Skip to content
Artwork for Third Party

Third Party

Third Party

If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact.

Third-Party is the podcast built for the people behind the dashboards. The ones managing 5,000 vendors with a team of three.

Hosted by Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley, this show unpacks what actually works (and what doesn’t) in TPRM. No fear tactics. No buzzwords. Just unfiltered conversations, sharp insights, and the occasional roast of a really bad SIG questionnaire.

Play
  • 20 episodes
  • fortnightly
  • Avg 39 min
  • English
  • September 23 · 37 min

    Is AI the End of Humanity or Just Another Y2K?

    Some of the people building AI are warning it could end humanity. Others say it's all hype. Meanwhile, AI agents have already escaped a testing sandbox and attacked another company's infrastructure. So is AI the end of the world, or just the next Y2K? In this unscripted, off-cycle episode, Jeffrey Wheatman and Bob Maley sit down with Black Kite co-founder and CTO Candan Bolukbas and Rock Lambros, Director of AI Standards and Governance at Zenity and a core team member of the OWASP GenAI Security Project, to cut through the headlines. They debate whether the latest warnings signal real danger or another cycle of panic. They also get into why the bigger threat may be the people using AI rather than the technology itself, and what defenders need to do now that attackers have already adapted. Then they bring it back to the question security leaders are facing: how do you manage AI risk across an ecosystem of partners and suppliers you can't fully control? In this episode, you will learn: Why today's AI doom headlines echo past panics like Three Mile Island and Y2K, and why banning AI could backfire Why the bigger AI risk may be the humans using it rather than the technology itself How AI has cut the time attackers need to turn a new patch into a working exploit from days to hours What the AI sandbox breakout that hit Hugging Face teaches defenders about using AI to fight AI Why free AI tools and API tokens can quietly expose your passwords, secrets, and source code How to treat AI as a third-party and supply chain risk, starting with where your data goes If you're trying to separate AI hype from real risk in your security program, this conversation is for you.

  • September 9 · 35 min

    Are Your Vendors Lying to You?

    Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells you and what is actually happening inside their environment? In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable space between attestation and reality. Jeffrey wants to call it lying. Bob and Ferhat push back hard, arguing most of it is bad data, missing inventory, and answers that are aspirational rather than dishonest. From there they get into the harder problem: how do you verify anything when you cannot send an auditor into Google or Amazon, and what happens to verification itself when the answers you receive were generated by AI in the first place? In this episode, you will learn: Why yes or no questionnaire answers measure compliance, not the efficiency of a control The three types of verification, from signals to behavior analysis to vendor testimony Why every signal needs a confidence level before you decide which battles to fight How to get real value from SOC 2 reports and where third-party audits fall short Why most programs are built to discover and ask questions, but never to follow up What happens to trust but verify when AI is producing the answers on both sides If your program collects a lot of vendor answers and verifies almost none of them, this conversation is worth your time.

  • August 26 · 37 min

    The AI Scanner Hype Test

    AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game changer, or just the latest round of marketing built on fear, uncertainty, and doubt? In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik pressure-test the hype around tools like Project Glasswing and the new class of AI scanners. They dig into why discovery has raced ahead of remediation, why throwing AI at the end of the process may be solving the wrong problem, and where these tools actually earn their keep today versus where the marketing gets ahead of reality. Along the way they get into prioritization, explainability, and the uncomfortable question of what happens when you can find far more than you could ever fix. In this episode, you will learn: Why the real story is the gap between vulnerabilities discovered and vulnerabilities patched Where AI genuinely helps today, from discovery and attack chaining to triage Why shifting these tools earlier in the development cycle may matter more than faster remediation How to cut through vendor AI claims using explainability as your filter Why prioritization, not patching everything, is the only way out of the deluge What security leaders should expect from these tools over the next year If you have ever wondered whether the AI vulnerability hype is signal or noise, this conversation gives you a framework to tell the difference.

  • August 12 · 37 min

    Your TPRM Program Isn't Fixable

    Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the whole thing down and start over.In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik get honest about what it takes to rebuild a TPRM program from the ground up. They dig into why the hardest part isn't the tooling, it's breaking the mental model you've been committed to for years. Drawing on the idea of creation and destruction, they walk through what they would keep, what they would throw out, and why using AI to speed up a broken process just gets you to the wrong answer faster. In this episode, you will learn: Why incremental improvement is the trap, and when a program needs a full rebuild instead of a refresh What the questionnaire industry is really protecting, and what could actually disrupt it The three things Bob and Ferhat would build first if they started from scratch Whether you can outsource a TPRM program, and where that logic breaks down Why AI model cards may replace stacks of AI questionnaires How to shift from assess-everybody to monitor-everybody and assess by exception If you have ever inherited a program you did not build and wondered whether to fix it or start over, this conversation is for you.

