You Can't Say No to Your Vendors
Third Party29 Heinä

You Can't Say No to Your Vendors

You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if leverage is mostly an illusion, what actually moves a vendor to fix their exposure?

In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dismantle the idea that third-party risk is about power and rebuild it around something more useful: collaboration. They dig into why the questionnaire-led, finger-wagging approach fails, how to communicate risk in dollars and cents that the business will actually act on, and why the relationship you build before an incident matters far more than any contract clause after one.

In this episode, you will learn:

  • Why "saying no" was never the CISO's job, and what the real role is

  • How to turn a contract into a collaboration tool instead of a weapon

  • Why intelligence-led outreach beats questionnaire fatigue every time

  • How to communicate vendor risk so business stakeholders actually respond

  • What to do when a hard-to-replace vendor won't budge

  • Why the first interactions with a vendor set the tone for the entire relationship

If you have ever felt ignored by a vendor who has bigger customers than you, this conversation will change how you show up to the table.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(23)

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why t...

15 Heinä 33min

The #1 Mistake Boards Make on Cyber Risk

The #1 Mistake Boards Make on Cyber Risk

Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well...

1 Heinä 32min

The Hidden Signals Predicting Vendor Collapse

The Hidden Signals Predicting Vendor Collapse

Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether for...

17 Kesä 37min

Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this s...

4 Kesä 45min

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and w...

20 Touko 31min

Why Automation Is Creating More Cyber Risk

Why Automation Is Creating More Cyber Risk

Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and wha...

6 Touko 34min

How to Calculate the Real Cost of a Third-Party Breach

How to Calculate the Real Cost of a Third-Party Breach

Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how org...

22 Huhti 40min