Third Party Threat Hunters

Third Party Threat Hunters

Gregory Rasner
Shteti Shtetet e Bashkuara
Gjuha EN-US
Episode 3
I/E fundit 30.09.2026

Third Party Threat Hunters is a podcast hosted by Gregory Rasner, a leader in cybersecurity and third-party risk management. Each episode features conversations with experts in the field, covering topics related to third-party risk and security threats. Rasner is the author of several books on TPRM and privileged access management (PAM).

Episodet

  • AI That Actually Helps TPRM with Brian Shaw 30.09.2026 25min
    Send us Fan Mail “100% automated vendor risk assessments” sounds seductive right up until you are staring at unstructured SOC 2 reports, mismatched ISO certificates, and a queue you cannot clear. Greg sits down with Brian Shaw, a long-time third-party risk and compliance leader, to talk about what AI can realistically do in third-party risk management today, and what it absolutely should not do yet. We start with a blunt warning: do not automate a broken process. If a question does not chang...
  • Continuous Third-Party Risk Monitoring with Girish Redekar 29.09.2026 36min
    Send us Fan Mail Support the show
  • Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS 24.09.2026 23min
    Send us Fan Mail Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor. We dig into q...
  • Short: Surprise! There's AI in your Enterprise with Bill Haber 23.09.2026
    Send us Fan Mail Many organizations don't realize how far AI is into their systems Support the show
  • The Vendor Trust Gap with Bill Haber 22.09.2026 26min
    Send us Fan Mail Your vendors are not “outside” your business anymore. When an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access. We talk with Bill Haber, co-founder and CEO of Tekrisq, about how to build third-party risk management that earns real trust instead of producing paper compliance that looks good until it fails. We get blunt about security questionnaires: why flat, self-attested checklists cr...
  • Short: Tech Gians and OFAC with Michael Volkov 16.09.2026
    Send us Fan Mail In this short video, Mike explains how this is an unappreciated risk Support the show
  • Short: How to Identify Material Third Parties with Julie Giaischi 15.09.2026
    Send us Fan Mail In this short video, we hear Julie explain how to identify the vendors risks that really matter - with your "material" third-parties. Support the show
  • Sanctions Ready Third-Party Risk with Michael Volkov 15.09.2026 27min
    Send us Fan Mail Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens wh...
  • Treat Vendors As Part Of The Enterprise with Julie Giaischi 10.09.2026 26min
    Send us Fan Mail Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction. We dig into a core myth that still drives bad decisions: scaling third-party risk management based o...
  • Short: Communicate Risk in Business Terms for Success with Becky Newton 09.09.2026 1min
    Send us Fan Mail In this short video, Becky explains how to do this best. Support the show
  • Short: How TPRA is Accelerating Threat Intelligence Sharing with Heather Kadavy 09.09.2026
    Send us Fan Mail In this short video, Heather provides examples of how this is being accomplished. Support the show
  • Vendor Risk Beyond The SOC Report with Becky Newton 08.09.2026 24min
    Send us Fan Mail A vendor hands you a clean SOC 2 Type II report, the boxes look checked, and everyone relaxes. Then the breach happens anyway. That’s the control assurance paradox, and it’s why we sat down with Becky Newton, founder and managing partner of Newton Risk Intelligence, to get brutally practical about what third-party risk management should look like when the goal is real operational security, not paperwork comfort. We unpack why TPRM is neither “just audit” nor “just security,”...
  • Relationships Beat Tools In Vendor Risk with Heather Kadavy 03.09.2026 23min
    Send us Fan Mail Vendor risk doesn’t fail because you picked the wrong platform. It fails because nobody trusts the program, nobody speaks the business unit’s language, and everyone thinks it’s someone else’s job. We’re joined by Heather Kadavy, Director of Membership Success at the Third Party Risk Association (TPRA), to get honest about what actually moves third-party risk management forward when teams are lean, vendors are complex, and AI is changing the rules. We dig into the biggest myt...
  • Short: AIs Impact on Third-Party Risk Governance with Michael Berman 02.09.2026
    Send us Fan Mail In this short video, Michael explains AI's impact on how we process and develop and run our TPRM programs. Support the show
  • Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman 01.09.2026 28min
    Send us Fan Mail Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable. Key topics Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question...
  • From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib 25.08.2026 19min
    Send us Fan Mail In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure. They discuss the growing risk of third-party access, the limit...
  • Short: Map your critical dependencies before it's too late 21.08.2026
    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The...
  • Short: Starting Small with a Critical Service Dependency Map with Michael Rasmussen 20.08.2026
    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The...
  • AIs Impact on Enterprise Boundaries with Michael Rasmussen 18.08.2026
    Send us Fan Mail The enterprise no longer ends at the org chart The idea The real organization is the network around the organization. Vendors, contractors, platforms, data brokers, APIs, and outsourced processes are not support functions - they are part of the operating system. Why it matters Risk, performance, and control can no longer be understood by looking only inside the company. If you treat the perimeter as external, you miss where value is created and where failure actually happens....
  • Short: The most dangerous assumption in third-party risk with Michael Rasmussen 18.08.2026
    Send us Fan Mail Michael Rasmussen explains why the biggest mistake in third-party risk is assuming you already know who your suppliers are and what risk they bring. Rather than focusing only on contract size or spend, he argues for measuring value at risk, because small vendors can create outsized operational or security impact. Key topics Michael Rasmussen says the most dangerous assumption is that an organization already knows its third parties and the risk they bring. He describes how his...

I/E popullarizuar në

Ky podkast shfaqet edhe në listat e podkasteve të këtyre shteteve.