Say Easy, Do Hard – AI Governance in the Supply Chain – Nick Mistry, Richard Bird – BSW #407
Recent findings of AI ecosystem insecurities and attacks show the importance of needing AI governance in the supply chain. And this supply chain is rapidly expanding to include not only open-source software but also collaborative platforms where custom models, agents, prompts, and other AI resources are used. And with this expansion of third-party AI component and services use comes an expanded security threat often not included in traditional supply chain management processes. It's time to update our supply chain management process to include AI governance. Easier said than done.
In this Say Easy, Do Hard segment, we invite three CISOs to discuss the challenges of AI and the supply chain, including:
- Data privacy concerns
- Flaws and malicious code in AI dependencies
- Lack of security tools to test for AI
- Vibe coding risks
and more. But we also do the hard part, by discussing the changes needed to your supply chain management process to address these concerns.
With over 20 years of experience in the development and implementation of new and emerging technology solutions, Nick Mistry has experience leading cloud security, application security, and cyber initiatives at multinational corporations and the government. Also, Nick led technical architecture efforts to implement the US Federal Government Data Consolidation program, FedRAMP, and HealthCare.gov “fix it” initiatives supporting DoD, GSA, and CMS, respectively. Nick is the recipient of the Ken Ernst North America Innovators Award.
Richard Bird is the Chief Security Officer for Singulr AI, an AI security and governance solution, and a six-time C-level executive in the corporate and startup worlds. Internationally known for his observations on AI security, data privacy, digital consumer rights, and identity security. Richard currently focuses his attention on the operationalization of AI and how we can secure, govern and control the use of AI effectively. He is the author of Famous With 12 People: A Career Guide on Becoming an Internationally Recognized Expert in Something Nobody Cares About, and Richard is frequently quoted on cybersecurity topics and headline news events in the media and has been featured by ISMG, The Wall Street Journal, CNBC, Bloomberg, Financial Times, Business Insider, CNN, Dark Reading, and TechRepublic.








