Skip to content
TrackPodcasts
technologyMar 14, 202621:55

Software Supply Chains, AI Risk, and the Transparency Gap | A Brand Spotlight with Daniel Bardenstein of Manifest | RSAC 2026

About this episode

As RSAC 2026 approaches, Daniel Bardenstein, CEO and Co-Founder of Manifest, joins hosts Sean Martin and Marco Ciappelli to unpack the growing disconnect between how security leaders perceive their AI and software supply chain posture and what practitioners on the ground actually experience. Drawing from Manifest's new research report — Beyond the Black Box — Bardenstein connects the dots between shadow AI, SBOM adoption gaps, and a dangerous pattern: history is repeating itself as organizations rush to adopt AI with the same disregard for security that characterized the early cloud era.

 

In a wide-ranging pre-event conversation ahead of RSAC 2026, Daniel Bardenstein, CEO and Co-Founder of Manifest, explores what it means to truly secure the software and AI supply chain — not just check the compliance box. Manifest's new research report, Beyond the Black Box, surveyed more than 300 security and AI leaders globally to understand the reality of AI adoption and software supply chain risk. One of the most striking findings was not a statistic, but a structural problem: a significant perception gap exists between how confident executive security leadership feels about their AI security posture and how unprepared frontline practitioners actually are. Where there is misalignment, Bardenstein notes, there is risk.

 

The conversation draws a vivid parallel to the cloud adoption wave of a decade ago, when organizations rushed to SaaS and cloud infrastructure without thinking through security implications — and gave birth to entire new industries to clean up the mess. Today, the same dynamic is playing out with AI. Nearly two-thirds of the survey respondents reported encountering shadow AI within their organizations, as employees freely use tools like ChatGPT, DeepSeek, or locally downloaded models without centralized governance. When that AI eventually gets embedded into software that organizations build, deploy, and sell, the blind spots compound.

 

SBOMs — software bills of materials — represent a promising step toward supply chain transparency, and Bardenstein credits the US government's regulatory nudging for driving adoption. Manifest's research shows that roughly 60% of organizations are now generating SBOMs, a meaningful milestone. But generation is not governance. Too many organizations treat an SBOM as a compliance artifact — a JSON file on a hard drive — rather than an operational tool that could dramatically accelerate vulnerability response, regulatory compliance, and incident management. The prescription has been filled; it's just not being taken.

 

To reframe the urgency, Bardenstein introduces the concept of the "transparency tax" — the hidden cost organizations pay in time, money, and risk when they build or buy opaque technology. Just as consumers demand ingredient labels on food, Carfax reports on used cars, and active ingredient disclosures on prescriptions, the technology sector needs to normalize the same transparency for software and AI. For organizations willing to do the math, the case for investing in supply chain visibility becomes not just a security argument, but a business one.

 

Heading into RSAC 2026, Manifest will not have a booth but will be active across the conference floor, meeting with customers, partners, and prospects. Bardenstein will appear on an invite-only panel alongside leadership from Corridor Dev, 1Password, and Google to discuss secure software and secure AI. The team is also planning to announce new platform capabilities designed to close the governance gaps their research surfaced — helping organizations move fast without creating the kind of blind spots that make AI adoption a liability rather than an advantage.

 

Tune in for this sharp, candid pre-event conversation — and look for the full on-location Brand Spotlight recorded live at RSAC 2026 in San Francisco.

 

🎙️ This story is part of the RSAC 2026 Coverage Series on ITSPmagazine, produced in partnership with Manifest.

