『Third Party Threat Hunters』のカバーアート

Third Party Threat Hunters

Third Party Threat Hunters

著者: Gregory Rasner
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)

© 2026 Third Party Threat Hunters
マネジメント マネジメント・リーダーシップ 経済学
エピソード
  • Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS
    2026/09/24

    Send us Fan Mail

    Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor.

    We dig into questionnaire fatigue and the trap of treating checklists as controls. A static security questionnaire can’t tell you whether a control exists today, whether it’s sufficient for your specific integration, or whether your internal use case has quietly drifted since onboarding. We walk through concrete examples like marketing analytics tools that are low risk with anonymized data but high risk when fed PII or tied to business critical operations. The takeaway is a simple shift: stop asking “is the vendor secure” and start asking “are our use cases secure.”

    Then we get practical about AI in cybersecurity and vendor risk management. Forget the hype about AI agents auto-filling 400 questions. The real value is correlation: pulling context scattered across contracts, documentation, procurement systems, emails, and Slack into one place so a human can make a defensible decision and prioritize the right actions. We also connect third-party risk to zero trust, covering privileged access management, identity-bound sessions, and just-in-time access, plus why continuous assessment matters far more than an annual review.

    If you want a step you can take this week, we share a lightweight “context graph” exercise for your 10 most critical vendors that clarifies data access, dependencies, and what happens if a vendor fails. Subscribe, share this with a teammate in security or procurement, and leave a review with your biggest vendor risk blind spot.

    Support the show

    続きを読む 一部表示
    23 分
  • Short: Surprise! There's AI in your Enterprise with Bill Haber
    2026/09/23

    Send us Fan Mail

    Many organizations don't realize how far AI is into their systems

    Support the show

    続きを読む 一部表示
    1分未満
  • The Vendor Trust Gap with Bill Haber
    2026/09/22

    Send us Fan Mail

    Your vendors are not “outside” your business anymore. When an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access. We talk with Bill Haber, co-founder and CEO of Tekrisq, about how to build third-party risk management that earns real trust instead of producing paper compliance that looks good until it fails.

    We get blunt about security questionnaires: why flat, self-attested checklists create an attestation gap, why yes-no scoring collapses nuance, and how branching, point-and-click assessments can surface clearer risk signals using language vendors actually understand. We also dig into what business leaders and TPRM teams should ask for when evaluating service providers, including architecture choices, back-end tooling exposure, incident readiness, and the financial risk dimension like coverage limits and breach preparedness.

    Then we move into the messiest frontier: AI in the supply chain. We break down how AI agents increase speed and blast radius, why shadow AI is spreading across organizations, and how fourth-party risk grows when your vendor’s “AI features” depend on external LLM providers and shared cloud platforms. We close with a practical action item: what continuous monitoring should mean in 2026, with EDR, logging, and vulnerability management that goes beyond point-in-time scans.

    If you want a vendor risk program that’s defensible, collaborative, and built for modern supply chain security, subscribe, share this with a teammate, and leave a review with the toughest vendor question you think everyone should be asking.

    Support the show

    続きを読む 一部表示
    27 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません