Discover
Third Party Threat Hunters
26 Episodes
Reverse
Send us Fan Mail In this short from the podcast, Ken explains how organizations are failing to capture all the AI risk in their enterprise. Support the show
Send us Fan Mail Your vendor’s product might be running an LLM you never evaluated and that silent dependency can become the cleanest path into your data. We sit down with Ken Huang, author and AI security researcher, to unpack what “third-party AI supply chain” really means when GenAI features are stitched together from embedded models, vector databases, RAG pipelines, agent frameworks, and downstream APIs you do not directly control. We get practical about the risks security teams ar...
Send us Fan Mail “100% automated vendor risk assessments” sounds seductive right up until you are staring at unstructured SOC 2 reports, mismatched ISO certificates, and a queue you cannot clear. Greg sits down with Brian Shaw, a long-time third-party risk and compliance leader, to talk about what AI can realistically do in third-party risk management today, and what it absolutely should not do yet. We start with a blunt warning: do not automate a broken process. If a question does not chang...
Send us Fan Mail Support the show
Send us Fan Mail Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor. We dig into q...