 

GUEST

Daniel Bardenstein

CEO and Co-Founder, Manifest

https://www.linkedin.com/in/bardenstein/

https://www.manifestcyber.com

 

RESOURCES

Beyond the Black Box Research Report — Manifest:

https://www.manifestcyber.com

 

Learn more about Manifest and their software and AI supply chain security platform:

https://www.manifestcyber.com

 

Learn more about and follow ITSPmagazine's coverage on RSAC 2026:

https://www.itspmagazine.com/rsac-usa-2026-san-francisco-cybersecurity-event-coverage

 

Catch all of our event coverage:

https://www.itspmagazine.com/technology-cybersecurity-society-podcast-coverage

 

Want to tell your Brand Story Difference Maker Podcast Story or Advertise with us? 👉 https://www.itspmagazine.com/telling-your-story

 

KEYWORDS

Daniel Bardenstein, Manifest, Manifest Cyber, software supply chain security, SBOM, AI supply chain, AI risk, RSAC 2026, RSA Conference, Sean Martin, Marco Ciappelli, brand spotlight, brand story, ITSPmagazine, brand marketing, marketing podcast

 


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Get every episode summarized

Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

82 searchable segments. Every word is indexed and playable.

Software Supply Chains, AI Risk, and the Transparency Gap | A Brand Spotlight with Daniel Bardenstein of Manifest | RSAC 2026

The ITSPmagazine Podcast

0:00
21:55

Full transcript

The ITSPmagazine PodcastSoftware Supply Chains, AI Risk, and the Transparency Gap | A Brand Spotlight with Daniel Bardenstein of Manifest | RSAC 2026. Machine-transcribed; use the interactive transcript above to jump the player to any line.

I am and I have to say I really hope the supply chain holds up on my journey from east to west while we all hope that right not just for you over the entire world that's exactly well everything is software these days and pretty much every software is built by a bunch of pieces of software if we don't have an idea of what's going on in there things can go sour fairly quickly so hopefully that doesn't happen. It doesn't look Daniel and I already had a quick five minute chat before so we have some metaphor I think we have some food label metaphor. Oh we got it already. Our space is full of metaphors and anatomy.

Sean you're joking about the supply chain of collecting travel reminds me of there is an incident last year and I don't have point fingers incorrectly because I forget what was but it was either a major airline or a major airline manufacturer that had to ground a count a bunch of planes because there was a bad software update and it took them most of a day or two just to figure out where across all the planes they have and run that one piece of software with that certain version was running so because they didn't know they couldn't say it's just one plane or two plane or all the planes. For a day or two so the joke is right on the money about the importance of software supply chains and how it affects how we fly what we eat the water and electricity we get to our homes. It's both fascinating and terrifying at the same time for sure it is fascinating it is fascinating. So I'm happy to stick with the food food stuff and I don't know perhaps we'll get into that when we start talking about San Francisco and sourdough bread and kind of chatter who knows what else we touch on there but this isn't about food necessarily and it's not just about supply chain but it's about building secure software and of course.

Daniel you and the manifest team we're going to be at RSA conference and having some good conversations with customers and partners and that prospects and peers and talking about all this. So what's before we get into the conversation maybe a few words about who you are Daniel your role with manifest and a brief view of what the company does we have that stage set as we get into all the things RSA conference. Sounds good well thanks for having me boys a pleasure for those who don't know me I'm Daniel Bardenstein I'm the CEO and co-founder of manifest. I background very briefly I've been building enterprise security tools for most of my career spend some time in government academia as well ultimately trying to make the society that we all have been more secure since as we've already noted and joked software is everywhere and as we'll allude to with future metaphors we don't demand the same level of transparency in the software that governs our lives. As we do for the food we eat the prescription drugs we buy the cars we drive the houses we want to live in manifest we're three and a half year old startup that focuses on all things software supply chain and AI supply chain security.

Our mission is to help organizations build and buy more trusted software and AI in the ultimate impact we hope to have on the world and technologies we want both people and organizations to have that same trust in the technology that governs our everyday lives again whether it's AI and the cars for driving or software and the medical devices and MRI machines that we in our families are hooked up to as we do in the world. We do in in the food we eat in the grocery store where we can look at ingredients lists prescription drugs that list the primary active ingredient even the cars we want to buy you can look at the car facts. So ultimately we're on a mission to make technology more transparent and more trusted. And I'm expecting a lot of those kind of conversations on the floor are say conference you know we make the joke where we say when we go this conference we kind of look into the future is a way to look at the status of thing and into the future.

