Fifty Years of Open Source Software Supply-Chain Security

Summary: The article discusses the enduring issues of software supply-chain security, highlighting a recent major attack on open source software through the XZ project. It reviews the history of software vulnerabilities, the consequences of supply-chain attacks, and the need for improved security measures such as authentication, vulnerability scanning, and the adoption of safer programming languages. The importance of funding open source projects to prevent security weaknesses is emphasized, drawing parallels to past incidents like Heartbleed. The author advocates for ongoing efforts to bolster defenses against potential attacks, as many fundamental security challenges persist in the industry.

https://cacm.acm.org/practice/fifty-years-of-open-source-software-supply-chain-security/

How to Gain Control of AI Agents and Non-Human Identities

Non-human identities (NHIs), including AI agents and service accounts, are proliferating in enterprises, posing significant security risks due to lack of visibility and oversight. Traditional identity management tools struggle to manage NHIs as they lack ownership, context, and standard protocols, making them vulnerable to exploitation. Security teams must proactively govern these identities, create inventories, and implement strong access controls to mitigate risks. A unified identity security approach is essential to address the increasing complexities of NHIs and to ensure a robust defense against potential threats.

https://thehackernews.com/2025/09/how-to-gain-control-of-ai-agents-and.html

Automated Decision-Making (ADM)

ADM uses algorithms for decision processes, enabling efficiency and speed. Applications span finance, healthcare, and logistics. Concerns include bias, transparency, and accountability. Regulatory frameworks are evolving to address risks.

5 Things Managers Do That Leaders Never Would, According to Simon

TLDR: Simon Sinek highlights five key differences between managers and leaders: 1) Managers hoard info; leaders overshare. 2) Managers rigidly follow policies; leaders adapt for people's needs. 3) Managers fire quickly; leaders help employees transition. 4) Managers avoid tough talks; leaders confront issues directly. 5) Managers reward conformity; leaders encourage dissent. Leadership is about choices that foster trust and human connection.

https://simonsinek.com/stories/5-things-managers-do-that-leaders-never-would-according-to-simon/

Understanding Right to Explanation and Automated Decision-Making in Europe’s GDPR and AI Act

Automated decision-making (ADM) systems aim to enhance decision accuracy and fairness in areas like hiring and healthcare. Europe's GDPR and AI Act seek to ensure fairness in ADM, emphasizing transparency and human oversight, but recent failures highlight risks of bias and lack of accountability. The “right to explanation” is essential for understanding automated decisions, yet complex models often complicate clear explanations. While explainable AI methods exist, they struggle with accuracy. There's a need for ADM protections to limit fully automated decisions, especially in contexts involving human agency, to prevent unjust outcomes and maintain fairness in democratic societies.

https://www.techpolicy.press/understanding-right-to-explanation-and-automated-decisionmaking-in-europes-gdpr-and-ai-act/

No More AI Silos: The CIO Integration Playbook

AI adoption is fragmented, creating silos within organizations and causing inefficiencies. CIOs must unify AI strategy, data, and platforms to enhance enterprise value. Key integration strategies include aligning AI with business goals, ensuring data integration, adopting a platform approach, fostering cross-functional collaboration, managing change, and establishing governance. Successful examples from CIOs illustrate the importance of breaking down silos and creating cohesive AI integration for improved organizational outcomes.

https://www.techtarget.com/searchcio/tip/No-more-AI-silos-The-CIO-integration-playbook

How AI Will Transform the CIO Role by 2030

By 2030, AI will radically transform the CIO role. CIOs will manage hybrid human-AI teams, lead business strategy, and drive revenue through AI-enabled products and services. Their responsibilities will expand to managing enterprise-wide AI portfolios, ensuring ethical, secure use of AI, and enabling new business models. Traditional duties in budgeting, procurement, and infrastructure management will evolve with AI-driven, real-time approaches, modular platform selection, and ethically adaptive systems. Overall, CIOs will focus more on top-line growth, innovation, and embedding ethical values into IT as business units become more autonomous with AI.

https://www.informationweek.com/machine-learning-ai/how-ai-will-transform-the-cio-role-by-2030

Why Shadow AI Is the Next Big Governance Challenge for CISOs

Shadow AI poses significant security and privacy risks as employees use AI tools without IT oversight, including public LLMs and SaaS applications. This use can lead to data breaches and compliance violations, as organizations cannot track sensitive data or protect it adequately. Banning these tools is ineffective and might increase hidden AI use. Instead, organizations should identify and approve AI tools while implementing safeguards, monitoring data flows, and training employees on risks. A proactive strategy is needed to balance security with the competitive advantages that AI provides.

https://www.infosecurity-magazine.com/news-features/shadow-ai-governance-cisos/

Five Takeaways for Tech From Draghi’s Speech

Five takeaways from Draghi's speech include: 1) Major telecom reforms (Digital Networks Act) are expected soon; 2) A call for deeper reforms to GDPR, which has increased data costs for EU firms; 3) A request to pause high-risk AI Act rules; 4) Advocacy for “Buy European” public procurement policies to support local tech; 5) Suggestions for easier merger regulations in Europe to promote industry consolidation. Overall, Draghi emphasized the need for impactful governance and simplification to boost European competitiveness. https://www.euronews.com/next/2025/09/17/five-takeaways-for-tech-from-draghis-speech

How CISOs Make the Business Care About Cybersecurity

CISOs share strategies to engage businesses in cybersecurity without fear tactics. Key points include aligning security with business goals, demonstrating value without breaches, careful insurance documentation, leveraging soft skills, creating effective awareness training, and emphasizing health and delegation. The conversation around security is evolving into a focus on business resilience, encouraging CISOs to build trust and foster strategic partnerships. https://cisoseries.com/how-cisos-make-the-business-care-about-cybersecurity/

Scroll to Top