Skip to content
Artwork for Third Party Threat Hunters
TechnologyBusinessManagement

Third Party Threat Hunters

Gregory Rasner

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)

Play
  • 10 episodes
  • Avg 15 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

  • S2 · E6
    Yesterday · 28 min

    Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman

    Send us Fan Mail Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable. Key topics Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question: are financial institutions truly reducing vendor risk or mainly satisfying examiners? Michael Berman shares his background as a recovering attorney turned entrepreneur, plus 17 years leading End Contracts and prior experience handling third-party risk as general counsel. Michael says his morning routine is cardio for fitness and stress relief, and he identifies as a technology enthusiast who enjoys learning how new tech works. The conversation opens with Michael's book, The Upside of Third Party Risk Management, which argues that risk management can be an organizational advantage instead of just a fear-driven obligation. Michael says third-party risk is improving, but many programs still overfocus on point-in-time assessments instead of real-world monitoring and response. He uses the Dwell AI startup controversy as an example of why trust but verify matters, especially when funding, AI outputs, and vendor claims collide. Greg and Michael compare vendor reviews to employee reviews, arguing that vendors deserve at least as much ongoing attention as internal staff because they often have deeper access to data and systems. Michael explains the gap between traditional GRC and threat hunting: one asks whether a vendor was secure at onboarding, while the other asks whether something is happening right now that needs action. He emphasizes that organizations need both approaches, plus a shared taxonomy between cybersecurity teams and compliance teams, so risk ratings and threat intelligence align. Michael describes how vendor management must shift from static questionnaires to real-time governance, especially when incidents like MoveIt show the value of knowing which vendors and fourth parties are affected immediately. On fourth party and shadow AI risk, Michael says the governance perimeter has dissolved because vendors now rely on cloud, model providers, subprocessors, APIs, and other hidden dependencies. He recommends expanding governance from just the vendor to the data flows themselves, with continuous discovery, clear escalation paths, and the ability to cut off risky tools quickly. For AI vendors, Michael recommends stronger contractual controls, including notice of material model changes, AI incident notifications, clarity on subprocessors and model providers, and audit or evidence rights. Greg suggests using the term security assessment instead of audit in some cases to reduce friction, and Michael agrees that evidence rights are especially important. Michael cautions that startups can be attractive but risky if they cannot provide maturity, controls, or evidence comparable to more established vendors. Greg adds that vendor requirements should be positioned as business guardrails, not just a flat no, especially when regulators and enterprise risk thresholds are involved. Michael closes by noting that risk leaders should focus first on contractual controls and a usable framework, since those two tools can reduce the need for constant manual intervention. Timestamps 00:00 - Guest introduction and why third-party risk matters 01:14 - The upside of third-party risk management 02:08 - Why Michael would have chosen medicine 02:28 - Technology as Michael's unexpected hobby 02:59 - Favorite place to unplug by the ocean 03:29 - A recent non-business book recommendation 04:11 - Are banks reducing risk or just satisfying examiners? 05:00 - Why vendor failures and fourth parties matter more now 06:14 - Vendor reviews should be as routine as employee reviews 07:22 - Moving from static compliance to active threat hunting 08:14 - Point-in-time assessments versus live monitoring 09:22 - Cyber, financial, and business continuity risks are connected 10:50 - Turning vendor data into action instead of overload 11:43 - Shared taxonomy between security and compliance teams 12:17 - Real-time governance for critical vendors 13:14 - Why MoveIt showed the weakness of one-time vendor questions 14:03 - Why contract terms matter when breaches happen 14:59 - AI is making third-party governance much harder 17:44 - Why AI dissolves the governance perimeter 18:37 - Shadow AI and incomplete vendor inventories 20:02 - Why vendors may not understand their own AI supply chain 21:01 - Expand governance from vendors to data flows 21:57 - Continuous discovery and escalation paths 23:24 - Evidence requirements for AI vendors 24:53 - Material model-change notice and incident notification 25:55 - Security assessment versus audit language 26:52 - Evidence rights and documented validation 27:22 - Why startup AI vendors may be too immature 28:27 - How to push back when the business wants a risky vendor 29:25 - Regulators still show up after a breach 30:16 - Not every AI tool is equally critical 31:12 - Why leaders should not wait for regulation 32:14 - Pick a defensible AI risk framework and stick to it 33:23 - Final advice: contract controls plus a framework Key frameworks Point-in-time vendor assessment versus continuous threat hunting Governance should cover both vendors and data flows Contractual controls should be built at relationship inception AI risk management should be supported by evidence rights, notice obligations, and escalation paths Risk treatment should be proportional to the use case, not just the presence of AI Notable quotes "You might have eight hundred vendors, but that doesn't mean I need to do threat monitoring for eight hundred vendors." "If it wasn't documented, it wasn't done." "Think about what contractual controls you can put in place at the inception of relationships to make your life easier." Action items Review vendor contracts for AI-specific notice, incident, and evidence obligations. Identify which vendors are critical enough to justify continuous monitoring. Build a shared taxonomy between security, compliance, procurement, and legal teams. Treat data flow visibility as part of vendor governance. Pick one defensible AI risk framework and apply it consistently. It works because the title and sectioning make the episode feel practical and high-value, while the timestamps and action items create instant scanability for busy LinkedIn readers. Support the show

