Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Relationships Beat Tools In Vendor Risk with Heather Kadavy
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Vendor risk doesn’t fail because you picked the wrong platform. It fails because nobody trusts the program, nobody speaks the business unit’s language, and everyone thinks it’s someone else’s job. We’re joined by Heather Kadavy, Director of Membership Success at the Third Party Risk Association (TPRA), to get honest about what actually moves third-party risk management forward when teams are lean, vendors are complex, and AI is changing the rules.
We dig into the biggest myth in TPRM and supply chain risk management: that technology “solves” the problem. Heather lays out why relationships and governance matter more than automation in the early days of fixing a broken program, and how to earn first line buy-in by shifting from compliance talk to business impact. If your stakeholders only care about sales and speed, we walk through how to translate cyber vendor risk into outcomes they already track like revenue loss, operational disruption, customer impact, and regulatory exposure.
From there, we get practical about resilience. Heather shares her “depth of three” strategy for training successors so TPRM survives turnover, plus the cultural marker of mature programs: leaving egos at the door and treating risk management as a team sport across security, compliance, finance, and the business. We also tackle shadow AI, AI governance, and fourth-party dependencies with concrete approaches like mapping critical business services, identifying concentration risk, asking direct AI questions, and combining continuous monitoring with human judgment where it counts.
If you want a clearer, more effective vendor risk management program that partners with the business and improves nth-party visibility, hit play. Subscribe, share this with a colleague, and leave a review so more practitioners can find the conversation.
Welcome And Guest Background
SPEAKER_00Hey, welcome to the next edition of Third Party Threateners Podcast. We have here our special guest today, Heather from the Third Party Risk Association, who is a, I consider a friend of mine, and I've known her now for a couple of years. I've been involved with TPRA for quite some time now, and I want to let Heather introduce herself and give her background.
SPEAKER_02Thank you, Greg. It's great to be here. My name is Heather Cadvy. I live in Lincoln, Nebraska. I spent roughly 35 years in a financial institution. Most of that time helping people understand and manage risk, creating enterprise risk, operational risk, third-party risk, security, safety, and continuity planning for a Nebraska-based financial institution. And now I serve as the director of membership success for TPRA, where I have the opportunity to collaborate with practitioners and regulators and consultants and technology providers around the world. And my passion really is helping to translate risk into business language and helping people build effective programs, connecting people through thought knowledge and networking.
SPEAKER_00Well said. Thank you. Thank you, Heather. And you do a good job of it. I'll be the first to say that happened.
The Biggest TPRM Myth
SPEAKER_00So let's we get into the five quick questions to get to know the guests better. First one is what is the one myth about TPM programs that tech first risk teams constantly get wrong?
SPEAKER_02Probably the biggest myth is that technology solves the problem. Technology is incredible, incredibly valuable. But third-party risk management or supply chain risk management or vendor risk management is fundamentally a people, process, and governance discipline. And I just think that organizations succeed because they learn that it's as strong a relationship issue as it is great technology.
SPEAKER_00Perfect. Great. All right. Next one's on relationship versus automation. Which matters more in the first 90 days of fixing a broken TPR program? Relationships or the automation?
SPEAKER_02Well, I bet you can get which guess which one I'm going to say. Relationships win without a question. Automation, definitely, I, you know, there's a place. It accelerates the maturity, but that relationship creates it. I think if people don't trust the program and the technology, the best technology in the world won't fix the problem.
SPEAKER_00Yeah, and and and uh and uh our our programs kind of sit in the middle of everything and you kind of have to build bridges to get things done because most folks you're you're getting people to do things they don't really want to do in in a lot of ways. That's great. Yeah, and I totally agree. I think relationships are are great. You can build off once you've got relationships, you can build the automation because you've got the bridges to the automated teams you need to automate with. What's the most unusual or surprising vendor type you had to assess during your 34 years of financial services? And did you? I'm sorry if I said the 34 years. I'm sorry.
SPEAKER_02That's it. That's a great question. My banking role probably, not necessarily the critical vendors, but the the next tier down, the high-risk vendors, due to data privacy concerns, they were more fascinating to me because it was oftentimes that the the vendors were using boilerplate agreements, they didn't align to the organizational actual products and like the scope. Um they were just throwing due diligence documents at you without even continu considering what the actual engagement scope was. But probably, you know, in 2024, I was assessing thousands of vendor sock reports for one large oil and gas company. And I found that very uh interesting because I was able to apply my knowledge across the industry lines. And so yeah, I I think that was probably the most intriguing. But today I would probably say I am intrigued by how third-party risk management programs are handled across the world, from South Africa to Canada to UK to Brazil. I think that's fascinating.
