Episode 105: From Compliance to Capability: Securing the Federal Software Supply Chain in the Age of AI episode artwork

EPISODE · Sep 9, 2025 · 40 MIN

Episode 105: From Compliance to Capability: Securing the Federal Software Supply Chain in the Age of AI

from Tech Transforms · host Carolyn Ford

On this episode of Tech Transforms, host Carolyn Ford welcomes Antoine Harden, Regional VP of Federal at Sonatype, to unpack one of the most urgent challenges in federal cybersecurity: securing the software supply chain. With more than 25 years of experience at Oracle, Google, and now Sonatype, Antoine shares why software supply chain risks from SolarWinds to Log4j have pushed SBOMs (Software Bills of Materials) and continuous monitoring into the spotlight. Together, they break down what SBOMs are (think nutrition labels for software), how mandates like Executive Order 14028 and frameworks like NIST’s Secure Software Development Framework (SSDF) and DoD’s SWFT are changing the compliance landscape, and why automation is essential to get from static ATOs to continuous authorization. Antoine also explains how Sonatype uses AI and software composition analysis tools to close critical gaps in open source and AI-heavy environments, helping agencies shift left, reduce vulnerabilities, and accelerate secure delivery of mission-critical systems. Along the way, the conversation covers everything from JFK delays caused by vulnerabilities, to the risks of “ludicrous speed” AI adoption, to the surprising history of Project Pigeon in WWII. For federal leaders ready to take action, Antoine offers one concrete step: start with a single mission-critical application, mandate an SBOM, and see what hidden risks you uncover. Show Notes: Connect with Antoine https://www.linkedin.com/in/antoine-harden-mba-035a441/ Executive Order 14028NIST Secure Software Development Framework (SSDF) CISA Zero Trust Maturity Model DoD’s SWFT (Software Fast Track Initiative) Sonatype Resource Center

Episode metadata supplied by the publisher feed · Published Sep 9, 2025

Embed this episode

NOW PLAYING

Episode 105: From Compliance to Capability: Securing the Federal Software Supply Chain in the Age of AI

0:00 40:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Tech Transforms?

This episode is 40 minutes long.

When was this Tech Transforms episode published?

This episode was published on September 9, 2025.

Can I download this Tech Transforms episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!