Mike Day is joined by Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, for a wide-ranging conversation on third-party cyber risk management (TPRM). They cover why questionnaires alone are no longer enough, how dynamic monitoring and cyber risk quantification are changing vendor oversight, why storytelling is the key to getting business buy-in, and how AI — both as a business tool and an attacker's weapon — is reshaping the third-party risk landscape. GuestJeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite. Previously spent 15 years as a research analyst at Gartner, built a security programme at Martha Stewart Omnimedia, and ran his own consulting practice. Joined Black Kite four years ago. In this episode[01:02] Jeffrey's route into cybersecurity — from managing a New York hardware store to Novell NetWare training, consulting, Martha Stewart Omnimedia, 15 years at Gartner, and now Black Kite.[04:42] How third-party risk management has evolved: from contract/legal sign-off, to security questionnaires, to outside-in vendor scores, to today's risk-based, intelligence-led approach.[07:11] Why not all vendors matter equally — tiering vendors so effort is focused on the ones that actually pose material risk.[09:45] Two UK-rooted supply chain incidents: the KNP Logistics ransomware attack that put the firm out of business, and the Jaguar Land Rover cyberattack that reportedly affected UK GDP.[11:17] Has the market moved beyond questionnaires? Financial services and insurance are further ahead; small niche vendors and giant vendors (e.g. Google) both present unique challenges.[13:47] The case for cyber risk quantification — Black Kite's OpenFAIR-based model and the three risk scenarios it prioritises: data loss, ransomware, and vendor non-delivery.[15:30] Translating cyber risk into business language: business impact analysis, stakeholder relationships, and a real anecdote about an aerospace manufacturer that stockpiled a critical component ahead of a supplier's ransomware attack.[23:04] Jeffrey's simplified framing for engaging executives: money coming in, money going out, and who's accountable if something goes wrong.[24:05] Scepticism around third-party risk scores, the case for methodology transparency ("open the raincoat"), and a credit-score analogy for contextualising vendor risk.[28:00] The shift from "assess everyone, monitor a few" to "monitor everyone, assess dynamically" — including examples from a large retail customer monitoring 100,000 vendors and an insurer streamlining onboarding.[30:00] Why questionnaires won't disappear entirely (audit and compliance still require them), and caution around AI-generated questionnaire responses and compliance reports.[33:08] Discovering AI in the supply chain — shadow AI, the idea of an "AI Bill of Materials," and why AI adoption often bypasses IT-led vendor review (e.g. HR or marketing tools).[40:01] A discussion of emerging agentic AI security research tools referenced in the episode, and concerns about a rising volume of reported vulnerabilities outpacing organisations' ability to triage them.[43:47] Attack chaining — how several medium-severity vulnerabilities can be combined for privilege escalation, changing how vulnerabilities should be prioritised.[46:47] A cautionary anecdote about a casino network reportedly compromised via an internet-connected aquarium thermostat.[47:54] Where CISOs should prioritise investment: governance and clear ownership, business impact analysis, a defined vendor onboarding process, and continuous monitoring — illustrated with the Change Healthcare/UnitedHealthcare ransomware case.[52:17] Regulatory pressure shaping third-party risk: DORA (EU/UK financial services), NIST, ISO, and HIPAA/NHS-equivalent requirements.[53:28] Closing thoughts on AI and human-in-the-loop working, including a quote Jeffrey attributes to Nvidia CEO Jensen Huang about AI and jobs.Notable quotes"All vendors are equal. Some vendors are more equal than others." — Jeffrey Wheatman, paraphrasing Animal Farm"Your business executives care about three things: money coming in, money going out, and if something goes wrong, who's in trouble." — Jeffrey Wheatman"The biggest risk in communication is assuming it has taken place." — quoted by Jeffrey Wheatman, attributed to George Bernard Shaw"Don't ask your vendors if they're using AI. They are. It's a matter of understanding what they're using it for." — Jeffrey Wheatman