SPEAKER_00Interesting. Yeah, yeah, yeah. That is. It is approached differently in different places as well. But there's some there's some universal truths around it as well. So those are those are usually things you can latch on to. Uh, what's the best piece of advice you can give practitioners struggling with first line buy-in?
SPEAKER_02Stop talking about what you need and start talking about what they need before an incident happens. The first line, you know, they are focused on growth, efficiency, getting things to the customers fast. We need to communicate in their language. So when people understand how risk management can protect protect revenue, customer reputation, all that, um, they become partners instead of reluctant partners.
SPEAKER_00Yeah, that's good. That's good. I had a boss years ago who said sometimes people speech fiber and third-party risk is in that boat too, as the department of no. He said, You should turn it into department of how. I'm not telling you no. I'm just telling you can't do it the way you're asking me to do it because it's against our policy or program, regulators, whatever it is that you're you're trying to use as the curbing to hit them.
SPEAKER_02I just heard an IT guy just said risk management went astray when the accountants and consultants got involved.
SPEAKER_00That's so true. All right, the last one's your more of a favorite one. What's your favorite pastime when you aren't connecting T per M professionals across the globe? What's your what's your outside activity that keeps you centered and grounded?
SPEAKER_02Uh spending time with my two adult children, writing, and I'm constantly putting puzzles together.
SPEAKER_00Very good. Nice.
Getting Real Business Unit Buy In
SPEAKER_00Well, all right. So we I think we know you a little bit better. We could always get you know you more, but we don't have time for that. So we'll we'll get into the actual hook questions, which is the first one is the hook question is the first line of engagement gap versus tool footage. Security tools can generate vendor scores instantly, but 79% of our organizations still lack visibility to nth party risk, and business unit leaders often view security questionnaires as a robot to closing deals. Speaking of, we talked about this earlier. How do you get business units owners the first time of defense to actually care about third-party threat hunting instead of treating it like a rubber stamp exercise? And you're going to kind of build, I think, off of what you said earlier is building that relationship, I'm guessing.
SPEAKER_02Yeah, you know, technology is a great thing, but we need the people that can provide the context. So I think uh we need to stop treating third-party risk management as a compliance exercise. Treat it as a business discipline. And a business discipline needs the people. The first line doesn't wake up in the morning thinking about inherent risk, like security questionnaires. They don't always think they're not always thinking about what the worst thing that could happen. They're thinking about revenues and customers and getting ahead, growth. So I think we need to really focus on the question's not can you complete the assessment? It's what happens if this vendor fails tomorrow. Keep it simple. Once the business owner starts to think in that vein, you've got them and you become an expert in and you can walk beside them in that real resiliency. So the threat hunting becomes more of a effective because the people closest to the vendor relationship are in partnership with you and you're all working as in in tandem with as a partnership.
SPEAKER_00I think what you're getting at is is it's it's not just about the technology and trying to find the gaps and all kind of stuff. It's partnering with your your your business unit to say, hey, I'm here to help you be more successful, get things like resiliency and and I you mentioned earlier too, is find out what their care abouts are because that may be your your hook to try and get them. Oh, you care about the fact that it's it's a really critical app. Well, how critical is it? Oh, it needs to be restored in four hours. Okay, well, right now that's not set up to do that, right? Whatever it is that you you need to have a conversation to get them to understand that there's a gap somewhere that that they need to address. And I think businesses are your best ally with the vendor often too, because they can usually get the vendor to listen where it's challenging sometimes for you, perhaps.
Translating Cyber Risk Into Revenue Impact
SPEAKER_00Okay. Uh big question number one is operational translation, breaking down styles between security and business units. Uh, there's a couple of questions embedded in this one, so we'll we'll take the first one first, obviously. You've described your approach, and and I've heard you describe your approach as operational risk management translator, which is a mouthful, but but makes sense. Uh how can threat hunters and CPRM teams communicate cyber communicate cyber vendor risk to business owners whose primary metrics are sales and speed.
SPEAKER_02Yeah, I like to say I translate technique technical findings into business outcomes using the language of the person that I'm speaking with. So if I'm talking to a CFO, instead of discussing vulnerabilities, which I might talk about with a cyber expert, I might talk about last revenue or operational disruption, customer impact, regulatory fine exposure. Business leaders understand when they understand the consequences, and you use their language.
