AI Governance, Cyber Risk, and the New Security Perimeter with Walter Haydock

walter haydock and marc schein

Summary

In this episode of Chattinn Cyber, Marc Schein is chattin’ with AI acceleration expert, Walter Haydock. Their chat opens with Walter explaining how his background in the Marine Corps, the intelligence community, and Congress shaped his approach to cybersecurity and AI governance. He describes founding StackAware after seeing how quickly companies were struggling to manage the risks created by AI tools, especially as adoption accelerated and organizations needed practical, cost-effective controls. The conversation opens with the idea that the corporate world has introduced a new kind of chaos — one centered on cybersecurity and AI governance — that many teams are still trying to understand.

A major theme of their chat is what AI governance actually means. Walter defines it as the practice of measuring and managing risks caused or created by AI systems, especially risks tied to confidentiality, integrity, and availability. He breaks the space into three categories: AI for security, AI for hacking, and security for AI. The final category is his primary focus, and he frames it as protecting organizations from the risks that come from using AI systems themselves, rather than simply using AI as a defensive or offensive tool.

The chat then turns to how traditional risk management applies in an AI-driven world. Walter says the core choices — accept, avoid, mitigate, or transfer — still hold, but the way organizations think about risk must evolve because AI is non-deterministic. Unlike traditional systems, AI may not produce the same output every time, even with the same inputs. That means companies need to move toward a more probabilistic way of assessing risk, where some deviation from expected behavior is acknowledged and managed rather than assumed away.

A substantial portion of their chat focuses on ISO 42001, which Walter describes as the first global standard for AI management systems. He explains that the framework helps organizations build policies, procedures, and practices for governing AI responsibly and demonstrating that governance to regulators and customers. He also discusses supply chain exposure, warning that AI is already embedded in vendor ecosystems whether companies want it or not. Rather than trying to ban AI outright, he argues for a measured, quantitative approach that compares the risk of supplier AI usage to the business value those suppliers deliver.

The chat concludes with practical advice for CISOs and security teams. Walter recommends three starting actions: define clear AI policy guidelines, create a full inventory of AI systems in use, and then perform a risk assessment to determine which systems and uses deserve the strictest controls. He also notes that ISO 42001 can support regulatory compliance and, in some cases, provide a form of safe harbor under emerging AI laws such as Colorado’s SB 205. The interview ends with Walter inviting listeners to connect with him on LinkedIn, where he posts AI governance and security content regularly.

Key Points

  1. AI governance is becoming a core security function. Walter frames AI governance as a way to manage cyber and operational risks created by AI systems.
  2. AI changes the risk model because it is non-deterministic. Organizations can no longer assume identical inputs always produce identical outputs.
  3. ISO 42001 is an important emerging standard. It provides a management-system framework for governing AI and demonstrating compliance.
  4. AI risk in the supply chain is unavoidable. Walter argues for practical, risk-based supplier assessment rather than unrealistic bans.
  5. Security teams need a structured starting point. Policies, inventory, and risk assessments are the first concrete steps to control AI usage.

Key Quotes

  1. “I saw a whole new level of chaos, specifically when it comes to cybersecurity and AI governance.”
  2. “AI governance is a practice related to measuring and managing the risk caused or created by AI systems.”
  3. “We’re going to need to revise how we think about risk to be more probabilistic.”
  4. “There’s no way that you’re going to avoid AI in the supply chain.”
  5. “I would recommend three concrete actions to start.”

About Our Guest

Walter Haydock is the Founder of StackAware, where he helps organizations address the biggest cybersecurity and AI governance risks without wasting time or resources on distractions. Before entering the private sector, he served on the U.S. House Homeland Security Committee, at the National Counterterrorism Center, and as a Marine Corps reconnaissance and intelligence officer. He is a graduate of the U.S. Naval Academy, Georgetown University’s School of Foreign Service, and Harvard Business School.

Follow Our Guest

Website | LinkedIn

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host

Website | LinkedIn

AI Governance Is a Living Operating System

Ahmad Alokush episode image

Summary

This episode, Marc is chattin’ with Ahmad Alokush, a technology risk, AI governance , and cybersecurity oversight expert. Their chat centers on AI governance and why organizations often approach it too narrowly. Ahmad explains that one of the biggest blind spots is treating governance as a one-time compliance exercise instead of a continuous operating discipline. He frames AI governance as an operating system for trust — something that must evolve as AI systems, business use cases, and risks evolve.

A major theme is the hidden cost of AI governance. Ahmad notes that many CFOs underestimate the true investment required, because governance includes not just technical maintenance but also data quality work, regulatory compliance, and change management. His point is that governance is not overhead; it is what makes AI’s ROI sustainable and defensible over time.

The discussion then shifts to the difference between reactive and proactive organizations. Reactive teams tend to address issues only after deployment, often after a problem has already become a crisis. Proactive organizations, by contrast, build risk assessments, bias testing, documentation, and oversight into the process before systems go live. Ahmad emphasizes the importance of visibility into AI usage, including the dangers of “shadow AI” when employees adopt tools outside approved policy.

They also chat about accountability and ownership. Ahmad points out that AI initiatives often span IT, data, HR, compliance, and business teams, which can make ownership unclear. In his view, mature governance requires a clear owner, often supported by a chief AI officer, risk committee, or audit committee, along with a living inventory of AI systems that identifies risk levels and update cadence.

Finally, the chat moves to global regulation and how organizations can manage conflicting rules across jurisdictions. Ahmad describes the need for jurisdiction-specific risk mapping, compliance by design, and deployment variants that can satisfy stricter disclosure or transparency requirements where needed. He closes by encouraging listeners to stay proactive, continuously improve, and treat AI governance as part of the organization’s long-term operating model rather than a box-checking task.

Key Points

  1. AI governance should be treated as an ongoing discipline, not a one-time project.
  2. The real cost of AI governance includes technical maintenance, data quality, compliance, and change management.
  3. Reactive AI programs often lead to shadow AI, poor documentation, and post-deployment crises.
  4. Clear ownership and a live AI inventory are essential for accountability.
  5. Global AI regulation requires jurisdiction-specific strategies, not a one-size-fits-all approach.

Key Quotes

  1. “[T]he biggest [blind spot] that I see is treating the governance like a one-time compliance project instead of like a living operating discipline.
  2. “[Governance] is not paperwork. It’s an operating system for trust.”
  3. “AI isn’t overhead. It’s the insurance that keeps ROI real.”
  4. “Reactive [thinking about AI] is thinking of it as a compliance task. That’s after deployment. ‘We’ll fix it after it breaks.’”
  5. “You have to have a live AI register with ownership, risk level, and updating the cadence for each model.”

About Our Guest

Ahmad Alokush is a globally recognized expert in AI, cybersecurity, fintech, and technology litigation, and the founder of Ahmadeus Technology Boutique. He advises foreign governments, institutional investors, and C-suite leaders on emerging technologies, M&A strategy, digital asset valuation, and complex regulatory matters, while also serving as a trusted expert witness and keynote speaker for Fortune 500 companies, AmLaw 100 firms, and global policy leaders. Known for bridging technical, legal, and business perspectives, Ahmad brings clarity, discretion, and strategic insight to high-stakes engagements in boardrooms, courtrooms, and advisory settings.

Follow Our Guest

LinkedIn | Website

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host

Website | LinkedIn