  • July 29 · 41 min

    You Can't Say No to Your Vendors

    You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if leverage is mostly an illusion, what actually moves a vendor to fix their exposure? In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dismantle the idea that third-party risk is about power and rebuild it around something more useful: collaboration. They dig into why the questionnaire-led, finger-wagging approach fails, how to communicate risk in dollars and cents that the business will actually act on, and why the relationship you build before an incident matters far more than any contract clause after one. In this episode, you will learn: Why "saying no" was never the CISO's job, and what the real role is How to turn a contract into a collaboration tool instead of a weapon Why intelligence-led outreach beats questionnaire fatigue every time How to communicate vendor risk so business stakeholders actually respond What to do when a hard-to-replace vendor won't budge Why the first interactions with a vendor set the tone for the entire relationship If you have ever felt ignored by a vendor who has bigger customers than you, this conversation will change how you show up to the table.

  • July 15 · 33 min

    Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

    Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why this industry has become one of the most targeted sectors for cyber attacks. If your business depends on uptime, supply chains, or physical operations, this conversation will show you where the real risks are hiding. Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore why manufacturing environments are especially vulnerable, from legacy systems and operational technology (OT) to the real-world consequences of downtime. They unpack new research showing how far behind many organizations are, why cyber attacks in manufacturing are shifting from data theft to operational disruption, and what leaders need to understand to protect production lines and critical infrastructure. Understand why manufacturing is a top target for cyber attacks Learn how downtime risk outweighs traditional data breach concerns Discover the gap between IT security and operational technology (OT) Explore why many organizations still struggle with basic cyber hygiene Get insights into how cyber threats are evolving across global supply chains Don’t risk production downtime or supply chain disruption. Learn how to identify and prioritize the cyber risks that matter most.

  • July 1 · 32 min

    The #1 Mistake Boards Make on Cyber Risk

    Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well-prepared security leaders fail to get buy-in where it matters most. If you’ve ever struggled to explain risk in a way executives actually understand, this conversation will show you how to fix it. Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what boards actually care about, why traditional reporting (like risk heat maps and technical metrics) often falls flat, and how to reframe third-party cyber risk in a way that drives action. Drawing from real-world experience and industry research, they explore the gap between cybersecurity teams and board-level decision-makers—and how to close it with clearer storytelling, smarter prioritization, and business-aligned messaging. Learn how to translate complex cyber risk into language boards care about Discover why common tools like heat maps often fail executives Understand the 3 things boards prioritize—and how to align your messaging Get practical strategies for answering “bad” board questions effectively See how better communication can directly improve organizational resilience Don’t risk your message getting lost in complexity. Learn how to communicate cyber risk in a way that drives real decisions.

  • June 17 · 37 min

    The Hidden Signals Predicting Vendor Collapse

    Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether forecasting vendor failure is realistic or just another false promise. If you’ve ever wondered how to identify hidden risks before they explode, this conversation delivers practical insights you can act on immediately. Hosted by Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik, this episode dives into the real signals behind vendor instability, from layoffs and geopolitical conflict to ransomware targeting patterns and operational blind spots. The team breaks down why correlation is often mistaken for causation, how attackers exploit chaos, and why most organizations still miss early warning signs. You’ll walk away with a clearer understanding of what can actually be predicted, what cannot, and how to build a smarter third-party risk strategy that goes beyond surface-level metrics. What you’ll learn: How to identify early warning signals of vendor failure before a breach happens Why layoffs, automation, and global conflict can increase third-party risk exposure The difference between correlation and causation in risk modeling How attackers exploit chaos and weak vendor ecosystems Why vendor self-reporting often fails and what to rely on instead Don’t risk missing the signals that matter. Learn how to spot risk earlier and make smarter third-party decisions before it’s too late.