SPEAKER_00So that translation um is um uh so you put put it put it in under know your audience, I think is what you're getting at, right, Andrew? Yeah, and don't know who you're talking to. How do you shift the culture from training the trainer to train their successors? So vendor risk management survives turnover and organizational shifts because that that that's something that we're always doing.
SPEAKER_02That's a that is a great question because too often we are trying to solve today's problems, but we're we really also need to be preparing for tomorrow challenges. So I believe we need to definitely move from train the trainer to train the successor because knowledge can't live in one person's head. And I always find myself in that predicament sometimes. Maybe the best example I can think of, just off the top of my head, as you're asking the question, is post-2020, I made a decision and told my friends and family that I was going to retire from banking in 2023. And so I knew I wanted to leave the organization stronger after I left, which is a motto I've always lived by. So I implemented what I call my uh depth of three strategy. And so for my third-party risk management and enterprise risk management roles, I went and found the key business stakeholders from the executive team, the executive successor, and the trust operational partner that was supporting them. And I intentionally involved all three in committees, advisory groups, training, decision making over that period leading up to my retirement so that I could display or hand off the knowledge, build the relationships, the accountability rather than just to one individual. So I think that's a great example of whether you're leading a third-party risk management program or other roles, it's critical that an organization never build a relationship that's only one person deep.
SPEAKER_00Yeah, yeah, yeah. I agree. That's great. I'll add on that your your your conversation triggered a lesson I learned from my dad years ago was always train your successor. Because if you if you don't, unless you want to keep that job for the rest of your life, you you need to train somebody to take over your role. Because if you're gonna go do something else within that firm, I'm assuming you're not moving onto a different firm, they're gonna want to know that that they've got somebody to replace you that is gonna be able to take over your your your shoes. So my dad always, my dad's that's the philosophy was train my trainer so that I can go on and do other things.
SPEAKER_02Right. If you never let go of what you do today, you can never never grow. And or yeah, exactly.
SPEAKER_00Yeah, yeah, yeah, yeah, yeah. I I I think some folks, uh you you and I have seen this in our professional lives. I I also have been doing this over 30 years. Uh, folks who who think that re- uh holding on to knowledge and retaining knowledge gives them job security, and it just doesn't, especially in AI today, because somebody will figure out an agent that'll grab all that stuff that you're doing if it's not that complex. Exactly. Okay, let me let me get to the last question
Mature Programs Leave Egos Outside
SPEAKER_00in this big question. Number one is with your perspective across hundreds of TPR member organizations, what sets apart a mature TPRM program that successfully partners with business teams with those that stay trapped in silos? What's the distinguishing characteristic?
SPEAKER_02Honestly, I think the biggest difference is mature organizations learn to leave egos at the door. Risk management's a team sport. I've seen organizations where technology teams wonder why compliance and finance are involved, and compliance wonders why technology has so much, such a strong voice in the process, but both sides were naive to the other's insights and values. So the truth is neither solve neither side can solve the problem. It's it's a team sport. And the most successful programs recognize everyone owns a piece of that puzzle.
SPEAKER_00That's great. Yeah, that's that's very that's very true. You can have somebody who's leading the charge, perhaps, right, in on second line, but but it needs uh it needs everybody uh every why do you always talk about cybersecurity risk domain? Well, one, because it's where I sit. But but two, it doesn't mean that the other risk domains aren't equally important and I don't want their voice to the table, it just be happens to be where I colloquially will sit.
SPEAKER_02Right. What I love about TPRA is we're the whole life cycle, we are all risk vectors pulling everyone together. Um and that and then even the uh Institutes, uh IIA's uh lines of defense, that that plays into this.
SPEAKER_00So it does, yeah. Yeah, you're right. All right, big question number two is on community insights, solving fourth party and AI visibility crisis. And TPRA's
Shadow AI And Fourth Party Visibility
SPEAKER_00industry analysis, nth party visibility, AI governance are highlighted as two of the biggest operational hurdles. What are practitioners on the ground actually doing beyond static questionnaires to track shadow AI and critical fourth party dependencies? And let me let me explain for folks who are understanding why the fourth party dependency is used, because almost all the AI tools are delivered through fourth party, right? I mean, when you're buying software from a company that says it's it got AI tools in it, 99% of the time they're not creating the LM models. They're buying they're buying tokens from Anthropic or one of the other big, big, big players, right? So that's why the shadow AI and the critical fourth party dependencies are becoming more and more critical. I've teed it up for you, Heather Shark.
