Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Navigating Third-Party Risk and AI in Cybersecurity with Rachel Curran
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape.
Key Topics
- Rachel’s background in GRC and her passion for security and compliance
- The role of AI in accelerating vendor assessments and risk management
- The importance of human-in-the-loop for effective governance at speed
- Bridging the governance gap by focusing on actual enforcement over paperwork
- How AI influences remote vendor onboarding and real-time data exchange
- Critical security risks introduced by AI agents, especially access control
- The shift from static to dynamic, self-optimizing AI-driven vendor risk profiles
- The evolving threat landscape and the dangers of AI-enabled malicious actors
- Practical strategies for organizations: going back to fundamentals and prioritization
- The significance of frameworks and continuous updating of security programs
- How to leverage evidence packs and automation for ongoing compliance verification
Timestamps
00:00 - Introduction to Rachel Curran and her expertise in GRC
01:17 - Rachel’s career journey and motivation in cybersecurity
02:37 - Personal interests: favorite travel destinations and favorite fruit
03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive
06:27 - The challenge of governance at speed in the AI era
07:00 - Human oversight’s critical role in AI-driven risk management
08:47 - Managing governance gaps through prioritization and verifiable data
10:11 - The biggest governance gaps organizations face today
11:37 - Using automation to improve vendor visibility and risk assessments
12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it
14:02 - The fallacy of paper policies versus actual practice in governance
15:40 - Data dependence and the importance of real-time controls and backups
16:07 - The impact of AI on third party risk landscape over the next 12-18 months
16:42 - Risks from AI-enabled access control and recent AI breach incidents
18:12 - Managing AI agents’ permissions and preventing privilege creep
20:30 - The threat of AI agents executing malicious or unintended actions
22:08 - The necessity of quality data, transparency, and human oversight
24:06 - Moving away from point-in-time assessments toward continuous, evidence-backed evaluations
25:00 - The potential to improve vendor transparency with real-time info sharing
26:12 - How AI can support dynamic security assessments and ongoing compliance
27:21 - The importance of foundational security controls and a risk-focused mindset
28:13 - Tactical action: back to basics—understand your vendors and their risk posture
29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring
Final Takeaways
Focus on fundamental security controls and verifiable data to reduce risks
Prioritize vendors based on actual risk to manage resources effectively
Use automation and frameworks for continuous compliance and rapid response
Recognize AI as a tool to augment, not replace, human judgment and oversight
Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management.
Want me to turn this into a LinkedIn post next?
Hey, welcome to Third Party Threat Hunters. This is our first episode in season two. I've got Rachel Kern on here, and she's the co-founder of Octivity and leader and moderator of GRC Meetup, which I have been able to attend a couple of and have been a participant of, and they are great. I want to highly recommend them. But I'm going to turn over to Rachel and let Rachel do her own introduction.
SPEAKER_02Awesome. Thanks so much for having me, Greg. I'm really excited to be here. And thank you for joining us in the GRC Meetup group to talk about third-party risk. Certainly an expert in that field. So uh yeah, I I am the founder at Loctivity. My career has a long and traveling one, but been in the world of GRC for about 15 years and really just fell in love with solving the problem of, you know, a lot of tech companies really don't know what to do when it comes to security and compliance and helping, you know, walked into a company where we had to go through bank due diligence and we didn't have the people or nobody knew what to do.
SPEAKER_01And that's right.
SPEAKER_02I dove in and just fell in love with it because I I do care probably more than I should about doing the right thing and seeing it as a superpower to help a company achieve its goals and do it safely. So that's a little bit of where I am. I live in Northern California, live on a little farm. It's my little my side hobby for the who I am.
SPEAKER_00But yeah, that that segues that segues perfectly, Rachel, into the next sort of the I've got a set agenda for this this season where I'm trying to so that users and and also that guests can kind of consistently know what I'm gonna get to and not just ramble on, which I have a tendency to do. Speaking of which, five questions. So about you that that give listeners an idea a little bit more about you. And you kind of answer a little bit about why did you get into this business, but maybe just expand on it a little bit more.
