Third Party Threat Hunters
Gregory Rasner
0
Third Party Threat Hunters is a podcast hosted by Gregory Rasner, a leader in cybersecurity and third-party risk management. Each episode features conversations with experts in the field, covering topics related to third-party risk and security threats. Rasner is the author of several books on TPRM and privileged access management (PAM).
Jaksot
-
Short: Tech Gians and OFAC with Michael Volkov 16.09.2026Send us Fan Mail In this short video, Mike explains how this is an unappreciated risk Support the show -
Short: How to Identify Material Third Parties with Julie Giaischi 15.09.2026Send us Fan Mail In this short video, we hear Julie explain how to identify the vendors risks that really matter - with your "material" third-parties. Support the show -
Sanctions Ready Third-Party Risk with Michael Volkov 15.09.2026 27minSend us Fan Mail Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens wh... -
Treat Vendors As Part Of The Enterprise with Julie Giaischi 10.09.2026 26minSend us Fan Mail Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction. We dig into a core myth that still drives bad decisions: scaling third-party risk management based o... -
Short: Communicate Risk in Business Terms for Success with Becky Newton 09.09.2026 1minSend us Fan Mail In this short video, Becky explains how to do this best. Support the show -
Short: How TPRA is Accelerating Threat Intelligence Sharing with Heather Kadavy 09.09.2026Send us Fan Mail In this short video, Heather provides examples of how this is being accomplished. Support the show -
Vendor Risk Beyond The SOC Report with Becky Newton 08.09.2026 24minSend us Fan Mail A vendor hands you a clean SOC 2 Type II report, the boxes look checked, and everyone relaxes. Then the breach happens anyway. That’s the control assurance paradox, and it’s why we sat down with Becky Newton, founder and managing partner of Newton Risk Intelligence, to get brutally practical about what third-party risk management should look like when the goal is real operational security, not paperwork comfort. We unpack why TPRM is neither “just audit” nor “just security,”... -
Relationships Beat Tools In Vendor Risk with Heather Kadavy 03.09.2026 23minSend us Fan Mail Vendor risk doesn’t fail because you picked the wrong platform. It fails because nobody trusts the program, nobody speaks the business unit’s language, and everyone thinks it’s someone else’s job. We’re joined by Heather Kadavy, Director of Membership Success at the Third Party Risk Association (TPRA), to get honest about what actually moves third-party risk management forward when teams are lean, vendors are complex, and AI is changing the rules. We dig into the biggest myt... -
Short: AIs Impact on Third-Party Risk Governance with Michael Berman 02.09.2026Send us Fan Mail In this short video, Michael explains AI's impact on how we process and develop and run our TPRM programs. Support the show -
Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman 01.09.2026 28minSend us Fan Mail Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable. Key topics Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question... -
From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib 25.08.2026 19minSend us Fan Mail In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure. They discuss the growing risk of third-party access, the limit... -
Short: Map your critical dependencies before it's too late 21.08.2026Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The... -
Short: Starting Small with a Critical Service Dependency Map with Michael Rasmussen 20.08.2026Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The... -
AIs Impact on Enterprise Boundaries with Michael Rasmussen 18.08.2026Send us Fan Mail The enterprise no longer ends at the org chart The idea The real organization is the network around the organization. Vendors, contractors, platforms, data brokers, APIs, and outsourced processes are not support functions - they are part of the operating system. Why it matters Risk, performance, and control can no longer be understood by looking only inside the company. If you treat the perimeter as external, you miss where value is created and where failure actually happens.... -
Short: The most dangerous assumption in third-party risk with Michael Rasmussen 18.08.2026Send us Fan Mail Michael Rasmussen explains why the biggest mistake in third-party risk is assuming you already know who your suppliers are and what risk they bring. Rather than focusing only on contract size or spend, he argues for measuring value at risk, because small vendors can create outsized operational or security impact. Key topics Michael Rasmussen says the most dangerous assumption is that an organization already knows its third parties and the risk they bring. He describes how his... -
The Evolution of GRC and Future Risks in Third-Party Ecosystems with Michael Rasmussen 18.08.2026 22minSend us Fan Mail In this episode, Michael Rasmussen, a leading expert in governance, risk, and compliance, shares insights into the origins of GRC, its ongoing evolution, and its critical role in managing complex third-party ecosystems amid rapid technological change. Discover how organizations can stay ahead of regulatory pressures and operational risks through innovative frameworks and proactive dependency mapping. Key Topics Covered: How Michael Rasmussen pioneered the GRC concept with the... -
AI, Third Party Risk, and the Real Work of Operationalizing It with Paul Kurtz 13.08.2026 24minSend us Fan Mail Greg reviews how AI is changing third party risk management with Paul Kurtz, a 30 plus year financial services veteran and current third party risk leader at First Century Bank. They focus on what actually changes in banking when AI enters vendor risk workflows, from ongoing monitoring to questionnaire design and regulator conversations. This episode matters because it cuts through the hype. Paul explains how AI can improve visibility and efficiency without replacing judgme... -
Navigating Third-Party Risk and AI in Cybersecurity with Rachel Curran 11.08.2026 26minSend us Fan Mail In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape. Key Topics Rachel’s background in GRC and her passion for security and complianceThe role of AI in accelerating vendor assessm... -
Beyond Questionnaires: AI Agents, Zero-Day Breaches, and TPRM with Clarence Chio 29.07.2026 27minSend us Fan Mail In this episode, Clarence Chio, CEO of Coverbase, discusses the evolving landscape of AI in cybersecurity, third-party risk management, and the implications of autonomous AI agents. We explore real-world incidents, innovative solutions, and strategic insights for security professionals navigating the AI-driven future. key topics AI's role in cybersecurity and risk managementImplications of autonomous AI agents in security breachesInnovative solutions for continuous third-part...
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.