Are You Measuring the Right Risks…Or Just the Easiest Ones?
Third Party20 Touko

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and why those metrics often fail to reflect real business risk. If you’ve ever wondered whether your TPRM strategy is actually driving better decisions or just producing reports, this conversation will challenge how you think about risk measurement.

Hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the gap between what organizations track and what actually matters—from misleading metrics and “top vendor” lists to the struggle of communicating risk to executives who don’t see the value. You’ll learn how to rethink your approach to third party cyber risk management, move beyond surface-level reporting, and focus on the signals that truly impact your business.

In this episode, you’ll learn:

  • Why most third party risk metrics are based on convenience, not impact

  • The difference between measuring activity vs. measuring real risk

  • How to make risk meaningful to boards and executive stakeholders

  • What “good” risk metrics actually look like in practice

  • How to avoid false confidence from incomplete or misleading data

Don’t risk building your strategy on the wrong signals. Learn how to measure what actually matters—and make better decisions because of it.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(27)

Is AI the End of Humanity or Just Another Y2K?

Is AI the End of Humanity or Just Another Y2K?

Some of the people building AI are warning it could end humanity. Others say it's all hype. Meanwhile, AI agents have already escaped a testing sandbox and attacked another company's infrastructure. S...

23 Syys 37min

Are Your Vendors Lying to You?

Are Your Vendors Lying to You?

Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells ...

9 Syys 35min

The AI Scanner Hype Test

The AI Scanner Hype Test

AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent....

26 Elo 37min

Your TPRM Program Isn't Fixable

Your TPRM Program Isn't Fixable

Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the wh...

12 Elo 37min

You Can't Say No to Your Vendors

You Can't Say No to Your Vendors

You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if levera...

29 Heinä 41min

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why t...

15 Heinä 33min

The #1 Mistake Boards Make on Cyber Risk

The #1 Mistake Boards Make on Cyber Risk

Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well...

1 Heinä 32min

The Hidden Signals Predicting Vendor Collapse

The Hidden Signals Predicting Vendor Collapse

Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether for...

17 Kesä 37min