Third Party

Third Party

If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact. Third-Party is the podcast built for the people behind the dashboards. The ones managing 5,000 vendors with a team of three. Hosted by Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley, this show unpacks what actually works (and what doesn’t) in TPRM. No fear tactics. No buzzwords. Just unfiltered conversations, sharp insights, and the occasional roast of a really bad SIG questionnaire.

  1. Sep 23

    Is AI the End of Humanity or Just Another Y2K?

    Some of the people building AI are warning it could end humanity. Others say it's all hype. Meanwhile, AI agents have already escaped a testing sandbox and attacked another company's infrastructure. So is AI the end of the world, or just the next Y2K? In this unscripted, off-cycle episode, Jeffrey Wheatman and Bob Maley sit down with Black Kite co-founder and CTO Candan Bolukbas and Rock Lambros, Director of AI Standards and Governance at Zenity and a core team member of the OWASP GenAI Security Project, to cut through the headlines. They debate whether the latest warnings signal real danger or another cycle of panic. They also get into why the bigger threat may be the people using AI rather than the technology itself, and what defenders need to do now that attackers have already adapted. Then they bring it back to the question security leaders are facing: how do you manage AI risk across an ecosystem of partners and suppliers you can't fully control? In this episode, you will learn: Why today's AI doom headlines echo past panics like Three Mile Island and Y2K, and why banning AI could backfire Why the bigger AI risk may be the humans using it rather than the technology itself How AI has cut the time attackers need to turn a new patch into a working exploit from days to hours What the AI sandbox breakout that hit Hugging Face teaches defenders about using AI to fight AI Why free AI tools and API tokens can quietly expose your passwords, secrets, and source code How to treat AI as a third-party and supply chain risk, starting with where your data goes If you're trying to separate AI hype from real risk in your security program, this conversation is for you.

  2. Aug 26

    The AI Scanner Hype Test

    AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game changer, or just the latest round of marketing built on fear, uncertainty, and doubt? In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik pressure-test the hype around tools like Project Glasswing and the new class of AI scanners. They dig into why discovery has raced ahead of remediation, why throwing AI at the end of the process may be solving the wrong problem, and where these tools actually earn their keep today versus where the marketing gets ahead of reality. Along the way they get into prioritization, explainability, and the uncomfortable question of what happens when you can find far more than you could ever fix. In this episode, you will learn: Why the real story is the gap between vulnerabilities discovered and vulnerabilities patchedWhere AI genuinely helps today, from discovery and attack chaining to triageWhy shifting these tools earlier in the development cycle may matter more than faster remediationHow to cut through vendor AI claims using explainability as your filterWhy prioritization, not patching everything, is the only way out of the delugeWhat security leaders should expect from these tools over the next year If you have ever wondered whether the AI vulnerability hype is signal or noise, this conversation gives you a framework to tell the difference.

  3. Jun 17

    The Hidden Signals Predicting Vendor Collapse

    Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether forecasting vendor failure is realistic or just another false promise. If you’ve ever wondered how to identify hidden risks before they explode, this conversation delivers practical insights you can act on immediately. Hosted by Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik, this episode dives into the real signals behind vendor instability, from layoffs and geopolitical conflict to ransomware targeting patterns and operational blind spots. The team breaks down why correlation is often mistaken for causation, how attackers exploit chaos, and why most organizations still miss early warning signs. You’ll walk away with a clearer understanding of what can actually be predicted, what cannot, and how to build a smarter third-party risk strategy that goes beyond surface-level metrics. What you’ll learn: How to identify early warning signals of vendor failure before a breach happens Why layoffs, automation, and global conflict can increase third-party risk exposure The difference between correlation and causation in risk modeling How attackers exploit chaos and weak vendor ecosystems Why vendor self-reporting often fails and what to rely on instead Don’t risk missing the signals that matter. Learn how to spot risk earlier and make smarter third-party decisions before it’s too late.

Ratings & Reviews

5
out of 5
5 Ratings

About

If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact. Third-Party is the podcast built for the people behind the dashboards. The ones managing 5,000 vendors with a team of three. Hosted by Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley, this show unpacks what actually works (and what doesn’t) in TPRM. No fear tactics. No buzzwords. Just unfiltered conversations, sharp insights, and the occasional roast of a really bad SIG questionnaire.

You Might Also Like