Thought Leadership  ·  Steve Weltman CISSP

Articles & Commentary

Practitioner perspectives on AI governance, SOC 2 compliance, software supply chain security, and the risks most organizations haven't mapped yet.

CSA Blog Forthcoming

Your AI Coding Agent Is Signing In As Tyler. Your SOC 2 Report Says Tyler Made 47 Changes on Tuesday. Tyler Was in Meetings.

AI coding agents operate under human credentials, receive goals without defined scope, and generate changes faster than any reviewer can meaningfully evaluate. All three breaks matter for SOC 2 CC8.1. Most organizations have closed none of them.

CSO Magazine Forthcoming

You Didn't Inherit the Software Supply Chain Problem. You Became It.

30% of data breaches now involve a third party. That figure has doubled year over year. If you build software that other organizations run, you are the third party. The EU Cyber Resilience Act makes that accountability concrete starting September 2026.

ISSA Journal Forthcoming

97% of Developers Use AI Tools. How Many Organizations Have a Policy That Covers It?

Nearly half of AI-generated code contains security flaws. 70% of organizations report that 40% or more of their code is now AI-generated. The SDLC your governance framework describes may not be the one your engineers are running.

SC Magazine Forthcoming

25% of Y Combinator Startups Have 95% AI-Generated Codebases. Enterprise Buyers Are Starting to Ask About It.

At 95% AI-generated, the codebase is the AI output. The standard vendor security questionnaire doesn't surface this. Enterprise procurement teams in regulated industries are starting to ask the questions that do.

Questions about AI governance or compliance exposure?

Book a 30-minute conversation. No pitch, no proposal. Just an honest look at where your program stands and what an auditor would find.