Nimrod Partush on how AI is reshaping third-party risk, and why visibility is the new challenge for supply chain cybersecurity

Nimrod Partush is Chief AI & Innovation Scientist at cybersecurity firm Cye, where he leads what he calls an in-house ‘innovation office’. With a PhD in Computer Science and a background in an elite IDF cybersecurity unit, Nimrod sits at the intersection of AI capability and cyber threat. As AI adoption races ahead of the safeguards designed to contain it, we speak with Nimrod about what supply chain leaders can learn from Cye’s 2026 Global Cybersecurity Maturity Report.

1. Let’s start with an introduction to you and your career.

I came to Cye with an entrepreneurial background. Before joining, I’d bootstrapped my own company building machine learning solutions for cybersecurity insights, on top of hands-on experience from an elite IDF cybersecurity unit and a PhD in Computer Science from the Technion. When I joined Cye about four years ago, it was as a data scientist doing purely engineering-focused work. I kept finding myself drawn into product questions, things like why we were doing something and what we should be doing next, and that pulled me toward innovation. I think of it as an in-house ‘innovation office’: a place to chase moonshot ideas while staying tightly connected to the business. That combination, being a scientist who’s still oriented around what the market and customers need, is how I ended up in my current role.

2. How have your experiences shaped how you apply AI tools to security problems?

Honestly, AI today is so different from the AI of my PhD or Army years that the technical specifics don’t carry over directly. What does carry over is discipline. First, making sure things are built correctly: asking the right requirements questions and holding AI systems to a high bar for robustness. Second, knowing where the genuinely hard problems live, and closely monitoring and verifying what the AI produces there. I saw this constantly in research. If you hand a model a hard problem and you don’t already know the answer, it will confidently give you a wrong one, and if you don’t know better, you’ll just use it. That instinct for spotting where AI needs close supervision is probably the biggest carryover from my research background.

Nimrod Partush
Nimrod Partush

3. What initially attracted you to Cye?

I joined Cye as a data scientist doing hands-on engineering work, building out the data science function essentially from scratch, using the scale and specificity of the cybersecurity data Cye had already amassed. Over time, that work naturally expanded beyond pure engineering into product and strategy questions, which is what eventually led to my current innovation-focused role.

4. What does a day in the life of a Chief AI & Innovation Scientist at Cye look like?

It’s still very hands-on. A lot of my time is spent writing code, often with AI, and looking at issues, bugs, and new features or models. I stay close to that work myself and with my team. Beyond that, a big part of the role is conversations, with R&D, product, marketing, and customer success, getting their feedback on what we’re doing and what’s missing, and keeping an eye on what’s happening in the industry and with AI more broadly. Sometimes that’s targeted, like testing an idea with people and hearing their reactions, but it can be a completely different conversation that surfaces a new opportunity. So it’s really research and execution in tandem: research through those stakeholder conversations, and execution on whatever meets the business need.

The one thing I’ll stress is that innovation only counts if it reaches production. It doesn’t matter how ‘moonshot’ a feature is, if customers can’t touch it, I don’t count it. I’ve seen plenty of research efforts that sound impressive but never leave the whiteboard or the lab, and to me that’s not real innovation. You can’t innovate if users can’t see it, touch it, or consume it, even in a small way.

5. Considering your position at the intersection of AI capability and cyber threats, what is your view on how these two concepts interact? How do you decide which emerging AI developments require Cye’s research attention?

Attackers are getting enhanced and accelerated, but so are defenders. The whole cycle just moves faster now. If anything, I’d say attackers currently have an edge, because it’s harder to build and maintain something robust than it is to find ways to break it, especially as more development means a bigger attack surface. That’s connected to what we internally call the exploitability gap: attackers have a larger attack surface and very strong capabilities, and it’s a dynamic that’s genuinely getting harder to keep in check in some cases.

As for what earns Cye’s research attention, a big part of it comes directly from our clients. They see developments happening and come to us with concerns, and that steers a lot of our roadmap. The other part comes from being a cybersecurity company ourselves. We must develop secure code and face these same challenges internally, and what we learn from operating in that space, we bring back to the rest of the industry.

6. Can you give us an overview of the research behind Cye’s 2026 Global Cybersecurity Maturity Report? What data points surprised you the most?

The report draws on more than 2400 assessments across 21 countries and 16 industries, scored against NIST’s Cybersecurity Framework (CSF 2.0) and, for the first time this year, against the NIST AI Risk Management Framework (AI RMF 1.0). We derived that by mapping existing CSF function scores onto the four AI RMF functions, with AI-specific findings pulled out through keyword and NIST subcategory analysis. Connecting data we already had to a genuinely new, AI-oriented framework, since there wasn’t an established benchmark for AI risk maturity before this.