SPEAKER_02Yeah, there you go. Well, I think the leading organizations are they're combining multiple approaches. They're focusing on using the continuous monitoring, mapping the critical business services, identifying the concentration risk, um, reviewing contractual obligations, and you know, they're asking much more direct questions about AI usage and fourth-party dependencies than ever before. But with that said, I think some orgs are specifically doing AI assessments while others are embedding it within the larger inherent risk uh assessment. Either way, TPRA has re-free resources that teams can leverage in their discussions. But I think they do need to get beyond the discussing the pain points and just get busy.
SPEAKER_00Yeah. Yeah, that there was a quote I heard the other day was we we can we stop discussing whether AI is good or bad. It's here. Just get over it and figure out how you're gonna manage the risk of around it. You're not gonna be able to stop it. You're gonna be the guy with the dike finger in the dike because then the holes are everywhere. He's gonna watch for like little leaks. All right, so when lean teams managing thousands of inner touch points, uh with sorry, with lean teams, most CPR teams are are not not overly, overly staffed. Staff abundance is not an issue. Where should risk practitioners draw the line between automated continuous monitoring and hands-on relationship improvement due diligence? What's where's that where do you think that line should be for folks?
SPEAKER_02Yeah, what I tell people right now, my simple rule is automate repetitive tasks and elevate human judgment. Um, technology is excellent at processing the large amount of data, but context, trust, and critical thinking still belongs to people.
SPEAKER_01I think.
SPEAKER_00Obviously, experienced and working with with some of the service providers, they are great at helping you get through some of the fluff, but you still need a human to make a decision about what is this does this meet my risk threshold? Do I do I need to make an action on this one or is it not does it not meet that threshold? Yeah, exactly. How can peer uh how can peer uh how can peer collaboration industry associations like TPRA accelerate threat intelligence sharing on vendor incidents before they become headline breaches?
Why Peer Communities Share Faster
SPEAKER_02Well, you know, threat actors collaborate extremely well. So us as defenders have to do the same. So communities such as TPRA create opportunities for practitioners to exchange ideas, share pain points, identify emergency emerging trends, discuss lessons learned, and just help one another become more resilient. TPRA can expose you a lot of technology providers in the space, both established and these start incubator startup organizations. And I think if you're only looking at the vendor you use today, you're doing yourself a disservice. And so TPRA, we do a quarterly demo day where we try to expose the industry to existing and new uh technology.
SPEAKER_00Yeah, I'd I'd recommend it as the as a as a as a person in this space. Uh, you know, I uh when I first started programs years ago, there was only three or four big vendors in this space. And now there's literally uh, you know, a smorgasbord of choices. And I think that's great for the practitioner because it gives you different price points. A lot of the incubator and startups are hungry for your business and and pricing become can become uh much more uh less challenging than some of the bigger players where the pricing can be a little challenging for some smaller, a smaller company to really afford to approach some of these tools. So I like that the choices give a choice not just on on what the tools do, but pricing and how the the how the models are deployed. I do like also that a lot of the folks are deploying customer service success models so that they have partners that don't just drop the software off and say, okay, good luck. You know, that that's really important. I see a lot of these organizations invested in their customer success, which I think is really important as well.
SPEAKER_02Well, and TPRA is invested in a lot of their success. We even have a startup advisory group for where we we pair key practitioners across multiple industries with startup companies. Oh, that's great. To solve their pain points and to advise them on, no, here's the real problem that needs to get fixed.
SPEAKER_00Yeah, yeah, yeah. That's great. Do you want to uh share anything else about uh TPRA?
TPRA Resources Events And Next Steps
SPEAKER_00I don't have any other questions set. Um do you have anything else that you want to uh sort of get off your chest that you think that the in the the the the uh community needs to know more about that do you think they don't well they need to know about TPRA, they need to become a member, obviously.
SPEAKER_02Absolutely. Yeah, there are very few barriers to get involved. We have um activities that you can get involved with, whether you are a you have all the time in the world to volunteer. Membership for practitioners is free. I do have some upcoming events. On September 9th will be the demo day. September 23rd, we'll have a consultant showcase. October 14th and 15th, we will be in Fort Worth, Texas for an in-person conference. Then TPRA is running to Orlando to be at the GRF summit, and then we'll end the year in London, November 10th and 11th, for our uh in-person conference in the UK.
SPEAKER_00And that's the one with CephPro, right?