SPEAKER_02Yeah, uh it really does come down to I I have a passion for helping companies get things done intelligently. Um and so, you know, I got a tagline at one company that was from Chaos Comes Order, and that's kind of a good description of how I approach things. But yeah, into the business, it was that I saw a problem. But that was really the getting into it, was what I described earlier. But then kind of carrying my career is that I found that I could help companies really I kind of fell in love with SOC too. There was a framework that I could go and help companies build a good security foundation. And so started doing that, helping a lot of different small businesses, and that led me into managing security and clients within organizations themselves. But the the path was the problem solving, the feeling like I could unlock them to kind of run fast safely.
SPEAKER_00Right. And so let's switch quickly to the fun side. Or what do you like to go? Where do you like to go for vacation?
SPEAKER_02Man, if I can be sitting on a tropical beach, I'm out snorkeling, I'm a happy girl.
SPEAKER_00Sand between your toes?
SPEAKER_02Yes, I love it. I mean, I'm happy to be anywhere that's outdoors, but that that definitely is a passion. Yeah.
SPEAKER_00Well, uh specifically, like if you if you had to pick a specific location, not just any seal.
SPEAKER_02So one thing I don't like to repeat locations. I love to see the world. And so I'll say the last one I did where the sand between the toes was Tahiti, and we got to go out and swim with whales and girl with sharks, and it that's that's a lot of fun. Excellent. Yeah.
SPEAKER_00What's your favorite fruit and why?
SPEAKER_02Chocolate.
SPEAKER_00Uh chocolate. Oh, well the regular. You know, has antioxidants.
SPEAKER_02We all need it. So just my health, you know?
SPEAKER_00Excellent. No, no, no. It's uh it's it what it has some endorphins or it helps you with the yeah, yeah. So I totally get that. So dark chocolate, milk chocolate. Dark.
SPEAKER_02Absolutely dark chocolate, yes.
SPEAKER_00Yeah, make it a what's the funniest excuse a vendor error gave you? Obviously, you're leaving names out, or we're not we're not trying to embarrass anybody.
SPEAKER_02I hear things. I think one of the things that I think is funny that this maybe isn't funny if you don't live in this business. Like it's kind of boring, but it's the person telling me they don't have time to have a conversation, just send me the giant questionnaire. I I've had that statement. You're like, it is so much easier to hop on the phone for 15 minutes and kind of validate, you know what you're doing with security, give me your reports or whatever. So I love that when it's like, no, no, just send me the giant questionnaire, which might be because now they can apply AI, but this is before they're probably doing that.
SPEAKER_00Which they probably are doing, yeah. Nobody knows. It'll be our secret. And then so the the last of the five questions I've got for you is you've been an entrepreneur or an independent a lot of your professional career. Um, what drives you to do that? A lot of folks find a safety end of working for somebody, not having to do it on your own, uh having and me having been in that space, knowing both sides of that fence. What what drives you to to do this on your own and and and and start your own business and all that? That that that's a challenge at times.
SPEAKER_02Yeah, I'd say two things. Um, one, I don't have a lot of that fear. I figure I'm gonna do this work anyways. I kind of like just the independence to do it my way and work for myself.
SPEAKER_01Nice.
SPEAKER_02And part of that is just like I said with vacation that I don't want to go to the same place every time. I love the opportunity to work with different businesses and different challenges and how that, you know, it kind of can get stale if you're in the same place all the time. Although there's always a lot of challenges. But I I'd say that. And the other one is frankly, I'm gonna work my tail off. And I would rather do it for myself than for somebody else. So there's a part of that too.
SPEAKER_00That's a great answer, actually. I like that one. Might as well might as well drive your might as well drive yourself into the grave by yourself for yourself as opposed to for somebody else. Yeah, I love it.
SPEAKER_01Yep, yep.