  • June 4 · 45 min

    Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

    A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob Maley, Ferhat Dikbiyik, and Black Kite co-founder and CTO Candan Bolukbas to break down what Mythos and Project Glasswing actually change, and what they don't. The numbers are already alarming. Forty-eight thousand CVEs published in 2025. A 43-day mean time to patch. An exploitation window that has gone negative, meaning threat actors are exploiting vulnerabilities an average of seven days before defenders even know they exist. Mythos accelerates vulnerability discovery, but as the team makes clear, discovering more vulnerabilities faster only matters if you have a program built to handle it. In this episode, you will learn: What Mythos and Project Glasswing actually are and why the hype may be outpacing the reality Why the vulnerability deluge is already unmanageable with traditional CVSS-based prioritization How the 135-day embargo window affects your third-party exposure Why fourth-party risk, meaning what your vendors run rather than just who they are, is becoming the real blind spot What SBOMs have to do with the future of supply chain vulnerability management The three things security leaders should do right now to prepare their programs This is not a theoretical conversation. It's the one your program needs before the window closes.

  • May 20 · 31 min

    Are You Measuring the Right Risks…Or Just the Easiest Ones?

    Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and why those metrics often fail to reflect real business risk. If you’ve ever wondered whether your TPRM strategy is actually driving better decisions or just producing reports, this conversation will challenge how you think about risk measurement. Hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the gap between what organizations track and what actually matters—from misleading metrics and “top vendor” lists to the struggle of communicating risk to executives who don’t see the value. You’ll learn how to rethink your approach to third party cyber risk management, move beyond surface-level reporting, and focus on the signals that truly impact your business. In this episode, you’ll learn: Why most third party risk metrics are based on convenience, not impact The difference between measuring activity vs. measuring real risk How to make risk meaningful to boards and executive stakeholders What “good” risk metrics actually look like in practice How to avoid false confidence from incomplete or misleading data Don’t risk building your strategy on the wrong signals. Learn how to measure what actually matters—and make better decisions because of it.

  • May 6 · 34 min

    Why Automation Is Creating More Cyber Risk

    Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and what that means for your TPCRM program. If you’re relying on automation to scale vendor risk assessments, this conversation will help you avoid costly blind spots and make smarter decisions. Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the real tradeoffs between speed and accuracy in TPCRM, exploring how automation can both strengthen and weaken your risk posture. They discuss the dangers of over-relying on data, where AI-driven decisions fall short, and why human judgment still plays a critical role in identifying real risk. This episode is essential for anyone responsible for vendor risk, cybersecurity, or compliance who wants to scale effectively without sacrificing confidence in their decisions. In this episode, you’ll learn: How automation in TPCRM can unintentionally increase risk The hidden tradeoffs between speed and accuracy in vendor assessments Why more data doesn’t always lead to better decisions Where AI and algorithms fall short in real-world risk scenarios How to balance automation with human judgment for better outcomes Practical ways to improve visibility and decision-making in your TPCRM program Don’t risk scaling bad decisions faster. Learn how to balance automation and accuracy to protect your business.

  • April 22 · 40 min

    How to Calculate the Real Cost of a Third-Party Breach

    Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about risk and start putting real numbers behind the potential cost of a third-party breach. If you want security leaders, executives, and boards to take third-party cyber risk seriously, you need to understand how to quantify its financial impact. Many security teams still rely on qualitative risk language like “high,” “medium,” or “critical,” but those labels rarely drive action. Jeffrey, Bob, and Ferhat break down why calculating the financial impact of a third-party breach is essential for communicating with executives, prioritizing vendors, and securing the right investments in risk management. From understanding uncertainty to building models that are accurate enough to guide decisions, this conversation offers practical insight into how leading teams estimate breach costs and translate cyber risk into business language. In this episode, you’ll learn: Why calculating the financial impact of a third-party breach is critical for executive decision making How security leaders translate cyber risk into dollars, euros, or pounds Why “something bad could happen” is not enough to justify cybersecurity investment The difference between precision and usefulness when modeling cyber risk How risk quantification helps prioritize vendors and third-party exposures Why boards and executives respond better to financial risk than technical risk language Don’t risk letting third-party cyber risk remain invisible to leadership. Learn how to calculate the real financial impact of a third-party breach and turn risk conversations into decisions that protect your organization. 0:00 Introduction & Teaser 0:50 Welcome & Episode Overview 2:01 Guest Introduction: Jack Jones & the Origin of FAIR 7:17 Challenges to Implementing Risk Quantification 10:57 Wrap-Up with Jack Jones 11:23 Calculating Financial Impact of a Third-Party Breach 25:54 Precision vs. Accuracy in Risk Models 30:01 Research Roundup: Cybersecurity Outlook 2026 36:44 Agree or Disagree 39:41 Outro & Next Episode Preview

  • April 8 · 38 min

    Vendor Sprawl Is Out of Control (Here’s How the Best Teams Fix It)

