Your TPRM Program Isn't Fixable

Your TPRM Program Isn't Fixable

Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the whole thing down and start over.In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik get honest about what it takes to rebuild a TPRM program from the ground up. They dig into why the hardest part isn't the tooling, it's breaking the mental model you've been committed to for years. Drawing on the idea of creation and destruction, they walk through what they would keep, what they would throw out, and why using AI to speed up a broken process just gets you to the wrong answer faster.

In this episode, you will learn:

  • Why incremental improvement is the trap, and when a program needs a full rebuild instead of a refresh
  • What the questionnaire industry is really protecting, and what could actually disrupt it
  • The three things Bob and Ferhat would build first if they started from scratch
  • Whether you can outsource a TPRM program, and where that logic breaks down
  • Why AI model cards may replace stacks of AI questionnaires
  • How to shift from assess-everybody to monitor-everybody and assess by exception


If you have ever inherited a program you did not build and wondered whether to fix it or start over, this conversation is for you.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(24)

You Can't Say No to Your Vendors

You Can't Say No to Your Vendors

You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if levera...

29 Jul 41min

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why t...

15 Jul 33min

The #1 Mistake Boards Make on Cyber Risk

The #1 Mistake Boards Make on Cyber Risk

Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well...

1 Jul 32min

The Hidden Signals Predicting Vendor Collapse

The Hidden Signals Predicting Vendor Collapse

Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether for...

17 Jun 37min

Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger

A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this s...

4 Jun 45min

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are You Measuring the Right Risks…Or Just the Easiest Ones?

Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and w...

20 Mai 31min

Why Automation Is Creating More Cyber Risk

Why Automation Is Creating More Cyber Risk

Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and wha...

6 Mai 34min

Populært innen Teknologi

lydartikler-fra-aftenposten
tomprat-med-gunnar-tjomlid
shifter
rss-ai-forklart
teknisk-sett
elektropodden
rss-ki-praten
hans-petter-og-co
smart-forklart
rss-alt-som-gar-pa-strom
pedagogisk-intelligens
fornybaren
rss-polypod
rss-fish-ships
rss-bak-skyen
nasjonal-sikkerhetsmyndighet-nsm
rss-ki-til-kaffen
rss-grenser-for-ki
kortslutning
rss-digitaliseringspadden