Find partners
Third Party Threat Hunters

Third Party Threat Hunters

Hosted by Gregory Rasner

TechnologyInterviews guests

Episodes

7

Latest episode

Aug 2026

Language

EN-US

About the show

A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)

Listen to episodes

9 recent
August 25, 2026Episode 419 min

From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib

Send us Fan Mail In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure. They discuss the growing risk of third-party access, the limits of traditional vendor assessments, and why inventory is the foundation of any serious third-party risk program. Ronan also explains how AI can help security teams separate true risk from alert noise, prioritize what matters, and move from reactive checklists to actionable security decisions. Key Topics Ronan’s background in offensive security, Microsoft Security, and Barclays The origin story behind Shift Security Why vendor questionnaires are no longer enough The importance of knowing all third parties, known and unknown Third-party access as a major breach vector AI agents, shadow AI, and third-party exposure Using AI to reduce alert fatigue and prioritize real risk Building a third-party operational security program, not just a tool stack Main Takeaways Inventory is the first step to securing third parties. Risk management must account for both probability and impact. Vendor access is often more dangerous than vendor compliance gaps. AI can help filter noise, but only when it has strong business context. CISOs need a programmatic approach to third-party operational security. Notable Quote “We’re living in darkness until we understand what third parties exist, what access they have, and what they’re doing.” Why It Matters As third-party ecosystems grow more complex and AI agents become part of the security landscape, organizations can no longer rely on one-time assessments. This episode shows why visibility, continuous monitoring, and context-driven response are now essential for operational resilience. Guest Ronan, Co-founder and CEO of Shift Security Host Greg Mentioned Themes Third-party risk management Vendor access governance AI exposure Security alert fatigue Operational resilience Continuous monitoring Want me to turn this into a LinkedIn post next? Support the show

August 21, 20260 min

Map your critical dependencies before it's too late

Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once. Choose a service that directly affects customers, operations, revenue, or regulatory obligations. Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement. Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors. Ask what information and access each dependency has. Examine what could fail, be compromised, or behave unexpectedly. Define the intelligence signals that would tell you the risk is changing. Decide in advance what action to take if a dependency becomes unavailable or untrustworthy. Use the dependency map as a focused starting point rather than a massive transformation program. Support the show

August 20, 20260 min

Starting Small with a Critical Service Dependency Map with Michael Rasmussen

Send us Fan Mail Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live. In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable. Key topics Start with one critical business service instead of trying to map the entire enterprise at once. Choose a service that directly affects customers, operations, revenue, or regulatory obligations. Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement. Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors. Ask what information and access each dependency has. Examine what could fail, be compromised, or behave unexpectedly. Define the intelligence signals that would tell you the risk is changing. Decide in advance what action to take if a dependency becomes unavailable or untrustworthy. Use the dependency map as a focused starting point rather than a massive transformation program. Support the show

August 18, 20260 min

AIs Impact on Enterprise Boundaries with Michael Rasmussen

Send us Fan Mail The enterprise no longer ends at the org chart The idea The real organization is the network around the organization. Vendors, contractors, platforms, data brokers, APIs, and outsourced processes are not support functions - they are part of the operating system. Why it matters Risk, performance, and control can no longer be understood by looking only inside the company. If you treat the perimeter as external, you miss where value is created and where failure actually happens. In practice A SaaS outage, a broken supplier workflow, or a third-party data issue can now hit the business as directly as an internal failure. The modern leader has to manage the extended web, not just the firm. Support the show

August 18, 20260 min

The most dangerous assumption in third-party risk with Michael Rasmussen

Send us Fan Mail Michael Rasmussen explains why the biggest mistake in third-party risk is assuming you already know who your suppliers are and what risk they bring. Rather than focusing only on contract size or spend, he argues for measuring value at risk, because small vendors can create outsized operational or security impact. Key topics Michael Rasmussen says the most dangerous assumption is that an organization already knows its third parties and the risk they bring. He describes how his supplier third-party risk workshop has focused on a key question: how do you measure value at risk? He challenges the common practice of using contract size or spend as the main proxy for risk. He gives a practical example: a small supplier that delivers a critical widget may not cost much, but if it fails, manufacturing stops. He points to the Target breach as a reminder that a non-obvious vendor can become the doorway into a major incident. He notes that an HVAC vendor helped open the path to one of the largest credit card breaches in history. He emphasizes that identifying who your vendors are and what risk they bring is not simple Support the show

August 18, 2026Episode 322 min

The Evolution of GRC and Future Risks in Third-Party Ecosystems with Michael Rasmussen

