Third Party Threat Hunters

Gregory Rasner

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)

  1. 2d ago

    Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS

    Send us Fan Mail Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor. We dig into questionnaire fatigue and the trap of treating checklists as controls. A static security questionnaire can’t tell you whether a control exists today, whether it’s sufficient for your specific integration, or whether your internal use case has quietly drifted since onboarding. We walk through concrete examples like marketing analytics tools that are low risk with anonymized data but high risk when fed PII or tied to business critical operations. The takeaway is a simple shift: stop asking “is the vendor secure” and start asking “are our use cases secure.” Then we get practical about AI in cybersecurity and vendor risk management. Forget the hype about AI agents auto-filling 400 questions. The real value is correlation: pulling context scattered across contracts, documentation, procurement systems, emails, and Slack into one place so a human can make a defensible decision and prioritize the right actions. We also connect third-party risk to zero trust, covering privileged access management, identity-bound sessions, and just-in-time access, plus why continuous assessment matters far more than an annual review. If you want a step you can take this week, we share a lightweight “context graph” exercise for your 10 most critical vendors that clarifies data access, dependencies, and what happens if a vendor fails. Subscribe, share this with a teammate in security or procurement, and leave a review with your biggest vendor risk blind spot. Support the show

  2. 4d ago

    The Vendor Trust Gap with Bill Haber

    Send us Fan Mail Your vendors are not “outside” your business anymore. When an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access. We talk with Bill Haber, co-founder and CEO of Tekrisq, about how to build third-party risk management that earns real trust instead of producing paper compliance that looks good until it fails. We get blunt about security questionnaires: why flat, self-attested checklists create an attestation gap, why yes-no scoring collapses nuance, and how branching, point-and-click assessments can surface clearer risk signals using language vendors actually understand. We also dig into what business leaders and TPRM teams should ask for when evaluating service providers, including architecture choices, back-end tooling exposure, incident readiness, and the financial risk dimension like coverage limits and breach preparedness. Then we move into the messiest frontier: AI in the supply chain. We break down how AI agents increase speed and blast radius, why shadow AI is spreading across organizations, and how fourth-party risk grows when your vendor’s “AI features” depend on external LLM providers and shared cloud platforms. We close with a practical action item: what continuous monitoring should mean in 2026, with EDR, logging, and vulnerability management that goes beyond point-in-time scans. If you want a vendor risk program that’s defensible, collaborative, and built for modern supply chain security, subscribe, share this with a teammate, and leave a review with the toughest vendor question you think everyone should be asking. Support the show

  3. Sep 15

    Sanctions Ready Third-Party Risk with Michael Volkov

    Send us Fan Mail Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens when regulators decide your controls were never built to see the end user in the first place.  We also dig into the enforcement trend line: DOJ’s National Security Division is leaning in, and sanctions cases can now resemble classic FCPA outcomes with coordinated settlements, criminal exposure, and painful fines. The practical question is simple: if the government asks why you did business with a third party, can you pull a complete, auditable due diligence file that shows your screening, your OSINT research, your beneficial ownership checks, and your documented compliance sign-off? If your evidence lives in emailed questionnaires and scattered attachments, we explain why that approach breaks the moment there is a subpoena, an investigation, or a breach.  Then we widen the lens to today’s vendor ecosystem, where cybersecurity and AI governance are inseparable from third-party due diligence. Vendors can become the pathway into your systems, and AI tools can create liability when they act on your behalf, especially in HR hiring decisions. We share a clear next-step mindset: automate onboarding workflows, build cross-functional partnerships with procurement and IT, and put AI guardrails and a framework in place so the program can evolve without chaos. If this helps, subscribe, share the episode with a colleague, and leave a review with the biggest third-party risk you are tackling right now. Support the show

  4. Sep 10

    Treat Vendors As Part Of The Enterprise with Julie Giaischi

    Send us Fan Mail Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction. We dig into a core myth that still drives bad decisions: scaling third-party risk management based on the number of vendors. Julie explains why mature TPRM scales by risk and strategic impact, not raw volume, and why soft skills like communication and relationship building become even more critical as AI changes what “doing the work” looks like. We also unpack why standardized questionnaires can create assessment fatigue when they’re treated as a checkbox, and how evidence-based testing and continuous monitoring better reflect the real control environment. From there, we get practical about the future: AI-powered vendor risk tools, trust portals, and the move toward near real-time assurance that can become predictive, not just reactive. We also address the governance side of AI, including the risk of feeding vendor data into frontier AI when contracts and confidentiality rules say you cannot. Finally, we break down nth-party and fourth-party supply chain risk, including a simple set of questions to identify which sub-tier providers are truly material, plus how to translate benchmarks and risk metrics into board-level messaging that supports budget and action. If you found this useful, subscribe, share it with a risk leader who is drowning in questionnaires, and leave a review with your biggest TPRM challenge. Support the show

Ratings & Reviews

About

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)