    • Transcript
  • S2 · E4
    August 25 · 19 min

    From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib

    Send us Fan Mail In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure. They discuss the growing risk of third-party access, the limits of traditional vendor assessments, and why inventory is the foundation of any serious third-party risk program. Ronan also explains how AI can help security teams separate true risk from alert noise, prioritize what matters, and move from reactive checklists to actionable security decisions. Key Topics Ronan’s background in offensive security, Microsoft Security, and Barclays The origin story behind Shift Security Why vendor questionnaires are no longer enough The importance of knowing all third parties, known and unknown Third-party access as a major breach vector AI agents, shadow AI, and third-party exposure Using AI to reduce alert fatigue and prioritize real risk Building a third-party operational security program, not just a tool stack Main Takeaways Inventory is the first step to securing third parties. Risk management must account for both probability and impact. Vendor access is often more dangerous than vendor compliance gaps. AI can help filter noise, but only when it has strong business context. CISOs need a programmatic approach to third-party operational security. Notable Quote “We’re living in darkness until we understand what third parties exist, what access they have, and what they’re doing.” Why It Matters As third-party ecosystems grow more complex and AI agents become part of the security landscape, organizations can no longer rely on one-time assessments. This episode shows why visibility, continuous monitoring, and context-driven response are now essential for operational resilience. Guest Ronan, Co-founder and CEO of Shift Security Host Greg Mentioned Themes Third-party risk management Vendor access governance AI exposure Security alert fatigue Operational resilience Continuous monitoring Want me to turn this into a LinkedIn post next? Support the show

    • Transcript
  • August 21 · 51 sec

    Short: Map your critical dependencies before it's too late

    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once. Choose a service that directly affects customers, operations, revenue, or regulatory obligations. Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement. Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors. Ask what information and access each dependency has. Examine what could fail, be compromised, or behave unexpectedly. Define the intelligence signals that would tell you the risk is changing. Decide in advance what action to take if a dependency becomes unavailable or untrustworthy. Use the dependency map as a focused starting point rather than a massive transformation program. Support the show

  • August 20 · 56 sec

    Short: Starting Small with a Critical Service Dependency Map with Michael Rasmussen

    Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once. Choose a service that directly affects customers, operations, revenue, or regulatory obligations. Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement. Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors. Ask what information and access each dependency has. Examine what could fail, be compromised, or behave unexpectedly. Define the intelligence signals that would tell you the risk is changing. Decide in advance what action to take if a dependency becomes unavailable or untrustworthy. Use the dependency map as a focused starting point rather than a massive transformation program. Support the show

