4.7 • 53 Ratings
🗓️ 12 August 2021
⏱️ 40 minutes
🧾️ Download transcript
As the infamous SolarWinds attack showed, it’s no longer sufficient to just write secure code, you need to ensure that you understand the security risks throughout your entire software supply chain: whether that’s compilers, containers or the tools used to manage deployment pipelines.
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the ThoughtWorks Technology podcast. I'm your host, Mike Mason, |
0:10.3 | and today's podcast is going to be about securing the software supply chain. I'm joined today by |
0:18.0 | two guests, Mike Ensor, who is a solution architect at Google, and |
0:22.9 | Jim Gumley, who is a tech principal at ThoughtWorks with a focus on cybersecurity. |
0:29.5 | Hi to both of you, and can I get you to just introduce yourselves briefly, Mike? |
0:35.6 | Sure. |
0:36.6 | Hey, thanks for letting me come in and chat today. My name is Mike. I work at Google. |
0:41.5 | I work as a solution architect, which allows me to go in and talk to a lot of different companies, |
0:47.2 | a lot of different situations, and then try to capture that and then turn that back around |
0:52.1 | and give that advice back to many of our other |
0:56.1 | customers at the same time. So the most recent thing that I've been working on here has been |
1:00.6 | tackling the supply chain and how do we secure that, you know, especially given some of the |
1:06.0 | more recent breaches and more more recent news that we've seen. And Jim? Hey, Mike and Mike. |
1:13.0 | Thanks to having me. Yeah, I'm Jim. I'm a tech principal out of ThoughtWorks, London office. |
1:19.2 | My focus is very strongly on cybersecurity. So work with our clients, you know, we've got got more |
1:27.2 | higher-end risk profiles, healthcare, finance, |
1:30.8 | government, that kind of thing, to secure software, really. That's my focus. |
1:35.3 | I'm going to throw it back to Mike, because, you know, you said you've been working on this |
1:38.9 | securing the software supply chain. What is the software supply chain and what do we mean by securing it? |
1:46.0 | Sure. |
1:47.0 | So, basically, earlier this year, published a paper that talked about the supply chain |
1:53.0 | and where we have vulnerabilities in that. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from Thoughtworks, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of Thoughtworks and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.