    Vendor sprawl is out of control, and most organizations have far more third-party vendors than they realize. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the growing problem of vendor sprawl and why it has quietly become one of the biggest sources of cyber risk. If your organization relies on dozens or hundreds of third parties, this conversation will help you understand how vendor sprawl creates hidden exposure and what the best teams are doing to manage it. As companies adopt more SaaS tools, cloud services, AI platforms, and specialized vendors, visibility and control become harder to maintain. Jeffrey, Bob, and Ferhat break down how vendor sprawl happens, why simply adding more tools does not solve the problem, and how leading security and risk teams are changing their approach to third-party risk management. From rogue applications to overlapping tools and hidden dependencies, this episode explores practical strategies for regaining visibility and prioritizing the vendors that actually matter. In this episode, you’ll learn: Why vendor sprawl is accelerating across modern organizations How hidden third parties introduce unexpected cyber risk The difference between vendor visibility and real vendor risk management Why adding more tools can sometimes make the problem worse Practical ways security teams are prioritizing the vendors that matter most How AI and automation are changing third-party risk management Don’t risk letting vendor sprawl quietly expand your attack surface. Learn how leading teams are taking back control before hidden vendor risk becomes the next breach.

  • March 25 · 37 min

    What You Should NEVER Automate in Risk Programs

    TPCRM automation is rapidly becoming a priority for risk teams, but automating the wrong things can quietly increase exposure instead of reducing it. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the reality of TPCRM automation and what you can safely automate versus what should never be automated inside a third-party cyber risk program. If you are responsible for managing vendors, cyber risk, or compliance, this conversation will challenge the assumption that more automation always leads to better outcomes. Automation promises speed and efficiency, but when organizations automate processes they do not fully understand, they often end up accelerating broken workflows and hiding critical risk signals. The hosts break down where automation truly helps risk teams scale and where human judgment, visibility, and traceability must remain at the center of decision-making. In this episode, you will learn: What TPCRM automation actually means and why many programs misunderstand it The biggest mistake organizations make when automating risk workflows Why automating a broken process makes risk programs worse Where automation can genuinely improve efficiency in TPCRM programs The decisions that should never be fully automated Why visibility and traceability matter when AI and automation are involved Don’t risk automating the wrong parts of your cyber risk program. Learn how to apply TPCRM automation the right way before it creates new blind spots.

  • March 11 · 56 min

    Is Cybersecurity Regulation Actually Dangerous?

    Is cybersecurity regulation actually dangerous? In this episode, we examine whether cybersecurity regulation is improving real security or quietly making organizations less safe. If you have ever wondered whether compliance helps or hurts your defenses, this conversation breaks down what cybersecurity regulation gets right, where it fails, and how leaders should think about risk beyond checklists. In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik debate the regulation paradox facing modern security teams. They explore when compliance drives better risk management, when it becomes a dangerous distraction, and why outdated or overly prescriptive rules can pull focus away from real threats. The discussion covers audits, fines, regulatory fragmentation, and the growing gap between fast moving technology and slow moving regulation. What this episode covers: Whether cybersecurity regulation actually improves security outcomes How compliance can become a checkbox that misses real risk When regulation helps CISOs secure budget and attention Why outdated and overly prescriptive rules can increase exposure The difference between managing audits and managing real risk Don’t risk confusing compliance with protection. Learn how to think critically about cybersecurity regulation and focus on what actually makes organizations safer before regulation becomes a liability instead of a safeguard.

  • February 25 · 42 min

    The Real Meaning of “C” in TPCRM

    What puts the “C” in TPCRM? As third-party risk management evolves, leaders are asking what the “C” in TPCRM really means, and why cyber risk now has an outsized impact on every other risk. We unpack what puts the “C” in TPCRM, why cyber is more than a checkbox, and how misunderstanding it can quietly put your entire business at risk. In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down the shift from traditional TPRM to TPCRM and explain why cyber risk can’t be treated as just another compliance item. From operational disruption and resilience to cascading supply-chain failures, the conversation explores how cyber risk intersects with financial, operational, and enterprise risk, and why boards and executives need a clearer, more connected view. What this episode covers: What the “C” in TPCRM actually stands for… and what it doesn’t Why cyber risk isn’t just about data breaches or compliance How cyber creates cascading impact across operations, finance, and supply chains Why treating cyber as a point-in-time risk leaves organizations exposed How leaders should think about cyber in business and boardroom terms Don’t risk treating cyber as a checkbox while it quietly drives your biggest exposures. Learn how to understand the real “C” in TPCRM and protect your business before cyber risk turns into operational and financial damage.

  • February 11 · 42 min

    Whose Breach Is It Anyway?