  • August 18 · 56 sec

    AIs Impact on Enterprise Boundaries with Michael Rasmussen

    Send us Fan Mail The enterprise no longer ends at the org chart The idea The real organization is the network around the organization. Vendors, contractors, platforms, data brokers, APIs, and outsourced processes are not support functions - they are part of the operating system. Why it matters Risk, performance, and control can no longer be understood by looking only inside the company. If you treat the perimeter as external, you miss where value is created and where failure actually happens. In practice A SaaS outage, a broken supplier workflow, or a third-party data issue can now hit the business as directly as an internal failure. The modern leader has to manage the extended web, not just the firm. Support the show

  • August 18 · 46 sec

    Short: The most dangerous assumption in third-party risk with Michael Rasmussen

    Send us Fan Mail Michael Rasmussen explains why the biggest mistake in third-party risk is assuming you already know who your suppliers are and what risk they bring. Rather than focusing only on contract size or spend, he argues for measuring value at risk, because small vendors can create outsized operational or security impact. Key topics Michael Rasmussen says the most dangerous assumption is that an organization already knows its third parties and the risk they bring. He describes how his supplier third-party risk workshop has focused on a key question: how do you measure value at risk? He challenges the common practice of using contract size or spend as the main proxy for risk. He gives a practical example: a small supplier that delivers a critical widget may not cost much, but if it fails, manufacturing stops. He points to the Target breach as a reminder that a non-obvious vendor can become the doorway into a major incident. He notes that an HVAC vendor helped open the path to one of the largest credit card breaches in history. He emphasizes that identifying who your vendors are and what risk they bring is not simple Support the show

  • S2 · E3
    August 18 · 22 min

    The Evolution of GRC and Future Risks in Third-Party Ecosystems with Michael Rasmussen

    Send us Fan Mail In this episode, Michael Rasmussen, a leading expert in governance, risk, and compliance, shares insights into the origins of GRC, its ongoing evolution, and its critical role in managing complex third-party ecosystems amid rapid technological change. Discover how organizations can stay ahead of regulatory pressures and operational risks through innovative frameworks and proactive dependency mapping. Key Topics Covered: How Michael Rasmussen pioneered the GRC concept with the first market models in February 2002 The seven generations of GRC, from Sarbanes Oxley-driven GRC 1.0 to GRC 7.0 focusing on orchestration and AI The importance of treating risk as an appetite for value, not risk itself Why periodic risk assessments are insufficient in dynamic environments and the need for continuous intelligence Bridging the gap between technical threat detection and business risk perspective The risks associated with opaque AI supply chains and shadow tech, and how to govern them proactively Critical dependencies in third-party ecosystems and how to map and manage them effectively Practical steps organizations can take today, such as dependency mapping and defining systemically critical vendors The role of organizational culture and personal routines in staying informed and resilient Timestamps: 00:00 - Introduction to Michael Rasmussen and his GRC background 02:45 - The origin story: How the GRC acronym was created in 2002 05:00 - The seven generations of GRC: From reactive to orchestrated AI-driven frameworks 09:00 - Common industry misconceptions and what should be retired in risk management 11:12 - How personal experiences and career pivots shaped Rasmussen’s expertise 15:13 - The future of vendor risk ecosystems and the dangers of shadow tech 17:24 - Governing non-transparent AI supply chains ahead of regulation 19:49 - Bridging the gap: Connecting technical threat intelligence with operational risk 22:13 - The importance of contextual analysis over simple scoring in third-party risk 24:32 - Risk management lessons from Star Trek and risk appetite misconceptions 27:27 - Practical advice: Building dependency maps for critical business services 29:09 - Final thoughts on identifying systemically critical vendors and ensuring resilience Want me to turn this into a LinkedIn post next? Support the show

