For a long time, compliance meant paperwork. Fill out the right forms, pass the annual audit, file it away. Done. Now, your development pipeline is generating code at a pace no human team can review manually, your supply chain runs three layers deep into open-source packages and AI plugins you didn’t choose, and regulators are watching in real time. The old approach doesn’t just underperform; it creates a false sense of security.
That was the thread running through Veracode’s recent webinar, “Building Trust in the AI Era: The New Compliance Imperative.” The panel brought together Anthony Barkley, Veracode’s Chief Strategy Officer; Chris Wysopal, Veracode’s Chief Security Evangelist and co-founder; and Tim Brown, CISO in Residence at Team 8 and the former CISO of SolarWinds.
Tim Brown holds a distinction no one wants: he was the first CISO in history to face personal liability under securities fraud statutes when the SEC filed its landmark lawsuit in 2023. The case was dismissed in 2025. He can now talk about it openly, and what he has to say is worth every security leader’s full attention.
The New Compliance Reality: From Paper to Practice
Legacy compliance was built around moments in time. Scan the environment, collect the screenshots, pass the audit, repeat next year. Barkley’s central argument is that this model was already struggling before AI arrived, and now it’s genuinely indefensible.
“That single most important shift is really this idea that we’re moving away from point-in-time, paper-based compliance to more continuous, evidence-backed operational resilience — both for software but also for AI-driven systems. Traditional approaches fail because they can’t keep up with AI-accelerated change, complex supply chains, and real-time regulatory scrutiny.”
The audience for compliance has also changed. Regulators and customers aren’t asking whether you have a policy anymore. They want to see the controls working.
“Regulators, customers, and auditors care a lot less about whether you have a policy or a certification — and a lot more about whether your controls actually work in production over time. Compliance is going to be judged by that live and demonstrable control performance.”
Wysopal added the dimension most organizations are still reckoning with. AI-generated code is flooding into production and developers are proud of it. The problem is that volume and quality are not the same thing.
More code means more audit trails, more decision records, more false positive determinations, more human oversight required at a scale humans weren’t designed to handle alone. The old frameworks were not built for any of this.
Lessons from the SolarWinds SEC Case: What Personal Liability Actually Feels Like
Tim Brown’s story is the most consequential first-person account in modern cybersecurity. Not because of what happened to SolarWinds, but because of what happened to him, and what it means for every CISO moving forward.
The SolarWinds breach was discovered December 12, 2020. What followed was a five-year ordeal. The immediate response to the breach was, by most measures, exemplary. SolarWinds filed its 8K material event disclosure before the market opened Monday morning, ahead of the SEC’s own breach disclosure requirements.
It didn’t matter. The SEC opened an investigation into whether SolarWinds had misled investors, and eventually charged Brown individually, the first time in history a CISO faced personal securities fraud liability. He learned about the charges while in Zurich. He had a heart attack that day. He flew home, went to the hospital, had two stents placed, and within days was looking at a settlement letter from the SEC in his hospital bed.
He didn’t sign it. He fought. So did the company. A judge dismissed 90% of the case. The SEC eventually dropped everything.
Supply Chain as the New Perimeter: Security in the AI Era
SolarWinds changed how the industry thinks about supply chain risk. What happened wasn’t a breach in the traditional sense. Nobody broke through the firewall. The attackers inserted tainted code between source control and the final product, in the build process itself, and it shipped to 18,000 customers before anyone knew.
Brown says, “What it really woke up for everyone was supply chains… That sparked a bunch of supply chain conversations — how do we improve supply chains? How do we understand what’s in our supply chain? How do we have compliant supply chains?”
Wysopal has been tracking this surface area since before most of today’s CISOs were in the field. He testified before the U.S. Senate about software vulnerabilities 25 years ago. Back then it was all first-party code. Then open source arrived and expanded the attack surface in ways most organizations still haven’t fully addressed. Now AI developer tools and plugins have added another layer of exposure that most organizations aren’t even tracking.
He says, “All these dev tools and plug-ins need to be reviewed and tracked just like the OSS dependencies. This is a new thing that has to enter into the compliance equation — is your pipeline and your development process in a state where it can generate a compliant application?”
