Adeel Saeed of Kyndryl, chief technology officer CTO for global cyber resiliency, discusses Kyndryl's approach to software supply chain security and Chainguard adoption at Chainguard Assemble 2026. In this theCUBE Research interview hosted by Paul Nashawaty and Rebecca Knight, Saeed highlights Chainguard adoption strategies and shifting vulnerability checks left into the build process; they also address improvements to the software development life cycle SDLC, open source governance, developer experience platforms and preparation for agent-driven observability across global engineering teams.
Saeed presents practical adoption tactics and measurable key performance indicators. They report that Kyndryl drives adoption with a unified developer platform, guardrails, mandatory training and a hard enforcement date, reaching roughly 70–80% adoption. They emphasize trust but verify for open source, treat the software bill of materials SBOM as a must-have and focus on agent inventory, observability and security to harden the software supply chain.
This interview provides actionable guidance on DevSecOps, vulnerability management, container security, developer experience and supply chain security for enterprise engineering and security teams. Watch to learn deployment strategies, governance practices and metrics to measure adoption success.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Chainguard Assemble 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Chainguard Assemble 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Chainguard Assemble 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Chainguard Assemble 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Chainguard Assemble 2026
Please sign in with LinkedIn to continue to Chainguard Assemble 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Adeel Saeed, Kyndryl
Adeel Saeed of Kyndryl, chief technology officer CTO for global cyber resiliency, discusses Kyndryl's approach to software supply chain security and Chainguard adoption at Chainguard Assemble 2026. In this theCUBE Research interview hosted by Paul Nashawaty and Rebecca Knight, Saeed highlights Chainguard adoption strategies and shifting vulnerability checks left into the build process; they also address improvements to the software development life cycle SDLC, open source governance, developer experience platforms and preparation for agent-driven observability across global engineering teams.
Saeed presents practical adoption tactics and measurable key performance indicators. They report that Kyndryl drives adoption with a unified developer platform, guardrails, mandatory training and a hard enforcement date, reaching roughly 70–80% adoption. They emphasize trust but verify for open source, treat the software bill of materials SBOM as a must-have and focus on agent inventory, observability and security to harden the software supply chain.
This interview provides actionable guidance on DevSecOps, vulnerability management, container security, developer experience and supply chain security for enterprise engineering and security teams. Watch to learn deployment strategies, governance practices and metrics to measure adoption success.
Practice Lead and Principal AnalysttheCUBE Research
HOST
Rebecca Knight
HostSiliconANGLE Media
HOST
In this interview from Chainguard Assemble in New York City, Adeel Saeed, chief technology officer of global cyber resiliency at Kyndryl, joins theCUBE's Rebecca Knight and theCUBE Research's Paul Nashawaty to discuss how one of the world's largest managed service providers is embedding security directly into the developer workflow without sacrificing engineering velocity. Saeed explains why Kyndryl adopted Chainguard as a utility-grade capability within its software development lifecycle, enabling thousands of engineers across heavily regulated global enviro...Read more
exploreKeep Exploring
Why did Kyndryl decide to adopt Chainguard, and how does it fit into Kyndryl’s security posture and SDLC as a large, global managed service provider?add
How did Kyndryl manage the cultural and process changes involved in shifting vulnerability checks left to build time when adopting Chainguard, and what steps were taken to drive developer adoption?add
What challenges, pain points, and trust issues did you encounter in getting developers to adopt a new development platform/tooling, and how did you address them?add
>> Hello everyone and welcome back to theCUBE's coverage of ChainGuard Assemble here in the Big Apple, New York City. I'm your host, Rebecca Knight alongside Paul Nashawaty, principal analyst here at SiliconANGLE Media. I would like to welcome to the show for the first time ever, Adeel Saeed, CTO Global Cyber Resiliency at Kyndryl.
Adeel Saeed
>> Thank you for having me.
Rebecca Knight
>> Thank you so much for coming on the show. So for viewers who are a little bit less familiar with Kyndryl, Kyndryl operates at a scale that most organizations can only imagine managing infrastructure across some of the world's largest enterprises. Talk a little bit about how you're a customer of Chainguard, how you use Chainguard and what you use it for.
Adeel Saeed
>> Absolutely. So first of all, thank you for having me. Second, Kyndryl being a large MSP and servicing large enterprise clients that are heavily regulated, not locally, but globally. The owners kind of falls on us to make sure we are secure by design. That's the first thing, as a managed service provider. Secondly, we develop applications for our customers. We are developing, we're managing the infrastructure, what we call it, we are the hearts and lungs of our customers. Sometimes we end customers more than the CEOs of those companies are there because the infrastructure teams are kind of there and they outlive any management change. But at the end of the day, what matters is we're also a third party. And third party risk is a key tenant in many of our customer agreements. The reason we started looking at Chainguard as an example was, again, we develop applications, our SDLC processes, for those that don't know SDLC, software development lifecycle process were robust, but they were not fully fine grade. So in an effort to improve our security posture, we started looking at companies that provide that capability almost as a utility because we want our engineering teams to focus on high value work versus... It's not low value, but versus remedial work. I mean, you create a golden image one day and then tomorrow it's not golden anymore. There are tons of vulnerabilities out there. So we started working with Chainguard almost a year ago in looking at how the product will operate in our environment. Again, we are large, we are global. We have a couple of thousand engineers out there, and we have heavily regulated customers that are demanding the right security posture. So that's what drove us to look at Chainguard and almost adopt it from a utility standpoint to complete our security posture versus looking at it as just a placeholder.