We make the games of guests in the buzzword or you know of the year so I know we have some announcement and talk about some something that you will you know we'll go a little bit deeper into as far as the research that you guys are done and presenting but what's your expectation to do zero or say conference. Well I think AI is definitely going to be on my bingo card of buzzwords again it certainly was last year and to be honest we don't have a booth we're also going to be talking about our research and work into AI and AI security as well. My experience with RSA is always seeing kind of old topics redone you know whether it's zero trust or AI or whatnot and so I think we'll see lots of acronyms and buzzwords I'm excited to see. A much deeper advancement and maturity around how we talk about AI security last year there was just AI plastered onto every single company's booth and marketing or all of a sudden an AI company now and so I think as we'll talk about today the rapid proliferation of AI will not surprise anybody but it's actually caused these meaningful conversations around well how well do we actually know about what AI risk is and looks like how mature and ready are people in.

Getting ready to you know prevent detect respond to that risk and how do you make sure we have the technology to enable that so I'm excited for that along with a Sean mentioned I'm going to get my my sourdough my croissance you know I lived in the San Francisco Bay area for 10 years so it's always a little bit of a nostalgic homecoming and yeah as you know did manifest won't have a booth but will be. Running around meeting customers prospects partners i'll be on a panel and invite only event with leadership from corridor dot dev one password and Google jimber excited about all about secure software and secure AI i'm there'll be a lot of fun and always a little bit crazy which RSA always is. So maybe we start to touch on you guys put out and report beyond the black box and. I guess that they still look at the part of an engineering team and manage engineering teams and the way software is built today has changed a lot there's so many parts and pieces and services and stuff run and on prem and in the cloud and I know part of the highlights that you mentioned and I think you even talked about at the beginning is kind of that visibility and knowing.

And because we're building so much and deploying so much and doing it so fast all can teams actually get that visibility and know and what what's some of what are some of the points from the research you did that kind of highlight some of that stuff I think they are within the same organization and that's pretty serious. There's a this gap is real and where there is misalignment there's risk right when security the ship is feeling very confident about we adopted AI but we're doing it securely but the front line security practitioners are saying actually we don't have these tools we know the shadow I we know there are users around the organization who are building their own AI enabled tools or using forbidden on compliant models that was a major gap and a bit of a wake up call that we weren't. So I think it's a very interesting thing to find I see I'm going to quote someone named Daniel Bartons in CEO and co founder says we are seeing history repeat itself.

Yeah well I think there's a couple ways to unpack that the first is this is like not the first time where there's been that overconfidence within leadership versus what we see at the ground level and I've certainly experienced that in my past career. The biggest application of that concept of seeing history repeat itself is in terms of how quickly we're all adopting new technology to try to benefit and leverage the efficiencies of it without thinking about the security and the risk reduction around it. I often think about the launch to cloud when cloud was a big thing now with 10, 15 years ago and SaaS everyone's rushing to the cloud and there were so many predictable things that people weren't thinking about that gave birth to entire new industries about how do you secure cloud technologies how do you migrate how do you hybrid cloud and the same thing is happening with AI in the same and the same way that we even have similar terminology so in this same way that in that that rush to adopt cloud based technology.

We end up with shadow IT because people were spinning up cloud instances here and there and everybody was doing it in their own local machines without centralized control. You know some of the research we found in our black box report was nearly two thirds of respondents are seeing shadow AI in their organizations. Because the bars so low for employees to go out to the public internet use chat gbt or deep seek download open and there's no centralized security management et cetera and it leads to this lack of visibility right this is why we're after trying to illuminate supply chains and software supply chains and as a supply chain because security leaders already aren't aware of all the shadow AI that organize that their employees and developers are using maybe it's just on their own laptops but when not that AI that can that then gets put into software that they develop deploy sell that becomes a blind spot and just like traditional software supply chain attacks the likes we've seen over the last five years.