    • Transcript
  • S2 · E5
    August 13 · 24 min

    AI, Third Party Risk, and the Real Work of Operationalizing It with Paul Kurtz

    Send us Fan Mail Greg reviews how AI is changing third party risk management with Paul Kurtz, a 30 plus year financial services veteran and current third party risk leader at First Century Bank. They focus on what actually changes in banking when AI enters vendor risk workflows, from ongoing monitoring to questionnaire design and regulator conversations. This episode matters because it cuts through the hype. Paul explains how AI can improve visibility and efficiency without replacing judgment, and why the real task is learning how to use it safely, document it properly, and keep the right humans in the loop. Key topics Paul Kurtz’s background and perspective Paul shares that he has spent more than 30 years in financial services, starting in retail loss prevention, then moving into banking and fraud investigation, and eventually focusing on third party risk management for the last 14 to 15 years. He frames himself as an AI generalist rather than a cybersecurity or technology specialist, which shapes how he approaches vendor risk. Why AI clicked for third party risk Paul says he was drawn to AI training because it was framed through the lens of third party risk management, not as generic AI hype. That context helped him see how AI fits into the specific decisions and controls TPRM teams need. The biggest challenge in traditional banking Paul points to change management as the first major hurdle when introducing AI tools in a conservative financial environment. Cost is the second major issue, since teams need enough understanding to do due diligence, choose the right tool, and understand how third parties are using AI too. What banks should automate first Paul says ongoing monitoring is the biggest manual process that should be automated sooner rather than later. He argues that too many organizations still treat assessments like a one-time exercise instead of a living risk process. Why AI is useful in ongoing monitoring Paul describes AI-enabled monitoring as a way to watch for cyber threats, financial changes, and other risk signals without relying on manual fishing. The goal is not to automate judgment away, but to surface the right issues earlier. AI is not a magic bullet Paul emphasizes that AI is still maturing and that many vendors are rushing into the market. He rejects the idea that AI will simply replace people, comparing current fears to earlier waves around computers, the internet, cloud, and robotics. What changed after AI training Paul says the biggest practical shift was learning to ask not just whether a vendor uses AI, but how they use it, where they use it, and what data it touches. He uses those questions to deepen his Infosec questionnaire and focus scrutiny where it actually matters. Risk-based focus beats blanket fear Paul draws a clear line between low-risk uses, like a vendor using Copilot for internal meeting notes, and higher-risk uses, like AI making decisions or interacting with customers. The key is understanding scope, safeguards, and whether the use case could affect business outcomes or regulated data. AI affects more than cybersecurity Paul and Greg discuss how AI touches legal, compliance, privacy, and information security, not just IT. That makes cross-functional conversation essential. How to balance speed and safety in banking Paul says the best path is staying connected to how regulators are thinking and keeping communication open. He notes that regulators are increasingly asking questions and engaging on AI, rather than simply blocking it. How to work with regulators Paul argues that if you can show you considered the risk, documented your decisions, and followed your process, regulators usually respond well. Greg reinforces that the issue is often not the tool itself, but failing to follow the process. Where the industry is headed Paul notes that a cottage industry is forming around AI assessments, frameworks, and advisory work. Greg adds that even AI agent evaluation has become a real consulting opportunity. Best first step for banks starting out Paul recommends learning the basics through training and then applying that knowledge to vendor populations. He warns that the danger is either moving too fast without understanding AI or too slowly and missing the competitive advantage. Community and peer learning matter Paul and Greg both stress that third party risk professionals benefit from sharing best practices instead of treating knowledge as proprietary. They encourage joining industry groups, attending events, taking certifications, and reaching out to peers directly. Notable quotes "I am not a cybersecurity specialist. I am not a technology specialist. I consider myself an AI generalist." "This is not a magic bullet." "The regulators are going to tell you what to do, but not how to do it." Episode Title Title 1: Why AI Won’t Replace TPRM Teams—But Will Change Them Fast Why it works: This title hits the core tension in the episode: fear of replacement versus the reality of augmentation. It speaks directly to third-party risk professionals worried about AI, while promising a practical, balanced perspective rather than hype. Title 2: The AI Blind Spot Banks Keep Missing in Vendor Risk Reviews Why it works: This creates urgency by framing AI as something banks are overlooking, which triggers concern and curiosity. It also targets the exact audience most likely to care: banking and vendor-risk leaders who suspect their current reviews aren’t enough. Title 3: How One TPRM Leader Turned AI Training Into Better Vendor Questions Why it works: This title offers a clear transformation story: training leads to smarter due diligence. It’s specific, credible, and appealing to practitioners who want an actionable payoff, not abstract theory. Title 4: Set It and Forget It Is Dead: Why Ongoing Monitoring Must Be Automated Why it works: This uses a punchy, familiar phrase to create instant recognition and tension. It taps into a real pain point in TPRM—stale assessments—and promises a timely operational insight for busy risk teams. Title 5: The Real Risk Isn’t AI Itself—It’s Using It Without a Framework Why it works: This reframes the conversation in a way that feels smart and contrarian. It appeals to risk and compliance professionals by emphasizing governance, process, and control rather than panic, which makes it highly shareable across business and regulatory audiences. Recommended: Title 5 — It’s the strongest mix of contrarian insight, clarity, and broad relevance, and it cleanly captures the episode’s main message about governance over fear. Want me to turn this into a LinkedIn post next? Support the show

