Topic · 3 posts
Supply chain
Every Inline Code post tagged Supply chain, ordered most recent first.
AI · Supply chain
AI supply chain security: four ways code now enters your estate without a vendor review
Model weights, agent skills, MCP servers and packages your coding assistant invented all execute in your environment, and none of them trigger a vendor assessment. The documented incidents, the measured scale, and the controls that close the gap before CPS 230 makes it an audit finding.
Platform engineering
Securing CI/CD pipelines without slowing engineering down
Pipeline security is the gap between policy and reality. Most regulated firms have written rules about code review and signed releases that the actual pipeline does not enforce, and the audit evidence is whatever the runner happened to print to stdout.
Third-party risk
Third-party risk after the supply-chain attack era
Most third-party risk programs in mid-market financial services are questionnaire factories. They produce paperwork; they do not produce risk reduction. After several years of supply-chain incidents, the realistic position has changed. Here's what actually works.
Browse other topics
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.