Risk Management Show

Building modern Third-Party Risk Management programs with Eric Hensley

18 snips
Aug 31, 2025
Join Eric Hensley, CTO and CSO at Aravo, as he dives into the world of third-party risk management. With his extensive background in supply chain software, Eric reveals how indirect relationships often serve as weak links for data breaches. He critiques traditional IT risk assessments and advocates for a cultural shift towards a more integrated and automated approach. Discover the power of collaboration across departments and the role of AI in enhancing supplier risk management. It's a fresh perspective on making supply chains more resilient!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Rising Data Flow Expands Attack Surface

  • More data is being sent to third parties constantly, increasing attack surface over time.
  • Disconnected internal views of suppliers create persistent blind spots that attackers exploit.
INSIGHT

Legacy Assessments Fail At Scale

  • Traditional IT risk assessments were built for a few external vendors and internal systems and therefore don't scale.
  • Those point-in-time, manual control-based approaches miss risks when you have hundreds or thousands of suppliers.
ANECDOTE

CRM Vendors Caused Major Breaches

  • Several high-profile breaches stemmed from CRM providers that were underestimated by IT teams.
  • Those vendors handled customer data but were not treated as critical, creating blind spots.
Get the Snipd Podcast app to discover more snips from this episode
Get the app