    Whose Breach Is It Anyway? When a vendor gets breached and data is exposed, whose breach is it anyway, and who actually pays the price? In this episode, we break down why finger-pointing after every breach is becoming the default response and what that means for real security outcomes. You’ll learn how shared data creates shared damage, and how leaders can respond smarter when third-party risk becomes a crisis. In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable truth behind vendor breaches, accountability, and transparency. From supply-chain incidents to public disclosure, they explore why blame doesn’t fix breaches. And what actually helps organizations recover, protect customers, and reduce future risk. What this episode covers: Why “whose breach is it anyway” is the wrong question—and the better ones to ask How finger-pointing delays response and increases long-term damage The hidden risks of third-party and supply-chain breaches When transparency helps—and when it can backfire Who ultimately bears the cost of a breach: vendors, companies, or customers Don’t risk repeating the same mistakes after your next vendor incident. Learn how to move past blame, protect your customers, and respond to breaches the right way…before shared damage becomes permanent damage.

  • January 28 · 39 min

    The Biggest Lie in Cybersecurity

    Who owns cyber risk in third-party relationships? In this episode of Third Party, we tackle one of the most urgent questions facing security leaders today: who is actually accountable for third-party risk when something goes wrong? If you’re a CISO, risk leader, or executive trying to avoid blame, regulatory fallout, or career-ending mistakes, this conversation delivers clarity you can act on immediately. Hosted by Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik, this episode breaks down the real difference between ownership, responsibility, and accountability in third-party cyber risk. The hosts unpack why CISOs are often blamed for risks they don’t own, how boards and executives should be involved, and why documenting risk decisions matters more than ever as regulators and courts increase scrutiny. This discussion explains how misaligned risk ownership leads to firings, fines, and failures—and how to prevent that inside your organization. What you’ll learn in this episode: How to define ownership vs. accountability in third-party cyber risk Why CISOs should inform risk, not silently absorb it Who actually owns financial risk when vendors fail How to document risk acceptance so it doesn’t come back on you Why regulators and boards are forcing clearer risk decisions How to communicate third-party risk in business and financial terms Don’t risk being the one blamed when a third party breaches your ecosystem. Learn how to clearly assign ownership, document accountability, and protect both your organization and your career—before the next incident forces the issue.

  • January 14 · 43 min

    The Truth About AI in Risk Management

    AI risk models are changing how organizations assess vendors, quantify cyber risk, and make high-stakes decisions, but most leaders don’t truly understand what’s happening under the hood. In this episode, AI risk models are stripped down and stress-tested to reveal where automation adds clarity, where it creates blind spots, and why overconfidence in models can quietly increase risk. If you’ve ever struggled to explain or defend an AI-driven decision, this conversation delivers the context you’ve been missing. Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this episode of Third Party explores why all models are inherently flawed, how AI amplifies both insight and uncertainty, and why human judgment still matters in third-party risk management. The hosts unpack real-world examples from vendor scoring, cyber risk quantification, and executive decision-making to show why explainability, defensibility, and adaptability matter more than perfect accuracy. Don’t risk trusting models you can’t justify. Learn how to use AI without surrendering accountability before the wrong decision gets made for you.

  • Dec 31, 2025 · 51 min

    Why 2026 Might Be the Hardest Cyber Year Yet

    The 2026 cybersecurity predictions are here, and they’re more urgent than anyone expected. In this episode, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what’s coming in the next 12 months, why AI risk is accelerating faster than anyone projected, and how security leaders can stay ahead instead of getting blindsided. If you want clarity (not hype) this conversation delivers real insight into the future of cyber, AI, and third-party risk. From AI vendors collapsing, to entry-level security roles disappearing, to third-party breaches overtaking direct attacks, the trio unpacks the shifts already shaping 2026. You’ll hear exactly what CISOs, boards, and security teams must rethink, and why the old playbook won’t survive what’s coming next. In this episode, you’ll learn: The biggest 2026 cybersecurity predictions and why experts expect things to get worse before they get better How AI risk is accelerating beyond traditional time horizons Why 50% of AI vendors may shut down in 2026, and what that means for your organization The real reason third-party breaches will outnumber direct attacks Where automation is being used incorrectly, and where it should be deployed Why boards still aren’t asking the right questions (and the questions they must ask in 2026) How AI is reshaping cybersecurity roles—from entry-level to the C-suite 2026 won’t reward teams who wait. Don’t risk falling behind. Learn what’s coming and how to prepare today.

Showing 1–20 of 20 episodes