Cybersecurity News & Analysis by Cyber Sidekicks - Your Weekly Update’ · Christina Richmond | Rory Duncan - Cybersecurity Experts | Richmond Advisory Group

AI Compliance & Governance: why it matters - with ISMS Online's Chris Newton-Smith

·34 min·2 clips
The U.S. State Department is offering rewards for locating people tied to malicious cyber activity.
1. Cyber Sidekicks covers SBOM adoption, U.S. cyber rewards, and AI compliance with guest Chris Newton-Smith of ISMS Online. 2. Hosts Rory Duncan and Christina Richmond are Richmond Advisory Group principal analysts, and Chris Newton-Smith is CEO of ISMS Online, which says it works with more than 1,000 customers. 3. The episode asks whether companies can keep up with AI rollouts, supply-chain visibility demands, and cross-border compliance rules at the same time. 4. Rory and Christina introduce a new push for software bills of materials, or SBOMs, and connect it to the CISA framework published “as of yesterday.” 5. Christina says SBOMs improve visibility but also add “another thing” for CISOs who already manage TPRM questionnaires and supplier oversight. 6. Rory compares SBOMs to physical bills of materials from his product management days, where every item in the box had to be tracked. 7. The hosts say the same logic applies to software components, APIs, and third-party applications that interact with a platform. 8. They also bring in agentic AI, asking how software bills of materials will work if agents build software on a company’s behalf. 9. Rory shifts to the U.S. State Department’s Rewards for Justice site and says it has existed since 1984. 10. The site is described as covering terrorism and malicious cyber activity, with rewards for information that identifies or locates people acting for foreign governments. 11. Rory and Christina note that the site looks like a “shopping list” of individuals and groups with dollar values attached. 12. Rory highlights three Russian Federal Security Service officers, Pavel, Mikhail, and Marat, and says the page links them to targeting more than 380 foreign security agents. 13. The hosts say the same listings connect those officers to oil and gas firms, nuclear power plants, renewable energy firms, utility companies, and electrical grid entities in 135 countries. 14. Christina questions why the announcement is being emphasized now and calls part of the public framing “theater.” 15. The discussion treats the bounty system as a serious intelligence tool while also noting that it resembles bug bounty programs in structure. 16. Chris Newton-Smith says a major concern is the gap between rapid AI adoption and slower rollout of governance and safety systems. 17. He describes shadow AI as employees trying new tools without considering effects on company data safety and services. 18. Chris recommends ISO 42001 as a common framework for an artificial intelligence management system that combines technology, people, and process controls. 19. The interview is conversational and practical, with Rory and Christina pressing Chris on market specifics, legal risk, and the EU AI Act. 20. People building AI governance, compliance, or GRC programs will get the most value; listeners wanting deep technical exploit analysis may skip it.
Listen to the show on