Podcast: Play in new window | Download (Duration: 12:01 — 16.5MB)
Subscribe: RSS
Summary
In this episode of Chattinn Cyber, Marc Schein is chattin’ with AI acceleration expert, Walter Haydock. Their chat opens with Walter explaining how his background in the Marine Corps, the intelligence community, and Congress shaped his approach to cybersecurity and AI governance. He describes founding StackAware after seeing how quickly companies were struggling to manage the risks created by AI tools, especially as adoption accelerated and organizations needed practical, cost-effective controls. The conversation opens with the idea that the corporate world has introduced a new kind of chaos — one centered on cybersecurity and AI governance — that many teams are still trying to understand.
A major theme of their chat is what AI governance actually means. Walter defines it as the practice of measuring and managing risks caused or created by AI systems, especially risks tied to confidentiality, integrity, and availability. He breaks the space into three categories: AI for security, AI for hacking, and security for AI. The final category is his primary focus, and he frames it as protecting organizations from the risks that come from using AI systems themselves, rather than simply using AI as a defensive or offensive tool.
The chat then turns to how traditional risk management applies in an AI-driven world. Walter says the core choices — accept, avoid, mitigate, or transfer — still hold, but the way organizations think about risk must evolve because AI is non-deterministic. Unlike traditional systems, AI may not produce the same output every time, even with the same inputs. That means companies need to move toward a more probabilistic way of assessing risk, where some deviation from expected behavior is acknowledged and managed rather than assumed away.
A substantial portion of their chat focuses on ISO 42001, which Walter describes as the first global standard for AI management systems. He explains that the framework helps organizations build policies, procedures, and practices for governing AI responsibly and demonstrating that governance to regulators and customers. He also discusses supply chain exposure, warning that AI is already embedded in vendor ecosystems whether companies want it or not. Rather than trying to ban AI outright, he argues for a measured, quantitative approach that compares the risk of supplier AI usage to the business value those suppliers deliver.
The chat concludes with practical advice for CISOs and security teams. Walter recommends three starting actions: define clear AI policy guidelines, create a full inventory of AI systems in use, and then perform a risk assessment to determine which systems and uses deserve the strictest controls. He also notes that ISO 42001 can support regulatory compliance and, in some cases, provide a form of safe harbor under emerging AI laws such as Colorado’s SB 205. The interview ends with Walter inviting listeners to connect with him on LinkedIn, where he posts AI governance and security content regularly.
Key Points
- AI governance is becoming a core security function. Walter frames AI governance as a way to manage cyber and operational risks created by AI systems.
- AI changes the risk model because it is non-deterministic. Organizations can no longer assume identical inputs always produce identical outputs.
- ISO 42001 is an important emerging standard. It provides a management-system framework for governing AI and demonstrating compliance.
- AI risk in the supply chain is unavoidable. Walter argues for practical, risk-based supplier assessment rather than unrealistic bans.
- Security teams need a structured starting point. Policies, inventory, and risk assessments are the first concrete steps to control AI usage.
Key Quotes
- “I saw a whole new level of chaos, specifically when it comes to cybersecurity and AI governance.”
- “AI governance is a practice related to measuring and managing the risk caused or created by AI systems.”
- “We’re going to need to revise how we think about risk to be more probabilistic.”
- “There’s no way that you’re going to avoid AI in the supply chain.”
- “I would recommend three concrete actions to start.”
About Our Guest
Walter Haydock is the Founder of StackAware, where he helps organizations address the biggest cybersecurity and AI governance risks without wasting time or resources on distractions. Before entering the private sector, he served on the U.S. House Homeland Security Committee, at the National Counterterrorism Center, and as a Marine Corps reconnaissance and intelligence officer. He is a graduate of the U.S. Naval Academy, Georgetown University’s School of Foreign Service, and Harvard Business School.
Follow Our Guest
About Our Host
National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.
Follow Our Host