    • Transcript
  • S2 · E2
    August 11 · 26 min

    Navigating Third-Party Risk and AI in Cybersecurity with Rachel Curran

    Send us Fan Mail In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape. Key Topics Rachel’s background in GRC and her passion for security and compliance The role of AI in accelerating vendor assessments and risk management The importance of human-in-the-loop for effective governance at speed Bridging the governance gap by focusing on actual enforcement over paperwork How AI influences remote vendor onboarding and real-time data exchange Critical security risks introduced by AI agents, especially access control The shift from static to dynamic, self-optimizing AI-driven vendor risk profiles The evolving threat landscape and the dangers of AI-enabled malicious actors Practical strategies for organizations: going back to fundamentals and prioritization The significance of frameworks and continuous updating of security programs How to leverage evidence packs and automation for ongoing compliance verification Timestamps 00:00 - Introduction to Rachel Curran and her expertise in GRC 01:17 - Rachel’s career journey and motivation in cybersecurity 02:37 - Personal interests: favorite travel destinations and favorite fruit 03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive 06:27 - The challenge of governance at speed in the AI era 07:00 - Human oversight’s critical role in AI-driven risk management 08:47 - Managing governance gaps through prioritization and verifiable data 10:11 - The biggest governance gaps organizations face today 11:37 - Using automation to improve vendor visibility and risk assessments 12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it 14:02 - The fallacy of paper policies versus actual practice in governance 15:40 - Data dependence and the importance of real-time controls and backups 16:07 - The impact of AI on third party risk landscape over the next 12-18 months 16:42 - Risks from AI-enabled access control and recent AI breach incidents 18:12 - Managing AI agents’ permissions and preventing privilege creep 20:30 - The threat of AI agents executing malicious or unintended actions 22:08 - The necessity of quality data, transparency, and human oversight 24:06 - Moving away from point-in-time assessments toward continuous, evidence-backed evaluations 25:00 - The potential to improve vendor transparency with real-time info sharing 26:12 - How AI can support dynamic security assessments and ongoing compliance 27:21 - The importance of foundational security controls and a risk-focused mindset 28:13 - Tactical action: back to basics—understand your vendors and their risk posture 29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring Final Takeaways Focus on fundamental security controls and verifiable data to reduce risks Prioritize vendors based on actual risk to manage resources effectively Use automation and frameworks for continuous compliance and rapid response Recognize AI as a tool to augment, not replace, human judgment and oversight Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management. Want me to turn this into a LinkedIn post next? Support the show

    • Transcript
  • S2 · E1
    July 29 · 27 min

    Beyond Questionnaires: AI Agents, Zero-Day Breaches, and TPRM with Clarence Chio

    Send us Fan Mail In this episode, Clarence Chio, CEO of Coverbase, discusses the evolving landscape of AI in cybersecurity, third-party risk management, and the implications of autonomous AI agents. We explore real-world incidents, innovative solutions, and strategic insights for security professionals navigating the AI-driven future. key topics AI's role in cybersecurity and risk management Implications of autonomous AI agents in security breaches Innovative solutions for continuous third-party monitoring The evolution of security culture in tech companies Strategic insights for security professionals in an AI era Support the show

    • Transcript
Showing 1–10 of 10 episodes