Paul Nashawaty
>> Yeah, that makes a lot of sense. I like where you were going with the whole SDLC piece. The thing that I find incredibly interesting and taking it right out of the keynote this morning, the environments have changed a lot with organizations from having vulnerabilities checked post code delivery to having it checked pre-code built.
Adeel Saeed
>> Absolutely.
Paul Nashawaty
>> So it's moving further and further left, if not just across everywhere. How do you see that from a culture change, from a process change? What did that mean from the Kyndryl's adoption of using Chainguard, especially when you're looking at releasing code at the build time to do the vulnerability checking?
Adeel Saeed
>> You're absolutely right. It's a culture change. It's an adoption mechanism, right? I mean, folks are used to certain ways of working for years and now suddenly you have to change the posture. You have to change posture in a way on how you're adopting the tool. So the challenge wasn't getting the tool within the organization. The challenge was how do you have adoption? And a few ways we did that, right? We put guardrails into place and the guardrails kind of came first as how do we not force the developers to use it, but how do we create an ecosystem where there's natural adoption coming into play? So that's how we did it. By using simply, I mean, a development platform, because many companies don't use development platforms. You're directly connecting to your Git repos or you're connecting to your JFrog artifacts. What we did is we created a developer experience and that developer experience forces all the engineers to use that one interface to create an image, create a repo, write code. And you're right, it's far shifted left. So from inception to grave, right? Until you use the code and then it gets recycled, we actually are putting people through that platform basically.
Rebecca Knight
>> You make adoption sounds so easy. Can you talk a little bit about maybe some of the pain points and some of the trust issues involved in getting such a massive change management of getting your developers using this new tooling?
Adeel Saeed
>> You're absolutely right. I'm giving ourselves a lot of credit because the team did a great job. But no, you're right. It's a culture change plus also it's why can't we do it ourselves? And that mindset really can only be changed by showing and demonstrating the value the product provides. And it's not an easy adoption for us. I mean, we are there. We have been using it for almost a year now, but we are probably 70 to 80% adopted in that process. We have multiple languages that we use, right? And these images, these libraries keep rotating on a daily basis. So what we did is outside of the horror stories are very simple. It's not people don't want to adopt, they don't have time.
Paul Nashawaty
>> Yeah. Well, it's interesting they say it like that because a lot of times I hear developers are unique individuals, right? They definitely like their bespoke tools.
Adeel Saeed
>> Absolutely.
Paul Nashawaty
>> And to force them to change something causes a whole lot of disruption.
Adeel Saeed
>> It does.
Paul Nashawaty
>> So I think having Chainguard feed the information, the insights into the IDE, that makes a lot of sense, right?
Adeel Saeed
>> Yes.
Paul Nashawaty
>> And ID of choice, right? Because if they're using specific tool sets and whatever, that makes a lot of sense. So I like that you've, from a culture, from a company perspective that you're looking to standardize, one of the things that kind of comes to mind is standardization usually helps with operation efficiencies. And when you look at that from the open source community, like we look at open source, the scale of taking open source technologies and the modern enterprise infrastructure, how has that pivoted and changed your adoption? Because I would imagine prior to this kind of standardization, you probably had a number of bespoke solutions kind of going on at the same time and maybe siloed even.
Adeel Saeed
>> So first of all, being a tech company, I mean, we spun out of IBM back in 2021, so it's not new to us on how to kind of operate in that. But I'm glad you asked the question because the first thing is, it wasn't about adoption or open source adoption, because open source is core to our strategy. And in order to have a discipline open source approach, you need to have the right level of governance in place. So we have layers of governance, legal, an open source forum that brings all these things in and make sure any adoption that we are doing or contribution goes through a fine grain process. The process is great, governance is great, but people can bypass it, right? So how do you put the right guardrails in place for people to facilitate and adopt the solution itself? Again, Chainguard provided a utility that came in to saying, "Hey, guess what? Open source, trust, but verify. How do you adopt it? Absolutely a challenge, but how do we put that as part of our governance process?" And again, now with the whole agentic enablement, our agents being created, it becomes less of a utility and more of a requirement because those images that are being created in Python, as an example, in different libraries have a different connotation to it. So we almost are evolving ourselves, getting ready for the next gen of coders coming out or engineers. And again, you're right. I mean, engineers are so busy and they have less time, more product to release-
Rebecca Knight
>> And I'll put a very distinct point of view about how things should be done too.