SPEAKER_00That's a good one. But then you get you get, I think the what what drives entrepreneurs is that you you get all the reward. It's no longer, you know, it trickles down from somebody. So what just a quick five-minute discussion that we can kind of get users our sorry, listeners uh started on is the speed versus security dilemma. We're told that AI is going to revolution revolutionize the way we do vendor operations, promising to cut assessment times by weeks to hours, minutes, seconds, we've heard. But then the rush to automate, we are kind of accidentally opening the back door for the very third-party threats we're trying to prevent in some ways. What's uh you know, talk to me what you feel on the reality of governance at speed, especially since you're coming from this TRC perspective, and why the human in a loop is really more critical now than ever.
SPEAKER_02Yeah, I absolutely think that. But I think one of the things when I think about governance at speed is that applying AI to an existing process that's broken, I'm seeing that everywhere. And doing poor work really fast.
SPEAKER_00I've never heard that one. I haven't heard that one yet, too. What's a good one?
SPEAKER_02And I just look at this and we're like, now we're we're creating, I've always called third-party risk, frankly, third party risk management. I see so much security theater, right? This is a term I use all the time. But it's that we make ourselves think that we're doing something. I've got a whole lot of paperwork I did. Yay!
SPEAKER_00Yeah, I moved around.
SPEAKER_02It doesn't fundamentally mean I did anything. Right. And then I make that go faster with AI. And now it's like security theater at speed. And so that's my worry about that. So where I think about governance at speed isn't always, yes, automation is wonderful and we automate lots of things on our side. But a lot of it is prioritization. What is it doing to help you find what you need to focus your time? And that's really true of most things in security. Like where we see things fall down is that we missed something really important while we were over here making sure that, you know, I got my soxy report, but I forgot to put two FA on my snowflake. Right. That that's where we're missing. And so to me, the human in the loop is two things understanding the business. There's just a context that AI doesn't naturally have context about what's going on in your business. And yes, you can train, you can teach, you can do all this stuff, but most people aren't doing that. Asking a large LLM to tell you what matters, it's operating off of world's knowledge, not specific knowledge to your business. And that that's not going to fly. So to me, it's it's that intelligence that somebody understands the business, giving it context and also making sure that if you want to move fast, it's not necessarily about how much you can do fast. It's about doing the things that matter most and letting you know, really that prioritize.
SPEAKER_00Yeah, yeah, I I I can't, I can't I think what you're talking about is it to your point is is is you can you can just you're gonna fail faster. I mean to some extent. If you're just if your system is set up to just rubber stamp stuff and you want to just do that faster, that's not gonna get you better security. It just gets you faster compliance.
SPEAKER_01Yeah.
SPEAKER_00So so so you know be be careful what you're what you're what you're automating, right? So it may not really get the desired outcome, it may give you a false sense of security. And and I think the only thing I would add to that, uh, Rachel, is that uh it it emphasizes our need to be experts. If if you are just sort of skimming a surface of knowledge and then you're checking the AI, um you're you're both sledding down this down the slope blindfolded, right? You don't know if there's a tree in front of you, neither one of you, the AI or you. So again, don't think that the AI is now that suddenly the expert. You're you're you are the expert, and and you need to sometimes teach the AI the right way to do things, right? No, no, no, you're a little bit off the mark, you know, gets drift or whatever, hallucinates. I've seen hallucinations. So that's great. That's that's perfect. The which then segues into the the governance gap, which is our big question one. So, big question one for us is the governance gap. We talk a lot about using AI to accelerate vendor onboarding. We talked about this in governance at speed, but often the security assessments lag behind deployment. In your experience, where's the most significant governance gap in organizations trying to move at speed of AI and how do we bridge it without killing the AI agility we're trying to gain? That's a lot, but let's let's break it down. Where's the biggest significance governance gap what you that you've you see people doing?
SPEAKER_02For me, it's actually what we just hit on. It's the idea that what matters is that I've reviewed a SOC2 report really fast.
SPEAKER_01Yeah.
SPEAKER_02And so all of my vendors have come in and often to the point I've heard people tell me, oh no, we have a really good onboarding process. We know all of our vendors. And I will tell you, I do not believe that with any company I've ever seen. You might have a great process, it might work really well most of the time. But you know, working really well, or you know, what is it? It works 100% of the time, 60% of the time, right?