The data point that stands out most to me is that 88 percent of organizations are already using AI, yet their average AI risk maturity sits at just 2.35 out of 5, barely inside the ‘Managed’ band. It’s not that organizations are unaware of the risk, as governance is consistently the highest-scoring function in both frameworks we measured. It’s the functions that turn that awareness into action – Protect in cybersecurity and Manage in AI – that score lowest across the board. The real headline for me isn’t that AI adoption is outpacing security. It’s that organizations know exactly what they should be doing and still aren’t doing it at anywhere near the same rate.

7. The report describes AI turning third-party risk into a ‘moving target’. What does that look like in practice and how can organizations regain visibility?

Supply chains used to consume data and services from third parties in a deterministic way, classic APIs. Now, that’s shifting toward agents talking to agents, and consuming vendor systems via MCP. Everyone wants their own platform to be able to connect to and pull from a vendor automatically. That’s the core of the transition: from deterministic API usage to agent-to-agent, MCP-based data flow.

On visibility, at a basic level it’s a question of AI visibility generally, understanding things like token consumption and what your agents are pulling from third parties. On risk specifically, the emerging risks are things like inaccuracy, injection, and operational-continuity risk. Because a vendor’s agent output is itself AI-generated, it can introduce real problems. For example, a ticketing agent fed by a vendor’s agent could generate a ticket recommending deletion of part of a production environment because it looks ‘unstable’, or recommend elevating a user’s privileges unnecessarily. These aren’t hypothetical, variations of this have already happened in real incidents.

8. Why are supply chain-adjacent industries lagging in terms of AI exposure, and what can they learn from the leaders?

As we put it in the report, the AI attack surface is already here: in the tools you’ve sanctioned, the ones you haven’t, and a supply chain you can’t fully see. The numbers back that up starkly. Shadow AI exposure, meaning AI use that’s outside an organization’s visibility or governance, is 71 percent in transportation and 62 percent in energy, against just five percent in financial services. That’s roughly a fourteen-times gap between the most and least exposed sectors, and it lines up almost exactly with supply-chain-heavy, critical-infrastructure industries versus the most tightly regulated one.

The reason isn’t that transportation and energy companies are careless, or that banks face fewer threats. It’s regulation. Financial services has spent two decades building mandatory visibility and governance requirements around technology risk, so when AI showed up, the infrastructure to catch it was already there. Supply chain-adjacent industries mostly haven’t faced that same regulatory pressure yet, so AI use is spreading faster than anyone is tracking it.

What the leaders show is that compliance should be treated as a floor, not a ceiling. The sectors that improved fastest this year – Switzerland jumped 16 percent in overall cyber maturity, for instance – did so right after new regulatory deadlines came into force, not because they simply spent more money. The practical lesson for supply chain-adjacent industries is not to wait for a mandate. Start building the same kind of AI inventory, vendor risk criteria, and monitoring that regulation eventually forces on financial services, before a deadline, or an incident, forces the issue instead.

9. What should supply chain executives be asking their partners and suppliers about AI risk?

First: how does the vendor ensure the accuracy, safety, and robustness of their AI systems? What metrics and monitoring are they using to make sure their AI doesn’t run wild or create risk? Beyond the vendor’s own safeguards, organizations need to start protecting themselves from AI interactions even with trustworthy vendors. Right now, when one agent talks to another, or you consume an MCP, the result that comes back is usually just trusted outright. There’s rarely a middle layer inspecting it before it’s acted on. I’d strongly encourage organizations to start adding that layer, because ultimately this is AI-generated content, and you need to protect yourself from it accordingly. It’s an emerging risk I think we’re going to hear a lot more about.

10. How do you see AI reshaping supply chain security over the next five years?

Honestly, I’m about as optimistic or concerned as I was before AI came along. Like any new technology, it has the potential to do damage and the potential to do good. For every piece of malicious AI-generated content, there can be an agent on the other side defending it. The status quo holds; it just moves a lot faster now. I remember when the AI revolution started, everyone assumed software development would be unrecognizable – much faster, better, and with far fewer bugs. That’s not really what happened. It is faster, but the same challenges are still there, and arguably there are more bugs simply because more code is being written. There’s no silver bullet. Even with AI, you can’t hand a non-technical person the keys to a production-grade system and expect it to hold up, the complexity of managing that is still real.

11. What is one thing you wish people would ask about you, your career, or AI in general – and why?

I’d want people to ask how I make sure the things I build are actually aligned, accurate, and correct, given how fast AI development moves right now. That’s the question that matters most to me: keeping AI in check and making sure everything stays correct as the pace accelerates.

Read the full report here