We're really poised and this is we're here to try to navigate the nudge the industry to learn from our mistakes we're poised to repeat the same mistakes as we did when we rushed to cloud without thinking about security or rushing to adopt AI without being about proper security in governments. Speaking of nudging you're there in DC and I know you probably have a lot of mutual friends that worked a lot on the world of supply chain security and espoms and if I mention one name you'll pop up on the podcast all of a sudden join us but back to the nudging I think the government kind of helps when they put out guidelines and rules and frameworks and things like that and I think I saw in the report that we actually do generate espoms now. Which is a positive step but what what's your view of the state of software bill materials and are they really producing the results that we want and and what are security leaders and business leaders and app dev and abstract teams kind of where they misaligned on what that really looks like.

The U.S. government definitely deserves all the credit can for helping popularize the concept of an espom big it to some early regulation the executive order from a few years ago research shows that there has been pretty significant adoption of around 60 plus organizations are already generating espoms. It's not 100% it's not where we need to get if we want to get to the vision of self or supply chain transparency but it's not nothing but the other side of generation of these artifacts is operationalization what are you doing with them right a lot of organizations still see espoms as this compliance check box I've generated this. Jason file this ingredients list therefore must be more secure it's as valuable as it is to say hey I picked up my prescription but I haven't actually taken it. And so there's certainly more room both for government for policy makers for industry leaders to educate security leaders and practitioners around the world on or what you actually do with an espom how do you actually turn this little piece of data into something that helps you.

Builds and buys more secure software how do you use it for AI how do you use it for cryptography how do you use it to respond to vulnerabilities and software supply chain incidents much faster how do you use them to answer the mail on all the global compliance that's coming out much faster. Generation is not governance right generating espoms or AI bombs doesn't make you safer the fact that a visibility doesn't translate into decisions and enforcement it doesn't really reduce risk at all it's just security theater and so it's encouraging to see the adoption of espom generation but if you're just generating a compliance artifact but not doing anything with it then you're not actually making your organization or customers your data anymore secure. So I have a question as I like to think I mean you guys like to go obviously and you have the knowledge to go technical and deep I always look at a general overview and I'm thinking like so i'm assuming there are certain industries that need these more than other but i'm still thinking about the food industry right once you adopt the system you can just say well we're just going to do it for vegetables and meat right we're going to do it for everything because.

i'm thinking the synergy between all the different software and components and device and technology how possible is it to make progress where it becomes part of the system and not just something that oh we're going to do a legislation where healthcare needs to do it I don't know if it's going to really resolve the problem if it goes. Silas right yeah it's a great great question and point and a couple ways to think about it the first I believe is there is precedent for it and we think the automotive sector in terms of how it does recalls right so car manufacturers know every single part from every single supplier and what make a model of car goes into so if they detect a default in an air bag within. hours stays they can identify the supplier what makes a model is effective they can notify the dealership to sometimes and users i've certainly gotten notices from my car's manufacturing hey you have a problem in your car go take it in to get fixed so we just need to do that right.

There's another thing you touched on which is a fun idiosyncrasy of the US government which is there is no central regulator across industries in the US except for the US Congress which is focused on perhaps some other things these days there are different they're called sector risk management agencies that's a whole other thing we can dive into but. But in ultimately going back to the previous concepts you know I think one thing that that we hope. People across sectors really realize and will lead them not just to wait till those regulation to make them do this but to do this voluntarily to get ahead of them the curve is thinking about this in terms of attacks and so we are. Trying to really spread this message of thinking about a lack of transparency as a tax right that organizations when you build or buy software AI that you don't know. Where it came from what's in it how secure it is you don't know where you're putting it. There's a transparency tax right and that transparency tax that's the extra time money and risk that organizations have to spend in order to secure maintain and respond incidents in opaque technology.

