’s degree in Administration of Justice and Homeland Security with a concentration in Cybersecurity and Intelligence. Currently she is pursuing a doctoral degree in Homeland Security at St. John’s University in Queens, NY. Her research focus is software supply chain security. Tricia is the Branch Assistant for Supply Chain Risk Management in the U.S. Coast Guard Auxiliary Cybersecurity Directorate.
Protecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT OrganizationsMonday Keynote: Perseverance, Growth and Success. The Sunburst Story from the CISO perspective.Evaluating Threat Intelligence Through VelocitySaving Ourselves the ID Headache: How Purls Can Work for Models and DatasetsImproving Security Across Nations with FIRST: Sneha Rangari, FIRSTCON26 SpeakerNational CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination CasesFrom Roadmap to Results: Measuring CWE Adoption to Enable Prevention
FIRST |

Protecting Customers Through Smarter OSS Management

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER