

Building modern Third-Party Risk Management programs with Eric Hensley
18 snips Aug 31, 2025
Join Eric Hensley, CTO and CSO at Aravo, as he dives into the world of third-party risk management. With his extensive background in supply chain software, Eric reveals how indirect relationships often serve as weak links for data breaches. He critiques traditional IT risk assessments and advocates for a cultural shift towards a more integrated and automated approach. Discover the power of collaboration across departments and the role of AI in enhancing supplier risk management. It's a fresh perspective on making supply chains more resilient!
AI Snips
Chapters
Transcript
Episode notes
Rising Data Flow Expands Attack Surface
- More data is being sent to third parties constantly, increasing attack surface over time.
- Disconnected internal views of suppliers create persistent blind spots that attackers exploit.
Legacy Assessments Fail At Scale
- Traditional IT risk assessments were built for a few external vendors and internal systems and therefore don't scale.
- Those point-in-time, manual control-based approaches miss risks when you have hundreds or thousands of suppliers.
CRM Vendors Caused Major Breaches
- Several high-profile breaches stemmed from CRM providers that were underestimated by IT teams.
- Those vendors handled customer data but were not treated as critical, creating blind spots.