Third Party Threat Hunters

Gregory Rasner

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)

Episodes

  1. 1d ago

    Relationships Beat Tools In Vendor Risk with Heather Kadavy

    Send us Fan Mail Vendor risk doesn’t fail because you picked the wrong platform. It fails because nobody trusts the program, nobody speaks the business unit’s language, and everyone thinks it’s someone else’s job. We’re joined by Heather Kadavy, Director of Membership Success at the Third Party Risk Association (TPRA), to get honest about what actually moves third-party risk management forward when teams are lean, vendors are complex, and AI is changing the rules. We dig into the biggest myth in TPRM and supply chain risk management: that technology “solves” the problem. Heather lays out why relationships and governance matter more than automation in the early days of fixing a broken program, and how to earn first line buy-in by shifting from compliance talk to business impact. If your stakeholders only care about sales and speed, we walk through how to translate cyber vendor risk into outcomes they already track like revenue loss, operational disruption, customer impact, and regulatory exposure. From there, we get practical about resilience. Heather shares her “depth of three” strategy for training successors so TPRM survives turnover, plus the cultural marker of mature programs: leaving egos at the door and treating risk management as a team sport across security, compliance, finance, and the business. We also tackle shadow AI, AI governance, and fourth-party dependencies with concrete approaches like mapping critical business services, identifying concentration risk, asking direct AI questions, and combining continuous monitoring with human judgment where it counts. If you want a clearer, more effective vendor risk management program that partners with the business and improves nth-party visibility, hit play. Subscribe, share this with a colleague, and leave a review so more practitioners can find the conversation. Support the show

  2. 3d ago

    Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman

    Send us Fan Mail Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable. Key topics Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question: are financial institutions truly reducing vendor risk or mainly satisfying examiners?Michael Berman shares his background as a recovering attorney turned entrepreneur, plus 17 years leading End Contracts and prior experience handling third-party risk as general counsel.Michael says his morning routine is cardio for fitness and stress relief, and he identifies as a technology enthusiast who enjoys learning how new tech works.The conversation opens with Michael's book, The Upside of Third Party Risk Management, which argues that risk management can be an organizational advantage instead of just a fear-driven obligation.Michael says third-party risk is improving, but many programs still overfocus on point-in-time assessments instead of real-world monitoring and response.He uses the Dwell AI startup controversy as an example of why trust but verify matters, especially when funding, AI outputs, and vendor claims collide.Greg and Michael compare vendor reviews to employee reviews, arguing that vendors deserve at least as much ongoing attention as internal staff because they often have deeper access to data and systems.Michael explains the gap between traditional GRC and threat hunting: one asks whether a vendor was secure at onboarding, while the other asks whether something is happening right now that needs action.He emphasizes that organizations need both approaches, plus a shared taxonomy between cybersecurity teams and compliance teams, so risk ratings and threat intelligence align.Michael describes how vendor management must shift from static questionnaires to real-time governance, especially when incidents like MoveIt show the value of knowing which vendors and fourth parties are affected immediately.On fourth party and shadow AI risk, Michael says the governance perimeter has dissolved because vendors now rely on cloud, model providers, subprocessors, APIs, and other hidden dependencies.He recommends expanding governance from just the vendor to the data flows themselves, with continuous discovery, clear escalation paths, and the ability to cut off risky tools quickly.For AI vendors, Michael recommends stronger contractual controls, including notice of material model changes, AI incident notifications, clarity on subprocessors and model providers, and audit or evidence rights.Greg suggests using the term security assessment instead of audit in some cases to reduce friction, and Michael agrees that evidence rights are especially important.Michael cautions that startups can be attractive but risky if they cannot provide maturity, controls, or evidence comparable to more established vendors.Greg adds that vendor requirements should be positioned as business guardrails, not just a flat no, especially when regulators and enterprise risk thresholds are involved.Michael closes by noting that risk leaders should focus first on contractual controls and a usable framework, since those two tools can reduce the need for constant manual intervention.Timestamps 00:00 - Guest introduction and why third-party risk matters 01:14 - The upside of third-party risk management 02:08 - Why Michael would have chosen medicine 02:28 - Technology as Michael's unexpected hobby 02:59 - Favorite place to unplug by the ocean 03:29 - A recent non-business book recommendation 04:11 - Are banks reducing risk or just satisfying examiners? 05:00 - Why vendor failures and fourth parties matter more now 06:14 - Vendor reviews should be as routine as employee reviews 07:22 - Moving from static compliance to active threat hunting 08:14 - Point-in-time assessments versus live monitoring 09:22 - Cyber, financial, and business continuity risks are connected 10:50 - Turning vendor data into action instead of overload 11:43 - Shared taxonomy between security and compliance teams 12:17 - Real-time governance for critical vendors 13:14 - Why MoveIt showed the weakness of one-time vendor questions 14:03 - Why contract terms matter when breaches happen 14:59 - AI is making third-party governance much harder 17:44 - Why AI dissolves the governance perimeter 18:37 - Shadow AI and incomplete vendor inventories 20:02 - Why vendors may not understand their own AI supply chain 21:01 - Expand governance from vendors to data flows 21:57 - Continuous discovery and escalation paths 23:24 - Evidence requirements for AI vendors 24:53 - Material model-change notice and incident notification 25:55 - Security assessment versus audit language 26:52 - Evidence rights and documented validation 27:22 - Why startup AI vendors may be too immature 28:27 - How to push back when the business wants a risky vendor 29:25 - Regulators still show up after a breach 30:16 - Not every AI tool is equally critical 31:12 - Why leaders should not wait for regulation 32:14 - Pick a defensible AI risk framework and stick to it 33:23 - Final advice: contract controls plus a framework Key frameworks Point-in-time vendor assessment versus continuous threat huntingGovernance should cover both vendors and data flowsContractual controls should be built at relationship inceptionAI risk management should be supported by evidence rights, notice obligations, and escalation pathsRisk treatment should be proportional to the use case, not just the presence of AINotable quotes "You might have eight hundred vendors, but that doesn't mean I need to do threat monitoring for eight hundred vendors.""If it wasn't documented, it wasn't done.""Think about what contractual controls you can put in place at the inception of relationships to make your life easier."Action items Review vendor contracts for AI-specific notice, incident, and evidence obligations.Identify which vendors are critical enough to justify continuous monitoring.Build a shared taxonomy between security, compliance, procurement, and legal teams.Treat data flow visibility as part of vendor governance.Pick one defensible AI risk framework and apply it consistently.It works because the title and sectioning make the episode feel practical and high-value, while the timestamps and action items create instant scanability for busy LinkedIn readers. Support the show

    Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman
  3. Aug 25

    From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib

    Send us Fan Mail In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure. They discuss the growing risk of third-party access, the limits of traditional vendor assessments, and why inventory is the foundation of any serious third-party risk program. Ronan also explains how AI can help security teams separate true risk from alert noise, prioritize what matters, and move from reactive checklists to actionable security decisions. Key Topics Ronan’s background in offensive security, Microsoft Security, and BarclaysThe origin story behind Shift SecurityWhy vendor questionnaires are no longer enoughThe importance of knowing all third parties, known and unknownThird-party access as a major breach vectorAI agents, shadow AI, and third-party exposureUsing AI to reduce alert fatigue and prioritize real riskBuilding a third-party operational security program, not just a tool stackMain Takeaways Inventory is the first step to securing third parties.Risk management must account for both probability and impact.Vendor access is often more dangerous than vendor compliance gaps.AI can help filter noise, but only when it has strong business context.CISOs need a programmatic approach to third-party operational security.Notable Quote “We’re living in darkness until we understand what third parties exist, what access they have, and what they’re doing.” Why It Matters As third-party ecosystems grow more complex and AI agents become part of the security landscape, organizations can no longer rely on one-time assessments. This episode shows why visibility, continuous monitoring, and context-driven response are now essential for operational resilience. Guest Ronan, Co-founder and CEO of Shift Security Host Greg Mentioned Themes Third-party risk managementVendor access governanceAI exposureSecurity alert fatigueOperational resilienceContinuous monitoringWant me to turn this into a LinkedIn post next? Support the show

    From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib
  4. Aug 21 ·  Bonus

    Short: Map your critical dependencies before it's too late

    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once.Choose a service that directly affects customers, operations, revenue, or regulatory obligations.Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement.Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors.Ask what information and access each dependency has.Examine what could fail, be compromised, or behave unexpectedly.Define the intelligence signals that would tell you the risk is changing.Decide in advance what action to take if a dependency becomes unavailable or untrustworthy.Use the dependency map as a focused starting point rather than a massive transformation program.Support the show

  5. Aug 20 ·  Bonus

    Short: Starting Small with a Critical Service Dependency Map with Michael Rasmussen

    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once.Choose a service that directly affects customers, operations, revenue, or regulatory obligations.Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement.Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors.Ask what information and access each dependency has.Examine what could fail, be compromised, or behave unexpectedly.Define the intelligence signals that would tell you the risk is changing.Decide in advance what action to take if a dependency becomes unavailable or untrustworthy.Use the dependency map as a focused starting point rather than a massive transformation program.Support the show

  6. Aug 18

    The Evolution of GRC and Future Risks in Third-Party Ecosystems with Michael Rasmussen

    Send us Fan Mail In this episode, Michael Rasmussen, a leading expert in governance, risk, and compliance, shares insights into the origins of GRC, its ongoing evolution, and its critical role in managing complex third-party ecosystems amid rapid technological change. Discover how organizations can stay ahead of regulatory pressures and operational risks through innovative frameworks and proactive dependency mapping. Key Topics Covered: How Michael Rasmussen pioneered the GRC concept with the first market models in February 2002The seven generations of GRC, from Sarbanes Oxley-driven GRC 1.0 to GRC 7.0 focusing on orchestration and AIThe importance of treating risk as an appetite for value, not risk itselfWhy periodic risk assessments are insufficient in dynamic environments and the need for continuous intelligenceBridging the gap between technical threat detection and business risk perspectiveThe risks associated with opaque AI supply chains and shadow tech, and how to govern them proactivelyCritical dependencies in third-party ecosystems and how to map and manage them effectivelyPractical steps organizations can take today, such as dependency mapping and defining systemically critical vendorsThe role of organizational culture and personal routines in staying informed and resilientTimestamps: 00:00 - Introduction to Michael Rasmussen and his GRC background02:45 - The origin story: How the GRC acronym was created in 200205:00 - The seven generations of GRC: From reactive to orchestrated AI-driven frameworks09:00 - Common industry misconceptions and what should be retired in risk management11:12 - How personal experiences and career pivots shaped Rasmussen’s expertise15:13 - The future of vendor risk ecosystems and the dangers of shadow tech17:24 - Governing non-transparent AI supply chains ahead of regulation19:49 - Bridging the gap: Connecting technical threat intelligence with operational risk22:13 - The importance of contextual analysis over simple scoring in third-party risk24:32 - Risk management lessons from Star Trek and risk appetite misconceptions27:27 - Practical advice: Building dependency maps for critical business services29:09 - Final thoughts on identifying systemically critical vendors and ensuring resilienceWant me to turn this into a LinkedIn post next?Support the show

  7. Aug 13

    AI, Third Party Risk, and the Real Work of Operationalizing It with Paul Kurtz

    Send us Fan Mail Greg reviews how AI is changing third party risk management with Paul Kurtz, a 30 plus year financial services veteran and current third party risk leader at First Century Bank. They focus on what actually changes in banking when AI enters vendor risk workflows, from ongoing monitoring to questionnaire design and regulator conversations. This episode matters because it cuts through the hype. Paul explains how AI can improve visibility and efficiency without replacing judgment, and why the real task is learning how to use it safely, document it properly, and keep the right humans in the loop. Key topics Paul Kurtz’s background and perspective Paul shares that he has spent more than 30 years in financial services, starting in retail loss prevention, then moving into banking and fraud investigation, and eventually focusing on third party risk management for the last 14 to 15 years.He frames himself as an AI generalist rather than a cybersecurity or technology specialist, which shapes how he approaches vendor risk.Why AI clicked for third party risk Paul says he was drawn to AI training because it was framed through the lens of third party risk management, not as generic AI hype.That context helped him see how AI fits into the specific decisions and controls TPRM teams need.The biggest challenge in traditional banking Paul points to change management as the first major hurdle when introducing AI tools in a conservative financial environment.Cost is the second major issue, since teams need enough understanding to do due diligence, choose the right tool, and understand how third parties are using AI too.What banks should automate first Paul says ongoing monitoring is the biggest manual process that should be automated sooner rather than later.He argues that too many organizations still treat assessments like a one-time exercise instead of a living risk process.Why AI is useful in ongoing monitoring Paul describes AI-enabled monitoring as a way to watch for cyber threats, financial changes, and other risk signals without relying on manual fishing.The goal is not to automate judgment away, but to surface the right issues earlier.AI is not a magic bullet Paul emphasizes that AI is still maturing and that many vendors are rushing into the market.He rejects the idea that AI will simply replace people, comparing current fears to earlier waves around computers, the internet, cloud, and robotics.What changed after AI training Paul says the biggest practical shift was learning to ask not just whether a vendor uses AI, but how they use it, where they use it, and what data it touches.He uses those questions to deepen his Infosec questionnaire and focus scrutiny where it actually matters.Risk-based focus beats blanket fear Paul draws a clear line between low-risk uses, like a vendor using Copilot for internal meeting notes, and higher-risk uses, like AI making decisions or interacting with customers.The key is understanding scope, safeguards, and whether the use case could affect business outcomes or regulated data.AI affects more than cybersecurity Paul and Greg discuss how AI touches legal, compliance, privacy, and information security, not just IT.That makes cross-functional conversation essential.How to balance speed and safety in banking Paul says the best path is staying connected to how regulators are thinking and keeping communication open.He notes that regulators are increasingly asking questions and engaging on AI, rather than simply blocking it.How to work with regulators Paul argues that if you can show you considered the risk, documented your decisions, and followed your process, regulators usually respond well.Greg reinforces that the issue is often not the tool itself, but failing to follow the process.Where the industry is headed Paul notes that a cottage industry is forming around AI assessments, frameworks, and advisory work.Greg adds that even AI agent evaluation has become a real consulting opportunity.Best first step for banks starting out Paul recommends learning the basics through training and then applying that knowledge to vendor populations.He warns that the danger is either moving too fast without understanding AI or too slowly and missing the competitive advantage.Community and peer learning matter Paul and Greg both stress that third party risk professionals benefit from sharing best practices instead of treating knowledge as proprietary.They encourage joining industry groups, attending events, taking certifications, and reaching out to peers directly. Notable quotes "I am not a cybersecurity specialist. I am not a technology specialist. I consider myself an AI generalist." "This is not a magic bullet." "The regulators are going to tell you what to do, but not how to do it." Episode Title Title 1:  Why AI Won’t Replace TPRM Teams—But Will Change Them Fast Why it works: This title hits the core tension in the episode: fear of replacement versus the reality of augmentation. It speaks directly to third-party risk professionals worried about AI, while promising a practical, balanced perspective rather than hype. Title 2:  The AI Blind Spot Banks Keep Missing in Vendor Risk Reviews Why it works: This creates urgency by framing AI as something banks are overlooking, which triggers concern and curiosity. It also targets the exact audience most likely to care: banking and vendor-risk leaders who suspect their current reviews aren’t enough. Title 3:  How One TPRM Leader Turned AI Training Into Better Vendor Questions Why it works: This title offers a clear transformation story: training leads to smarter due diligence. It’s specific, credible, and appealing to practitioners who want an actionable payoff, not abstract theory. Title 4:  Set It and Forget It Is Dead: Why Ongoing Monitoring Must Be Automated Why it works: This uses a punchy, familiar phrase to create instant recognition and tension. It taps into a real pain point in TPRM—stale assessments—and promises a timely operational insight for busy risk teams. Title 5:  The Real Risk Isn’t AI Itself—It’s Using It Without a Framework Why it works: This reframes the conversation in a way that feels smart and contrarian. It appeals to risk and compliance professionals by emphasizing governance, process, and control rather than panic, which makes it highly shareable across business and regulatory audiences. Recommended: Title 5 — It’s the strongest mix of contrarian insight, clarity, and broad relevance, and it cleanly captures the episode’s main message about governance over fear. Want me to turn this into a LinkedIn post next? Support the show