So even if yes you can wait till there's a regulation that says hey if you want to get your medical device approved by the FDA just the case you have to provide an S bomb you have to understand your supply chain if you're trying to. You know be compliant with the EU cyber resilience act you pretty much have to do the same thing across sectors organizations who are very aware of their taxes and their costs and how much they spend need to be thinking about. Is there I think I'm paying this much money for this third party technology or I think I'm saving time by using AI coding tools or using open source tools. But if I change the thinking by factor in this additional cost this tax that I expect to pay long term that will actually start to change our behavior and see it actually is better for a bottom line to understand what technology we're bringing from the outside in the same way that we think about what we put into our bodies the food we eat the cars we buy the homes we live in. So it's so interesting and I'm excited to have another chat with you on location in San Francisco we can dive a little deeper and get in some of the tech parts of it and I know you guys are releasing some new capabilities which will touch on location as well as we wrap your Daniel you're talking about tax and Marco kind of led me to this idea that security often gets in the way of business.

Not just the department of no just by the way we talk about it not talking about it in terms of attacks we're talking about in terms of a threat and risk and threat attacking risk that turns into something else so looking at who you plan to talk to and and do business with an RSA conference. How do you expect those conversations to go where we can kind of get out of our own way as security and really get back to the real nuts and bolts of business. Yeah actually solve this problem. I think one of the greatest ironies here is that while AI is meant to be something that allows us to innovate faster and move faster and gain efficiencies it's already creating legal drag and compliance drag with an organization so we're already talking with Fortune 500 global 2000 organizations are report showed that this is true for over 50% of organizations that even just that process of securing AI or even approving or getting AI to be compliant so yes we sign off it.

My company that you can use this model but not this model or this data set that's already causing slow down so people in the race to adopt AI are actually slowing themselves down because they don't have the right processes and tools in place. And so there's this ironic push and pull that we expect to chat about more and I've already have some case studies on where everybody is racing so fast to adopt AI but not thinking about how do you automate and bring in tooling to make sure that we're bringing in a safe that it's actually causing delays right and if you're three months behind four months behind you're adopting the latest AI you're going to be behind your competition. And other things that we we end to talk about like you alluded to at our say we'll we'll have an announcement about new platform capabilities that will be delivering especially hitting some of these themes that we glean from the research report there are various gaps that organizations or vulnerabilities come from and whether they are worth triaging and spending time in and how they govern AI that we have already closed the gap for and we're excited to kind of bring that to market.

Overall, one of the themes of both what we are continuing to build and what we're continuing to talk about expect to talk about a RSA is how do we close that perception gap between how secure leaders think the R versus what the reality is on the front lines, how do we make sure that organizations really understand what's in the AI in a software they're building and buying and how does everybody have the tooling to make sure that their adoption of new software and new AI is as fast as the innovation they want to go to without introducing risk and slowing themselves down. Awesome stuff good stuff well I would encourage everybody to track you down look for Daniel Bardenstein and the rest of the manifest cyber team in San Francisco check out the report won't leave a link to that of course so you can get your hands on it and figure out how to a lot of operational stuff in there. There certainly is a lot of things that I was surprised to read as well about how AI is being adopted in some of its gaps and feel free to reach out and read the report.

I said manifest cyber dot com and we can always happy to meet up with folks in RSA who want to a nerd out about all these fascinating and yet depressing topics. We're going to keep an eye on on the floor and in the corridor about what we think security is and what it really is. Which is kind of like branding right is what people think you are not what you think you are. Anyway everybody stay tuned we'll have many more conversation we'll hang out a lot of Moscone North if you are or say stop by say hi and of course that's what we're going to record with you as well. Take care we'll see you next time. Thanks all. Thank you.

Thank you.

More episodes

More from The ITSPmagazine Podcast

View all episodes →