SPEAKER_01Right, yeah, yeah.
SPEAKER_02But it's not reality. Employees are signing up for things. So to me, what we should be using automation, it's not all AI, but it's part of it, is to understand what's going on in our environment. We have an unprecedented opportunity to be able to actually have visibility into what's happening and then take that information and it's about again prioritization. But it's this idea that I have now applied AI and I go through these assessments and I can check a box and get through, you know, compliance. And it's part of why, you know, some people kind of get tired of hearing the checkbox compliance complaint, or it is about compliance at the end of the day, I have to get through it. And that's true, but you can do compliance. Yeah, I always say like security is compliance, right? If you actually solve the problem with the risk, you're likely to have solved the problem for compliance. But when you just solve compliance, you've just created a false sense of security.
SPEAKER_00Yeah, you and I say say it the same thing in different ways. I I say if you create a good security program, cybersecurity program, compliance is a natural outcome of that. Because logging, monitoring, all those things are part of what produces compliance artifacts for you to put that you need to do to check the box. But if you and so if you aim for cybersecurity as your center mass, if you're thinking of bullseyes, then you're gonna you're gonna hit compliance too as part of it. But if your center mass is compliance, you will hit you will miss cybersecurity every time because the joke is, of course, everybody who's been breached is was 100% compliant the moment before they were breached. Compliance has nothing to do with cybersecurity. Uh it's a it's a it's a great discussion. Uh, I think the thing that I see, just if I could add, would be again, because I uh you know great great points would be um the governance gap I generally see coming from the assessor side when I started out was that what they have written down on paper isn't what they're doing, in fact. And so what usually what where we found when I would was running you know physical validation hundreds of s hundreds a year, almost all the fall downs by vendors were they had a policy, hopefully. The ones that didn't have a policy, they were a train wreck. And the worst would that you weren't even worried about that. But if they had a policy, it was generally that they didn't they didn't have it enforced in practice. Or you know, somebody was just doing it their own way, the way they've been doing it for the last three years, and never bothered to look at the process or documented policy. And so they were they were off. And that pop that process was documented for a reason. It was designed to be done in a specific way, and the person who is actually doing it or not doing it, doing it in their own way, has and somehow uh screwed up the process, you know, missing a control point, something like that. That's usually the governance gap I usually find.
SPEAKER_02Yeah, I think that's really fair. I think one thing that you're alluding to that I think is really important about the fact that like we build a great security program. I always look at like for compliance, you know, when I am doing a soccer or doing ISO or whatever you're doing, you can find those points that are repeatable, that that's what you share with your auditors, but it doesn't mean that's all you're doing. And there are things like to me, I always I'm broken record again on data access and dependencies. But what matters here when we're using a third party? It's not my job usually on the risk side to say, is this the quality of outcome that I want in terms of you know how we do how our HRS system works? Let HR figure that out. But what I need to know is are we dependent? Does this cause a serious issue for the company if this thing goes down? And then what do we do about that? And it doesn't mean that, oh, they have an SLA, it's 99%, we're good. Like so does AWS. If they're down, what does it mean for your business? And do you need to have a backup? And you may not need to, it might be fine. But you need to know that. And then if they're, you know, to have access to data. Now we're talking about data protections. Now that's where a lot more of that assessment comes into play, right? When their controls and ours. But if that data's lost, do I have a backup? Or am I completely dependent on this vendor and they disappear and everything's gone in my business? Those are the things that to me, and I just I think missing when we're going and saying, I checked for a stock two, we're good to go. We've never even thought about what the heck's going on. And so if we're missing those first few questions, and it's so simple. What access, what data, what dependency, right?
SPEAKER_00Like Yeah, and what what you're and and so what you're hitting on too, of course, is is resilience, but also inherent risk assessments that that aren't are not done. They're usually done as due diligence or they're done if if they're done at all. But there's some great examples out there. The one I like is the one from Third Party Risk Association. It's I think it's 14 or 15 questions. And if it's if it's more than 20, 30 questions, you're doing due diligence. You're not you're not really figuring out what what's the inherent risk in the vendor that then needs to trigger other due diligence. But again, this is supposed to be 30, 35 minutes. We'll go on, we'll go we'll keep going. Let's get to the next big question, which is the evolving threat landscape. If we if we look eight uh 12 to 18 months down the road, and that's kind of a scary uh thing because we've just seen some uh anomalous behavior, I would say, by AI, if you know what I'm alluding to. How is the nature of third-party risk changing because of AI? How is the third party changing because of AI? And that's a simple question, but it it's loaded.
SPEAKER_02Yeah, I was gonna say, I mean, you could go a hundred directions. So there's a part of me that can say that.
SPEAKER_00Let's do risk, let's do a risk-based approach. What's your riskiest, what's your scariest thing here?
SPEAKER_02I mean, frankly, I'm just gonna say access. And I the reason I say access, we're gonna really simplify it, is it comes down to these AI agents. We've already had our infrastructure, and I I consider our third party's part of our infrastructure because that's what we build on.
SPEAKER_00That's a great point.
SPEAKER_02It's so complicated and so integrated already, but then you add AI that can kind of make decisions, change what it's doing with the permissions that it's been granted. Historically, I gave this tool access to this tool and it had a single workflow, it was doing one thing. Now, whatever that token allows, anything that it allows can happen. And and teams are being told, go move fast with AI. And so there's more integrations, more permissions, and we hear about some certain models that are destructive by nature. That's not good news, right? Like and so, but you know, you have employees that might be destructive by nature. And so actually, Becky Newton, who we did a talk with the other day, wrote an article about thinking about AI as an employee. But I won't dive into that, but I'll say I would say if nothing else, our kind of access control has become something we have to be way more diligent around permissions and the idea of least privilege. You and I talk about zero trust. Um, obviously there's a lot more to AI, but I'd say if there's nothing else we're doing, it's understanding what when we grant access, yeah, something can do and and taking control there.
SPEAKER_00I I totally agree. My wife and I wrote a book on after before this AI and third priorist book, I wrote a book with my wife on privileged privileged access management because I've seen we both see this. She works in access management space. We we see this issue of privilege creep all over the place. And and no matter where you work, people just get it overprivileged. It sounds really weird. But you know, they're they're they're access. And so we're gonna do this now with AI agents. I know that we you know we're gonna do this. And and and you have even less control over an AI agent that than an employee to, I think, I I honestly think you're going to, because it will be harder to root out some of these AI agents once they get embedded into systems to some extent than it will be a human. I I I I hate to say that, but I think in some ways it will it'll be problematic. But that that's a good point. I the access management stuff is something I hadn't thought that was gonna be top of mind for you, but it is top of mind for me, not just because of the book, but because of just the just the knowledge that I have of and and having worked with with other folks in this space, the access issues uh are gonna be uh a paramount. But uh the hugging face I agent, this is the one where they were testing it and it actually broke outside the parameters and went and and did and actually hacked further than it was supposed to. Um I I I uh that that is uh a truly scary moment. Imagine if that well, that's it it got further access. That's not exactly how it must have done that. There's no other way it could have could have done the things it did without saying, hey, I'm gonna go escalate my access and then figured out how it did that. That's that's just truly scary.
SPEAKER_02Well, and that's what bad actors do, but AI is one thing that you have to faster. They do it faster, and uh, there's obviously bad actors in with humans, but with AI, it doesn't have to be a bad actor. It's on this goal to do something. Yeah, it's gonna do it no matter what. This isn't a conscious good or bad. It's not is my AI agent good. That's that's not a thing.
SPEAKER_00AI agents aim to please. They'll give you an answer, even if you don't like the answer, they're they're gonna give you the answer. Okay, so let me switch to the next question in that evolving threat landscape is are we seeing a shift from managing static vendor risk to managing dynamic self-optimizing AI agents? Meaning, you know, are we are we gonna get away from sort of point-in-time assessments to some extent and get into more dynamic AI agents talking to each other and and and accumulating data for our set for us and then giving us here's what the vendor looks like. Where do you think this is going in 12 to 18 months?
SPEAKER_02Frankly, I think we're gonna get a lot of noise first. And yes, I do think that we're gonna see AI agents, in a sense, that's already what's happening, right? Like you have a questionnaire that goes out from a system, may not be AI, but it's an out of a questionnaire, an AI agent answers it, then it comes back, an AI agent examines it or an AI tool or agent, will you either way? That's already in some sense happening. But the more we are doing this with just junk information, which is mostly what we're doing, it's all just a bunch of noise, as far as I'm concerned. Something that we're doing that I think is really important is that we're gonna need actual evidence. We're gonna need facts. That's where we have to operate from. AI does its best work with good context and good information. So we're gonna have to get to a place where we are a little bit more transparent and more working together. I mean, great third-party risk is a partnership, right? It's not Greg thinks he's gonna use Rachel's services and is going to interrogate her, right? It's Greg wants to use Rachel's services to achieve a goal and figure out how do we all do that safely together. We collaborate. And so we have to figure out how to do that and remember that that's what this is all about. It's not adversarial, it's working together. But I do think that yes, AI agents are gonna be doing a ton of this work, but they have to be served by actual data. And if we don't have that, then we're just getting a lot of noise and things are gonna fall apart. And yes, humans will be in the loop. I think they I'm rather convinced that always the humans who are doing the real work will always be there because AI agents can get they get off kind of a little bit, right? They're not reliable. And I know they'll get better and better, but I don't think we're ever gonna have that reliability without quality data, quality context, and oversight. I just think that's a part of how that works.
SPEAKER_00Yeah. I I I I I have a I totally totally agree with you. I I I think as we see uh a point in time assessment. So I actually have a small section of the book that says that AI will be the death of point-in-time assessments. I said it with a caveat. There will always be compliance-driven exercises that require an artifact to be driven, you know, f for force for a a SOC 2 to be done or a SIG to be answered, or, you know, some some sort of artifact to be produced. But you you'll get to the point where you don't you're to get good quality data, to feel to feel knowledgeable about your vendor's risk and security, you don't need to do the the point-in-time assessments as much. In fact, I think it's one of the ways uh you could get away from doing the point-in-time assessments like a like a like a uh uh physical validation or sending a remote questionnaire. If you're if you get to convince a vendor to give you more access to their data about their security, uh, then you could say, look, I don't have to come and assess you every year. I don't have to send you a questionnaire. And vendors can probably get into that a little bit more. Hey, uh, great. Okay. I I yes, you have to be a little more transparent about your your posture uh through through APIs and and and some of these new tools, but I think it also you could you can make the selling point to say, well, yeah, but I'm not gonna go bug you as much, right? Because I'm getting near real-time information that you're you're okay, or I get information that you're not okay, and we can have a more interventionist conversation than a preventive than than than than sort of reactionary, right? To some extent.
SPEAKER_02Yeah, I look at it as raising that minimum bar. So there's a place where you're not gonna get all the information you need about a company because there are things you can't check, right? Like I can't know for sure that you're not selling my data. Let's be honest. We're not gonna go, we have that level of information. This is a contract, this is an agreement that we have, this is a I've learned to trust you. But are you encrypting data? Do you have access controls? Is MFA enabled? These are Things that shouldn't be considered confidential or secrets. And if it's broken, right? We should be able to give each other that confidence that these kind of core controls are in place. And because we do need to focus more on what do these agents do? When I give you my data, what are you doing with AI? There's a lot to figure out of what's going on that we need to raise the bar and let third-party risk managers actually address the real risk. Right now they're busy in paperwork and checking off things that just shouldn't be conversations. So that's where I see that opportunity is that there's nothing to hide. And actually, I mean, I'll show that, but we've actually published our evidence pack. You can go see verifiable data of what's happening in our environment on foundational controls, because this isn't confidential. It's not a secret. Stuff you answer in a questionnaire, but it's verifiable. And that's something that then you get to that machine to machine. You get to AI can actually assess us, like you're saying, on an ongoing basis. The other part of this is that can be assisted by AI. I think these are a couple of things. When we talk about those kind of compliance artifacts, we are stuck in this kind of point in time for the sake of, you know, your regulator comes in and wants to see that annual report. But really, that's a revalidation that I looked at this stuff. But we have lots of things we do when we go through our audits that we say it's configuration control now. I no longer need to show you every ticket that went out. I can show you that there's a control in place that can't get released without being tested or reviewed or what have you, right? Right. That's what technology gives us. We can start to do that with third-party risk and even paying attention to what we're doing internally with the tool. We can start to get more and more context internally, where right now we're like, you know, we send emails, we beg, we plead, and half the time we don't know what our teams are actually doing with these tools. That's another side we need to be paying attention to because their security posture, what matters is what we're using them for. If we don't have that information, I think AI can help us with all of this. It's not only AI, though, it is automation generally can help us with these things, but we do have to have factual data and not a bunch of guesstimates that AI then works off of. Then we're just getting a lot of noise. And so I think that's the opportunity here. And it's very available. It can be done securely. So that's my take. Yes, though, I do think to the point that we are going to be managing more around AI agents, 100%. Companies are going to be so integrated. You're not going to have software that doesn't have AI integrated and that your internal teams aren't doing things with it with AI. Right. And so it's a security meets third-party risk conversation.
SPEAKER_00But so wrapping up at the end of each of these uh podcasts, we're going to do an after-action report, just taking some of the big conversations that we had today. What are the one things of tactical action you would want to take, have one of the uh listeners take back to their work and and and implement that would reduce some of these risks?
SPEAKER_02Yeah, I would say uh a couple of things. One is to not get so caught up in AI as this big, scary, crazy thing and go back to the fundamentals. What are we doing with this? What access does it have? That's one. Of course, there's things happening all over the place, but it's not fundamentally good or bad or crazy if AI is there. It's like, what are they doing? Are they training on our data? Honestly, the things that we've always done with any risk management is that we want to understand, again, access data dependencies. Like, let's go back to that.
SPEAKER_01Right.
SPEAKER_02And then prioritization. I think get out of this idea of can I do all these things faster? I've always been doing when it's broken. 48% of breaches involve a third party. This is proof. I mean, there's just no question. This still is a tedious job that takes a lot of time. It's frustrating. We're hiring trust teams and third party teams. So much investment into failure. And I hate to, you know, there's lots of people doing great things. I don't mean to put down everyone in the industry, but get back to basics and focus on what actually matters to your business. That that to me is find out what third parties you have and how they're being used. And from there, you'll get a lot of information.
SPEAKER_00I I would I those are great. That's a great uh way to wrap it up. I my threat hunter's take would be similar. I think the first thing you can do is have a good inventory of your vendors. If you don't, if you can't, if you don't know the depth of the of the problem, you're not gonna be able to start to figure out how to how to tackle it. And then secondly, get it, get it in risk-based order, right? Because it you're you're you're you're gonna spend time, you're gonna waste time spending trying to fix issues that you don't need to fix. And and then lastly, uh always be open and make sure that you pick a framework. Sorry, I was gonna still in there, but pick a framework for your system. Uh a framework uh really helps guide you to make sure you you get all the control points and that and everything. If you if you don't have a framework, your your your system, your program is just a bucket of best practices at best. It's you're probably gonna miss stuff. And also as things change, frameworks get updated, and then you can update your programs. So those are probably my three takeaways from this. Thanks again for attending, Rachel. It's been great. Uh thanks for joining us here on this edition of Third Party Threat Hunters Podcast. Be sure to subscribe for more cyber and risk insights. Stay uh stay tuned if you want for for bonus material where Rachel will share some uh some material about her product activity. Thanks a lot.
SPEAKER_02Thank you so much for having me.