    AI, Third Party Risk, and the Real Work of Operationalizing It with Paul Kurtz
  8. Aug 11

    Navigating Third-Party Risk and AI in Cybersecurity with Rachel Curran

    Send us Fan Mail In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape. Key Topics Rachel’s background in GRC and her passion for security and complianceThe role of AI in accelerating vendor assessments and risk managementThe importance of human-in-the-loop for effective governance at speedBridging the governance gap by focusing on actual enforcement over paperworkHow AI influences remote vendor onboarding and real-time data exchangeCritical security risks introduced by AI agents, especially access controlThe shift from static to dynamic, self-optimizing AI-driven vendor risk profilesThe evolving threat landscape and the dangers of AI-enabled malicious actorsPractical strategies for organizations: going back to fundamentals and prioritizationThe significance of frameworks and continuous updating of security programsHow to leverage evidence packs and automation for ongoing compliance verificationTimestamps 00:00 - Introduction to Rachel Curran and her expertise in GRC 01:17 - Rachel’s career journey and motivation in cybersecurity 02:37 - Personal interests: favorite travel destinations and favorite fruit 03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive 06:27 - The challenge of governance at speed in the AI era 07:00 - Human oversight’s critical role in AI-driven risk management 08:47 - Managing governance gaps through prioritization and verifiable data 10:11 - The biggest governance gaps organizations face today 11:37 - Using automation to improve vendor visibility and risk assessments 12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it 14:02 - The fallacy of paper policies versus actual practice in governance 15:40 - Data dependence and the importance of real-time controls and backups 16:07 - The impact of AI on third party risk landscape over the next 12-18 months 16:42 - Risks from AI-enabled access control and recent AI breach incidents 18:12 - Managing AI agents’ permissions and preventing privilege creep 20:30 - The threat of AI agents executing malicious or unintended actions 22:08 - The necessity of quality data, transparency, and human oversight 24:06 - Moving away from point-in-time assessments toward continuous, evidence-backed evaluations 25:00 - The potential to improve vendor transparency with real-time info sharing 26:12 - How AI can support dynamic security assessments and ongoing compliance 27:21 - The importance of foundational security controls and a risk-focused mindset 28:13 - Tactical action: back to basics—understand your vendors and their risk posture 29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring Final Takeaways Focus on fundamental security controls and verifiable data to reduce risks Prioritize vendors based on actual risk to manage resources effectively Use automation and frameworks for continuous compliance and rapid response Recognize AI as a tool to augment, not replace, human judgment and oversight Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management. Want me to turn this into a LinkedIn post next? Support the show

About

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)