The discovery problem has also gotten significantly harder. AI tools have democratized development to the point where the concept of “who is a developer” barely holds anymore.
Brown noted that the SolarWinds attack, sophisticated as it was in 2020, would be far easier to execute today. The reconnaissance, the code design, the injection itself — all of it is AI-enableable now. “Our attack was novel back then,” he said. “I don’t think they’re going to be that novel coming up in the future.”
From Reactive to Proactive Compliance: The Case for Continuous Attestation
Scan, certify, move on. That’s still how most organizations run compliance. It was never a great approach. Now it’s actively creating risk. Barkley’s argument for continuous attestation isn’t theoretical — it’s a direct response to a world where code changes happen constantly and every change is a potential exposure.
The shift from periodic proof to real-time verification means cryptographically validating builds, deployments, and runtime environments every time something changes, not once a year.
Wysopal took it a step further by saying, “Everything is moving so fast — this has to work at machine speed. Questionnaires and forms and checklists where people research things and fill out forms isn’t going to work. It’s got to be real-time, continuous. Every vendor, product version, API package, AI agent dependency has to sit in a trust graph that has live evidence.”
Building Audit-Ready Security Postures: Governance Without Friction
There’s a persistent belief in security circles that tight compliance slows down development. SolarWinds is a direct refutation of that. After the breach, Brown’s team rebuilt their build infrastructure from scratch, and what they built was both more secure and more auditable than what came before.
“We invented new build systems that assumed breach and were extremely resilient to attack. For the Orion platform, we do three builds before we ship. No one person has access to all three. We binary compare the results to make sure they were not tampered with by anyone.”
Assume breach. Design for verifiability. Remove every single point of trust. That architecture has a name now, but it came out of necessity, not theory.
Barkley’s version of audit readiness looks different from what most compliance programs produce. No screenshots gathered the week before the audit. No snapshots dressed up as ongoing evidence.
He says, “Compliance is going to be judged by that live and demonstrable control performance — continuous logging, monitoring, automated evidence collection, and some level of certification we can rely on. Not just screenshots that are collected before an audit.”
Brown added something worth sitting with on the AI governance side. He said, “AI is fantastic for many things, but it is non-deterministic — meaning it can decide to do things you’re not expecting. It’s very important that we put some deterministic layers on top of the non-deterministic. We’re not gonna slow things down — the big focus has been how do I enable without slowing down? Assuming breach in everything that we do… We’re going to need more of those types of controls in place to get to a point of acceptable risk. Resilience is the word that we should really start using.”
The Trust Advantage: Compliance as a Competitive Differentiator
Here’s the part most compliance conversations miss. Doing this well isn’t just about staying out of trouble. Organizations that build continuous, verifiable trust at speed end up with something their competitors can’t easily replicate: the ability to move fast without constantly stopping to prove they’re doing it safely. The results show up in concrete business outcomes.
Brown has earned the right to talk about transparency more than anyone. Five years of legal exposure, a heart attack, a settlement he refused to sign. His view of what good looks like is grounded in lived consequence, not theory.
When the webinar audience was asked what “building trust through compliance” means most to their organizations, the answer was overwhelming: all of the above. Proving a defensible posture to regulators. Winning customer confidence. Reducing personal liability. Gaining competitive advantage. They’re not separate goals. They point at the same thing.
The Bottom Line
What organizations need in 2026 is continuous, automated, independently verifiable evidence that their systems are working as intended, all the time, not just when someone’s watching. The ones that build that infrastructure first won’t just keep regulators satisfied. They’ll have a structural advantage over every competitor still running on annual audits and paper certifications.
SolarWinds is the proof. A company hit by one of the most sophisticated nation-state attacks in recorded history, whose CISO faced personal securities fraud charges and a heart attack before those charges were dismissed, came out the other side with renewal rates above 98%. Because they were transparent from day one, rebuilt with genuine resilience, and refused to let the incident become a permanent liability.
That’s what trust looks like when it’s built properly. Any organization willing to do the work can get there.
Watch the full webinar here.