Adeel Saeed
>> Absolutely. You're right. And they're very opinionated, but at the same time, what our approach in securing our processes was not imposing these rigid thou shall do this and thou shall do that. We always wanted to make sure that we empower our developers and our engineers to be more productive by securing the backend. And you're right, it didn't take us a week or two. It took us a year globally going across evangelizing. There's two things that are constant that we did. Training, communication, training, communication, training, communication, and then a hard date. By this date, we shall move on. Plus what we also did is we also instilled what we call security training for all our engineers. And the training modules, we introduce Chainguard and we introduce the product. So not anyone that needs access to any repos has to go through a training process. So we are almost doing the enforcement site on two bookends, but we are driving that through adoption and through collaboration versus a hard no.
Rebecca Knight
>> So you are a CTO and security leaders often know exactly what the technical risks are and what they're talking about, but it's a challenge sometimes to make it land in the greater boardroom. So I'm interested to hear how you personally translate what these vulnerabilities mean and represent to other executives who aren't necessarily as tech focused as you and as aware of them and what best practices have emerged from your-
Adeel Saeed
>> Definitely it's not an easy task to translate English to German and German to English. What we did is we used a very simple approach of risk management. In terms of what business understands, as I mentioned, many of our customers, all our customers, our enterprise customers, heavily regulated. So we have contractual obligations to them to make sure we have a secure environment, which any infrastructure service provider does. The second thing is, we also then put it in terms of risk. The risk that we carry today in not having something that is a constant is moving us away from productivity and developing our product. As long as you can explain that in terms of dollars and cents, but more importantly, in terms of risk posture management, right? Because I did not go and say, "Hey, we have a million vulnerabilities as an example, and how do we fix it?"
Because a million to me might be 500,000 to you. No two vulnerabilities are the same. What we said is, "Hey, vulnerabilities will be there as long as humans are writing code." Computers don't make mistakes, we do as humans, but at the same time, how do we make sure we provide the right guardrails? It was a very simple, and it wasn't simple. I'm simplifying everything. It's 4:00 PM, but it was simple in the sense that we drove the business case to a very KPI driven approach. First is how do we get developer efficiency? When I say efficiency, it's how do we have our developers focus on high value attributes versus low value tasks? And the second was, how do we actually manage our risk posture and drive it down?
Paul Nashawaty
>> I really think that there's a lot here that makes a lot of sense. You focus translating those values to business values. It makes a lot of sense. It's a tough job because sometimes people just don't understand what really is under the tech stack. I do want to ask one more question on open source when you're looking at, from a trust perspective, it's a big area where many organizations want that open source ecosystem. They want to have that flexibility. They want to have the ability to use these different tech stacks of their choice.
Adeel Saeed
>> Absolutely.
Paul Nashawaty
>> But they also need to know how they can trust it. So what does trust open source look like to your practice?
Adeel Saeed
>> Trusted open source to me is, or to our organization and me as well, making sure that you have the right authoritative source that you're getting the open source from. You have the right legal wrap around it and you make sure that it's certified. When I say certified, it goes through our governance process. Now again, that's one element of it. As somebody asked a question recently, they're like, "Hey, you can get an image that has zero vulnerabilities in there, pre-production." And then somebody touches that and you introduce vulnerabilities. How do you manage that? And again, you need to have not safeguards just on the starting point, but also when you're releasing code into production. How are you managing that security posture, not just from when you write code, but also when you're promoting code. And open source is that ecosystem that we all breathe at the end of the day. So trust but verify becomes a key tenant and your CI/CD automation needs to have the right security tools to make sure you test it, validate it, and then deploy it.
Paul Nashawaty
>> Makes sense.
Rebecca Knight
>> So the software supply chain conversation has been getting louder in recent years, particularly after SolarWinds and lock for Shell. Do you think that the industry is actually making progress or is it still mostly in reactive mode?
Adeel Saeed
>> That's an excellent point. I think it's passive-aggressive right now, right? Because you only talk about your software bill of materials when you have an issue. And you almost talk about SEA, which is a software composite analysis when you might want to have an issue. Now with the way agents are being driven right now, SBOM becomes not a you should have, but it's a must have. You need to have your SBOM in place in order to identify your open source, your agents, and the inventory. There are three constants in the agentic world, your inventory of your agents, observability of your agents, and security of your agents. It's not security by design, it's how you secure the agents is where the mantra is.
Rebecca Knight
>> Well, that was a fantastic note to end on, Adeel. Thank you so much for coming on the show.
Adeel Saeed
>> Thank you so much for having me. Appreciate it.
Rebecca Knight
>> That wraps up theCUBE's coverage of Chainguard Assemble 2026 here in New York City. I'm your host, Rebecca Knight. For Paul Nashawaty, you've been watching theCUBE, the leader in enterprise tech news and analysis.