Send us Fan Mail In this episode, Michael Rasmussen, a leading expert in governance, risk, and compliance, shares insights into the origins of GRC, its ongoing evolution, and its critical role in managing complex third-party ecosystems amid rapid technological change. Discover how organizations can stay ahead of regulatory pressures and operational risks through innovative frameworks and proactive dependency mapping. Key Topics Covered: How Michael Rasmussen pioneered the GRC concept with the first market models in February 2002 The seven generations of GRC, from Sarbanes Oxley-driven GRC 1.0 to GRC 7.0 focusing on orchestration and AI The importance of treating risk as an appetite for value, not risk itself Why periodic risk assessments are insufficient in dynamic environments and the need for continuous intelligence Bridging the gap between technical threat detection and business risk perspective The risks associated with opaque AI supply chains and shadow tech, and how to govern them proactively Critical dependencies in third-party ecosystems and how to map and manage them effectively Practical steps organizations can take today, such as dependency mapping and defining systemically critical vendors The role of organizational culture and personal routines in staying informed and resilient Timestamps: 00:00 - Introduction to Michael Rasmussen and his GRC background 02:45 - The origin story: How the GRC acronym was created in 2002 05:00 - The seven generations of GRC: From reactive to orchestrated AI-driven frameworks 09:00 - Common industry misconceptions and what should be retired in risk management 11:12 - How personal experiences and career pivots shaped Rasmussen’s expertise 15:13 - The future of vendor risk ecosystems and the dangers of shadow tech 17:24 - Governing non-transparent AI supply chains ahead of regulation 19:49 - Bridging the gap: Connecting technical threat intelligence with operational risk 22:13 - The importance of contextual analysis over simple scoring in third-party risk 24:32 - Risk management lessons from Star Trek and risk appetite misconceptions 27:27 - Practical advice: Building dependency maps for critical business services 29:09 - Final thoughts on identifying systemically critical vendors and ensuring resilience Want me to turn this into a LinkedIn post next? Support the show

August 13, 2026Episode 524 min

AI, Third Party Risk, and the Real Work of Operationalizing It with Paul Kurtz

Send us Fan Mail Greg reviews how AI is changing third party risk management with Paul Kurtz, a 30 plus year financial services veteran and current third party risk leader at First Century Bank. They focus on what actually changes in banking when AI enters vendor risk workflows, from ongoing monitoring to questionnaire design and regulator conversations. This episode matters because it cuts through the hype. Paul explains how AI can improve visibility and efficiency without replacing judgment, and why the real task is learning how to use it safely, document it properly, and keep the right humans in the loop. Key topics Paul Kurtz’s background and perspective Paul shares that he has spent more than 30 years in financial services, starting in retail loss prevention, then moving into banking and fraud investigation, and eventually focusing on third party risk management for the last 14 to 15 years. He frames himself as an AI generalist rather than a cybersecurity or technology specialist, which shapes how he approaches vendor risk. Why AI clicked for third party risk Paul says he was drawn to AI training because it was framed through the lens of third party risk management, not as generic AI hype. That context helped him see how AI fits into the specific decisions and controls TPRM teams need. The biggest challenge in traditional banking Paul points to change management as the first major hurdle when introducing AI tools in a conservative financial environment. Cost is the second major issue, since teams need enough understanding to do due diligence, choose the right tool, and understand how third parties are using AI too. What banks should automate first Paul says ongoing monitoring is the biggest manual process that should be automated sooner rather than later. He argues that too many organizations still treat assessments like a one-time exercise instead of a living risk process. Why AI is useful in ongoing monitoring Paul describes AI-enabled monitoring as a way to watch for cyber threats, financial changes, and other risk signals without relying on manual fishing. The goal is not to automate judgment away, but to surface the right issues earlier. AI is not a magic bullet Paul emphasizes that AI is still maturing and that many vendors are rushing into the market. He rejects the idea that AI will simply replace people, comparing current fears to earlier waves around computers, the internet, cloud, and robotics. What changed after AI training Paul says the biggest practical shift was learning to ask not just whether a vendor uses AI, but how they use it, where they use it, and what data it touches. He uses those questions to deepen his Infosec questionnaire and focus scrutiny where it actually matters. Risk-based focus beats blanket fear Paul draws a clear line between low-risk uses, like a vendor using Copilot for internal meeting notes, and higher-risk uses, like AI making decisions or interacting with customers. The key is understanding scope, safeguards, and whether the use case could affect business outcomes or regulated data. AI affects more than cybersecurity Paul and Greg discuss how AI touches legal, compliance, privacy, and information security, not just IT. That makes cross-functional conversation essential. How to balance speed and safety in banking Paul says the best path is staying connected to how regulators are thinking and keeping communication open. He notes that regulators are increasingly asking questions and engaging on AI, rather than simply blocking it. How to work with regulators Paul argues that if you can show you considered the risk, documented your decisions, and followed your process, regulators usually respond well. Greg reinforces that the issue is often not the tool itself, but failing to follow the process. Where the industry is headed Paul notes that a cottage industry is forming around AI assessments, frameworks, and advisory work. Greg adds that even AI agent evaluation has become a real consulting opportunity. Best first step for banks starting out Paul recommends learning the basics through training and then applying that knowledge to vendor populations. He warns that the danger is either moving too fast without understanding AI or too slowly and missing the competitive advantage. Community and peer learning matter Paul and Greg both stress that third party risk professionals benefit from sharing best practices instead of treating knowledge as proprietary. They encourage joining industry groups, attending events, taking certifications, and reaching out to peers directly. Notable quotes "I am not a cybersecurity specialist. I am not a technology specialist. I consider myself an AI generalist." "This is not a magic bullet." "The regulators are going to tell you what to do, but not how to do it." Episode Title Title 1: Why AI Won’t Replace TPRM Teams—But Will Change Them Fast Why it works: This title hits the core tension in the episode: fear of replacement versus the reality of augmentation. It speaks directly to third-party risk professionals worried about AI, while promising a practical, balanced perspective rather than hype. Title 2: The AI Blind Spot Banks Keep Missing in Vendor Risk Reviews Why it works: This creates urgency by framing AI as something banks are overlooking, which triggers concern and curiosity. It also targets the exact audience most likely to care: banking and vendor-risk leaders who suspect their current reviews aren’t enough. Title 3: How One TPRM Leader Turned AI Training Into Better Vendor Questions Why it works: This title offers a clear transformation story: training leads to smarter due diligence. It’s specific, credible, and appealing to practitioners who want an actionable payoff, not abstract theory. Title 4: Set It and Forget It Is Dead: Why Ongoing Monitoring Must Be Automated Why it works: This uses a punchy, familiar phrase to create instant recognition and tension. It taps into a real pain point in TPRM—stale assessments—and promises a timely operational insight for busy risk teams. Title 5: The Real Risk Isn’t AI Itself—It’s Using It Without a Framework Why it works: This reframes the conversation in a way that feels smart and contrarian. It appeals to risk and compliance professionals by emphasizing governance, process, and control rather than panic, which makes it highly shareable across business and regulatory audiences. Recommended: Title 5 — It’s the strongest mix of contrarian insight, clarity, and broad relevance, and it cleanly captures the episode’s main message about governance over fear. Want me to turn this into a LinkedIn post next? Support the show

August 11, 2026Episode 226 min

Navigating Third-Party Risk and AI in Cybersecurity with Rachel Curran

Send us Fan Mail In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape. Key Topics Rachel’s background in GRC and her passion for security and compliance The role of AI in accelerating vendor assessments and risk management The importance of human-in-the-loop for effective governance at speed Bridging the governance gap by focusing on actual enforcement over paperwork How AI influences remote vendor onboarding and real-time data exchange Critical security risks introduced by AI agents, especially access control The shift from static to dynamic, self-optimizing AI-driven vendor risk profiles The evolving threat landscape and the dangers of AI-enabled malicious actors Practical strategies for organizations: going back to fundamentals and prioritization The significance of frameworks and continuous updating of security programs How to leverage evidence packs and automation for ongoing compliance verification Timestamps 00:00 - Introduction to Rachel Curran and her expertise in GRC 01:17 - Rachel’s career journey and motivation in cybersecurity 02:37 - Personal interests: favorite travel destinations and favorite fruit 03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive 06:27 - The challenge of governance at speed in the AI era 07:00 - Human oversight’s critical role in AI-driven risk management 08:47 - Managing governance gaps through prioritization and verifiable data 10:11 - The biggest governance gaps organizations face today 11:37 - Using automation to improve vendor visibility and risk assessments 12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it 14:02 - The fallacy of paper policies versus actual practice in governance 15:40 - Data dependence and the importance of real-time controls and backups 16:07 - The impact of AI on third party risk landscape over the next 12-18 months 16:42 - Risks from AI-enabled access control and recent AI breach incidents 18:12 - Managing AI agents’ permissions and preventing privilege creep 20:30 - The threat of AI agents executing malicious or unintended actions 22:08 - The necessity of quality data, transparency, and human oversight 24:06 - Moving away from point-in-time assessments toward continuous, evidence-backed evaluations 25:00 - The potential to improve vendor transparency with real-time info sharing 26:12 - How AI can support dynamic security assessments and ongoing compliance 27:21 - The importance of foundational security controls and a risk-focused mindset 28:13 - Tactical action: back to basics—understand your vendors and their risk posture 29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring Final Takeaways Focus on fundamental security controls and verifiable data to reduce risks Prioritize vendors based on actual risk to manage resources effectively Use automation and frameworks for continuous compliance and rapid response Recognize AI as a tool to augment, not replace, human judgment and oversight Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management. Want me to turn this into a LinkedIn post next?

July 29, 2026Episode 127 min

Beyond Questionnaires: AI Agents, Zero-Day Breaches, and TPRM with Clarence Chio

Send us Fan Mail In this episode, Clarence Chio, CEO of Coverbase, discusses the evolving landscape of AI in cybersecurity, third-party risk management, and the implications of autonomous AI agents. We explore real-world incidents, innovative solutions, and strategic insights for security professionals navigating the AI-driven future. key topics AI's role in cybersecurity and risk management Implications of autonomous AI agents in security breaches Innovative solutions for continuous third-party monitoring The evolution of security culture in tech companies Strategic insights for security professionals in an AI era

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts