Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
From Check-the-Box to True Third-Party Operational Security with Ronen Gottlib
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure.
They discuss the growing risk of third-party access, the limits of traditional vendor assessments, and why inventory is the foundation of any serious third-party risk program. Ronan also explains how AI can help security teams separate true risk from alert noise, prioritize what matters, and move from reactive checklists to actionable security decisions.
Key Topics
- Ronan’s background in offensive security, Microsoft Security, and Barclays
- The origin story behind Shift Security
- Why vendor questionnaires are no longer enough
- The importance of knowing all third parties, known and unknown
- Third-party access as a major breach vector
- AI agents, shadow AI, and third-party exposure
- Using AI to reduce alert fatigue and prioritize real risk
- Building a third-party operational security program, not just a tool stack
Main Takeaways
- Inventory is the first step to securing third parties.
- Risk management must account for both probability and impact.
- Vendor access is often more dangerous than vendor compliance gaps.
- AI can help filter noise, but only when it has strong business context.
- CISOs need a programmatic approach to third-party operational security.
Notable Quote
“We’re living in darkness until we understand what third parties exist, what access they have, and what they’re doing.”
Why It Matters
As third-party ecosystems grow more complex and AI agents become part of the security landscape, organizations can no longer rely on one-time assessments. This episode shows why visibility, continuous monitoring, and context-driven response are now essential for operational resilience.
Guest
Ronan, Co-founder and CEO of Shift Security
Host
Greg
Mentioned Themes
- Third-party risk management
- Vendor access governance
- AI exposure
- Security alert fatigue
- Operational resilience
- Continuous monitoring
Want me to turn this into a LinkedIn post next?
Hello, welcome to uh Third Party Threat Hunters Season Two. This is my session with Ronan from Shift Security. Ronan is the co-founder and CEO of Shift Security. Ronan, I'd like to give the guests the opportunity to do their own introduction so that it's more poignant to what you're looking for.
SPEAKER_01Perfect. I'd like to introduce myself. Thanks for having me, Greg. Really pleasure and honor to be here. So yeah, Ronan, CEO of Shift, Shift Security. Shift is almost two years old. I'm myself much older, 27 years in the industry, from offensive security roles through consulting, head of Microsoft Security Division here in Israel, Signia ex-executive. And in my last role before starting this adventure of entrepreneurship, I was a practitioner, the director of cyber innovation under the chief security officer of Bopleys.
SPEAKER_00I'm glad you did the introduction. So that's some information I don't think I would have been able to get to. So that's great. Thank you, Ronan. We're going to do five quick questions. We always ask the guests to get them to know them better. The light bulb moment is the first question. What was the light bulb moment that shifted you from traditional security to building a third-party operational security-focused product? How did that what was that shift for you?
SPEAKER_01So actually, in my last role, I was in charge of all the technologies. I was in charge of the team that was the practically the gateway of technologies into the chief security officer of Park Lease. And the amount of work we've done around third party and assessment and all that kind of tedious work was frustrating because a year later, when the vendor was integrated, there was zero visibility in what they're doing. And I decided to this it's time to change, it's time to drive value, it's time to move the needle. Working with a lot of startups as again part of the role gave me that passion. So combining those two things.
SPEAKER_00Here we go. Thanks. That's good. So the Tel Aviv ecosystem, there's there's a lot of cybersecurity and industry around in the Tel Aviv and Israel as well, especially how does that cybersecurity ecosystem in Tel Aviv? I think somewhat like Silicon Valley change your approach to innovation and in that area.
SPEAKER_01I think in two ways. And again, this really also relates to working with a lot of startups, seeing a lot of young guys coming out of the 8200 of the IDF, seeing innovation created by itself, understanding how a good team, a good startup looks like, and understanding how innovation is built. Again, that would probably my last role was was the great point in time to uh to observe all that. But it's not only that, it's I think Tel Aviv has a unique approach between founders, between companies. There's a lot of support and a lot of kind of you know good vibe between founders that helps each other. And for me, this is you know the brainstorming, that's sharing problems, that's that's that's the power of this ecosystem here.
SPEAKER_00And then you have the you have the VC sort of interest around the area, so that that helps kind of fuel that fuel that innovation as well, because you do need that VC as well. Absolutely. The next question I'm gonna ask you is uh is probably the most contentious one, which is, and we'll lose you potentially friends and and and loved ones in the Tel Aviv area, but um, it's the hummus debate. And there's a it's a it's a it's a fierce one. And I'm gonna be asking some of your compatriots who are in the Tel Aviv area the same question. So you may end up we end up having everybody hate each other, but or disagree with each other. But what's your if I have to fly into Tel Aviv tomorrow, what's the what's the one place I have to go for the best hummus?
SPEAKER_01That question caused wars in the past. So basically, I don't think there's a single place. I think there's a well-known place, you know, Abu Hassan in Jaffa is is what what we it's kind of a consensus. But if you'll ask me, I prefer a small specific place. Completely different in Tel Aviv, a more kind of posh place. But the homes is a hums. If if you go to the originals, to the guys that you know to the hole in the wall, you're good. You're good.
SPEAKER_00That's a good recommendation. So it's not necessarily um a particular place, but it's the kind of place you pick that will give you good homework or not, correct, right? That's good. That's a very politically correct uh question answer as well, too, and it won't get you in any trouble. What's the biggest misconception? So the next one is developer misconception. What's the biggest misconception developers have about security teams?
SPEAKER_01That's a good one. Well, I think I think they think that we think we security people think they are the problem. And basically we we don't. I think most of most of us know that the problem is the deadline, the fact that they need to make it. And we are basically met on this and and and driving nuts from the same thing they are. I worked with so many developers that pushed an you know, individual that were super, you know, strong with security and and and and pushed for a better security. Well, we we think the same as you are.
SPEAKER_00Good, good answer. I didn't I wouldn't think I didn't think about that as an answer. It's like that's something when I mean that that's a great perspective. Let's have a the fun one. So if you weren't if you're not doing what you're doing now, what field would you be in that you would really enjoy? Again, no money, the money's not the issue, it's it's not an income issue, it's it's what you would do for fun. And it can't be this because I know this is fun, but something else.
SPEAKER_01Yeah, it it is fun. But you know, when you're building a style, you're always thinking, okay, what next? I'm gonna do if if I want to go and build again, what would I do? And the things that kind of burns and and kind of drives me now is uh teaching, education. I think it's a it's a very, very important mission. By the way, if you have money, you can and do it only because of passion, then and and I think it's even better because you're just there there for for for the value. So probably that will help.
SPEAKER_00Look, I I teach part-time uh class a semester at it uh online for community colleges in their cyber and it program. And I it doesn't pay a lot. The pay isn't really what I do it for. It's it keeps me connected to folks who are uh coming up, and and I think as leaders in the space, we have to do our best. We can't complain that there's not enough talented staff. We we have to do our best to try and find and teach them. So that's that's how I do it. So good kudos to you. We're gonna agree. I think teaching is an is a noble profession if you can afford to do it. All right, let's get into the hook start. So we're I'm gonna ask you a question about the hugging breach incident. So this is the one where um uh in a in a in a in a uh cyber test, it the AI agent went up went further afield than it was supposed to. Uh, there's more technicality to that, and I I don't mean to sort of minimize it, but I'm trying to get to more of the the the risk about the issue than specific issue itself, which is the fact that folks are not talking about agents doing things that they're not supposed to be doing or originally weren't taught to do, and they figured it out themselves, which is not autonomous, but getting there, and that's a concern. So, what are your thoughts on that? And what how should sort folks and leaders in the space be thinking about that for their third-party risk?
SPEAKER_01So I love that because this is basically one of the strongest use cases we're focusing on, the third party AI exposure and exactly that incident that kind of scaring everyone. Look, the the third party you've onboarded a year ago with and you gave them access. Now, replacing that access with a genetic entity that sits behind this and can start doing things, that's that's a scary thing. That's that's a real risk. Basically, first and foremost, and that's what we're focusing on. You first want to understand who are all those third parties that you're using and have access to your organization, and then you want to understand, okay, what did they do in terms of AI, what agenda capabilities they have, how what did they what they're adding, how you know what processing, what did they do with your data? That's kind of step one. You have to start inventoring and kind of building that inventory and understanding what's there in order to basically start securing it properly. Until we do that, you know, we we're we're living in darkness. So that's the first step.
SPEAKER_00That's an area hit it on as well. When people ask me what I do to start my third-party risk program, is thinking inventory with third parties, because if you don't have an inventory, you you you can't figure out where the risks are in the first place. That's good. The first big so I get we always had uh big question one, big question two. Big question one is on the the sort of the new definition of third-party visibility. And I'm I'm gonna read my questions, so I make sure I don't screw it up. But Ronan, traditional third-party risk management often ends at vendor questionnaires. We know that's really not enough. We've looked at modern software building materials, which I have some concerns about myself because I think it's just almost too much information. Um it's mostly open source in libraries, but unknown, but but built by unknown developers. From your perspective, how would CISOS redefine that third-party visibility where we focus too much on the security of the vendor and not on the dynamic security risk of the code that the vendor is pushing into our production? It's just for those at home, what we're trying to do is delineate between we're focused on the vendor, which is important. You want to you want to assess the vendor and understand what the risk is, but we're not assessing those changes they're making to code, which is what we're really consuming from the vendor. And so that's the question to Rome.
SPEAKER_01So so it's a it's a it's a very good question. I think, and specifically with what we do, okay, there's a big gap on, and again, it's it's related to the inventory and understanding what's happening after view on boarded the vendor. And that's I agree, right? I think that there the the market is is focused on okay, let's understand the the you know the the compliance and the you know and the and the artifact and the answer questionnaire and and missing what's happening the day before that before uh sorry, the day after that, after we're getting into the integration. And it's it's not just software, it's also the access, and and software is obviously code that the vendor is pushing is is part of that, but just understanding what the who again who are all the vendors, you've got you've done this, what access they have internally. Because at the end of the day, this is this is where the uh this is where the you know operational security happens. And it's you know it recently uh it was Verizon that uh released their uh 2025 DBIR uh kind of report. The numbers of uh breaches from third party has raised to somewhere around above 50 percent, somewhere around 60 percent now.
SPEAKER_00I don't know forty-eight percent, or is it but it's almost it's roughly half of all the breaches are caught by vendors, which that's a rounding area to 50 percent at 48. It's it's it's enough.
SPEAKER_01No, no, and and and and it's there. Now think of it. It's not it's not just the the the the software, and and to be honest, I don't think it we should focus only on that specific library. Because if if the third party breach is what's getting the attacker in, and it's not because of a library or a or a you know a code issue or a buffer overflow or what have you, it's because someone prov uh provisioned access to a vendor and they're not tracking it, and the vendor is not secure enough, and we're not tracking that access, then it's even worse than that weak software library because it's so easy to basically find those credentials and get in. The door is open.
SPEAKER_00Yeah. I I think if you took a Venn diagram of the third-party breaches and then access breaches that were caused by access, that's the area you'd want to focus on quite a bit, is what you're getting running. Is if it's a third party with with access, first of all, you need to know the access. And then I think I I my my advocacy has always been when I work with customers, clients of mine is is to recommend that all third parties have uh privilege access management, that they're always they're always uh considered elevated access because you don't really know who the next person they are on the inner end, is they're not your they're not your employer contractor. So you need that little bit extra ump to know it's really Ronin who's logging in, or Greg versus Greg's Greg's surrogate for today because Greg was sick and it the work had to get done. So Greg gave the password and stuff to to Ronin to do, right? That that's not what you signed up for as a customer of the vendor. So I I I I totally agree with you. I think the the overlap of privilege access and and um third parties is probably uh sorry, access in general. And then you're gonna add on to this vendors with AI agents who are gonna have their own access as well, which are just those are gonna grow exponentially.
SPEAKER_01And and and to your question, you know, I I love to speak about the Vercel breach that happened recently. Oh, yeah. Because of the, you know, remember context AI. So Vercel happened because of context AI. Context.ai was provisioned by by an employee into Vercel ecosystem. Context.ai was breached and there was leak, sort of leak credentials of comp uh context.ai people, which led to to again to the adversaries and entering Vercel. You know, that's the point. I mean, whether it went through an assessment process, and even if it you know it's a shadow IT or shadow AI, that's exactly where things are breaking up. This is you know the understanding who has access, known and unknown, understanding what access, and continuously monitoring that so you can have that kill switch handy when things are go wrong. Yeah.
SPEAKER_00Yeah, access is a real issue for and I I know it's uh we're repeating the dead horse and Dr. David Sherry beating some more, but but it is a real concern and it keeps coming up over and over again, and and and especially now with AI and the agents. All right, let's uh let's move on to big question number two, which is AI-powered remediation, which is something I love. Um automation is great at finding vulnerabilities because it's notorious for generating, but it's also notorious for generating noise. It burns out security teams. How do we ensure shift security's automated vulnerability detection is actually providing actionable remediation rather than just sitting on a list of alerts? What do you define as kind of true risk in the environment versus everything labeled as critical?
SPEAKER_01So again, great question, and one of the biggest problems, and and you know what, you know, alert fatigue and and all that noise is something that was very very close to my heart. If if if there's something that shift is doing, by the way, is tapping into a lot of kind of noise generator and identifying all the data points that we are collecting and filtering that relevant from noise. Because we collect the business context, because we understand you know whether there is a relation to the third party business relation, contractual or some sort of uh agreement and procurement, because we understand whether vendors in third party is connected in identities, when that alert is coming in, or that threat intelligence signal is coming in and we're starting to identify, you know, and we see what their behavior internally, we basically shift is providing the accurate business context supported uh with action items that filters the false positive from the actual relevancy. And because we know exactly what this vendor is touching, which data and which what access do they have, we can define essentially if it's a critical access or you know what? That's fine. We know that the vendor is being breached, but they don't have any critical access. So you can you can take care of that, but on your own speed. So this is how we basically provide not only value on understanding relevancy and and and the and the insight on what we need to do now, but also the the understanding when something is not that bad and you know, and act accordingly.
SPEAKER_00Yeah, yeah, yeah. No, it's good. What I think what you're getting at is, you know, in the in the old days back in the when it was you best you could get was a BI tool and and you could sort of create some threats and alerts and thresholds, was you still had to muck through, as it were, what the noise was. The advantage of AI properly trained with good data sets is you can get it to say, I I based upon what I've been trained and what I know in the world I see, this really isn't that important. They they're breached, but they don't have our data and they don't have access. They're a vendor of ours, and it's it's terrible that that happened, but there's no risk to us. I'm not gonna I'm not gonna throw that up on a dashboard for the for for the customer to look at. I'm gonna look at the one who had our data who isn't breached yet, but is trending to has got some operational issues that we need to pay attention to. Is that what you're gonna hear, Ronan? Absolutely, exactly.
SPEAKER_01And the fact that you have an I and you can collect all those data points and make in and identify with the eye, with learning, with um, you know, tagging the the right areas, you can provide that that insight very, very quickly and very accurately to the security operations.
SPEAKER_00Great. Um so we always like to wrap up and we're we're running a little bit early, but that's great. This just gives us uh time to go do something else. But the after-action report. So based upon some of the things we talked about today, Rodan, if you were gonna if you were gonna convert uh talk to a CISO about what they want to listen to this and what they want to do to improve their third party risk and program, give them what you what you think they should be paying attention to right away.
SPEAKER_01So that's that's another question I really love. Because essentially that this is why we're here. Shift is here to help move from that kind of check the box process to a proper third party operational security program, which is not partial. Okay, it moves, it it helps teams do the the assessment, an agentic assessment. But in order to have kind of the North Star kind of program, you want to have, and we've discussed this today, Greg, you have to have full visibility, understanding known and unknown third parties, governed and ungoverned, procured or not. That's first. You have to see it to secure it. Then you want to understand the impact. Risk is a mathematical equation of probability and impact. You can't just look at one side of that equation. For us, the assessment is okay, let's understand what the chance for something bad to happen essentially, probability. But we're missing the impact, what's happening the day after we were integrated, what the vendor can do if some in in in my organization if something goes wrong. So you have to understand the attack surface, you have to you have to understand and have visibility into vendor access and continuously access for all things changes, and then you want to have the right tooling to identify similarly, as we've discussed, the third-party AI exposure, because everything we we said that that is changing, and be able to respond to third-party breaches and incidents by having all those things. So essentially, everything we've discussed today is what we define as the North Star of a third-party operational security end to it.
SPEAKER_00Rodan, that's great. What I liked about it was, and if I was talking to a CISO in a similar conversation, or we were tag teaming the CISO, I would say look what Rodan's just said is not, he talked very briefly about the product. The 99% of what he talked about was a program. A program is not a tool, right? And so what I loved that you talked about was you know taking inventory, evaluating the risk, finding your risk thresholds, right? Um, what it what is your what is your optimal risk level? What are critical vendors versus low risk vendors? All those things are part of a discussion. And then you picked up at the end to say, then you find a tool set that meets those goals, your North Star of what you're trying to accomplish. You know, so if you're looking at operational resilience for your third-party risk, there you go. I I think uh the other thing I would add would be make sure that you're you're getting your staff well trained and uh link into organizations like Third Party Risk Association, who are great for sharing information back and forth with and collaborating and commiserating with your colleagues in the space. So I think that's also the other thing I would add. Ronan, thanks again for being a guest. It's been really helpful. I'm going to we're going to do bonus material for this one as well. But what we're going to do for this one is Ronan's going to send me a link or a video to his his existing uh demo, and we'll use that for that. So it's just a little crisper. So just stay tuned for that or look for that on the podcast site. Thanks again for tuning in for Threat Priority Threat Hunters, and hope to see you next uh next session.
SPEAKER_01Thank you, Craig.