SPEAKER_02Yes.
SPEAKER_00Yeah, yeah. And the same one in, I think in the one in Texas too, is also in the Ceph Pro collab as well, right? So uh I I would I'll concur uh obviously with with Heather on joining TPRA. I've I've been with TPRA since almost inception. When uh I first approached Julie years ago with the the book, the first book, get this one, this one right here. She said, Hey, it reads a lot like a textbook. Have you ever thought about creating a pro uh a a course around it? And that's what development of the third party cyber risk assessor certification. I I would add make sure that you check out all the training resources that TPR has, not just mine, but there's other other training resources there as well. There's the uh the third-party, what's the practitioner one called?
SPEAKER_02It's a third-party third-party risk management practitioners.
SPEAKER_00Yeah, yeah, yeah, yeah. That one is is a little bit newer, but also well well received, and it covers all the risk domains, not just cyber like the third party cyber risk assessment. And then there's uh there's two trainings on the certificate program on AI, one by Clarence and another by I forget the name of the company. They prompt armor. Oh, yeah, prompt armor. Okay, no problem. And then um, and then there's my training on test tree. And then actually, I'll have AI training available here soon as well. So for those who are tuning in, uh check that out. It'll be four hours. It's called AI, AI, AI training for AI for TPRM professionals. TPRM professionals, sorry. And um, it's four hours, it's a certificate-based course with the others, and I hope to see you on that one. Heather, um, what is the one practical action item a TPRM or security leader can implement tomorrow morning to get a closer uh closer to their first line business partners and improve vendor risk visibility? We'll wrap this one up.
SPEAKER_02Well, that's so tough to pick just one.
SPEAKER_00Yeah. Yeah. Maybe do it in order. What's your what's your do one, two, three? I'll give you, I'll give you an out.
SPEAKER_02Maybe tomorrow, schedule a 30-minute conversation with one of your business partners and ask them three simple questions. What vendor matters most to you? What would happen if one of them failed? And how can we work together to reduce that risk? That's a practical one. Third-party risk management has evolved beyond the traditional vendor management. Today, we're so interconnected with third parties, fourth parties, AI, but relationships and communication and that collaboration always remain the center of successful programs. So, probably my advice would be to learn and evolve. And full disclosure, all these answers I've given you today are based on my experience I've had so far. So ask me the same questions from a year from now, and I might have a better answer because technology changes, relationships change, threats change, but curiosity, humility, strong relationship, that just never goes out of style. So maybe I would leave you with one final thought. And my dad used to say, we know what we know until we're willing to learn something new in each and every interaction. So I think that's especially true in risk management and relationship.
SPEAKER_00Well, good. That is great. Uh my my uh threat's outtake would be make sure that you join TPRA. Like she said, like Heather said, it's it is free. So the price points are not painful. And uh look at look to do the conferences, in-person conferences uh are are amazing. Uh, she talked about the ones here at the beginning, at the towards the end of the year. There they have the annual one, which I think this year is in Florida, um, and and it's always in April. But you can check out the website, check out uh third party riskassociation.org and and and check out. There's also lots of resources there. So I again I yeah, I I teach classes and sometimes somebody say, Well, I need I don't go a lot into the contracts because I'm gonna train. I do some of it, but I don't I'm not a lawyer, so obviously I don't go to hey, I need help how to write a uh a contract. Go to the TPR website. They have stuff on how to write a contract so that you can protect yourself with vendor risk. So that kind of stuff is there. If it's not there, leave a message and say, I need help with it. And they, if it's not, if it doesn't exist, they'll they'll work to try and find it. I that's been my experience with with Heather and be up on LinkedIn and I will find it for you. Yeah, exactly. So and make take advantage of the demo days. Those are a great way for you to really take the tires and get a first-hand view of what the other products are out there, even if you don't avail of them, at least you can start to see what capabilities some other tools have. And if you want to stick with your existing vendor, ask them, hey, I saw this tool does this. Why don't you do that? I mean, those are the kind of conversations you should be having with your server providers, right? I like this thing, and I'd like to see it on your tool too. So if that's great. Thanks for joining us. Uh, that's gonna wrap our session today. Thanks for joining us on Third Party Threateners Podcast. And Heather, thank you for being a guest. I really appreciate it. It's been a great conversation. We talked quite a bit during the during during the weeks. Heather and I are are uh colleagues too, and trying to find folks who are between roles, the practitioners in the space who are between roles. So if you're between roles or you're looking for somebody also, reach out to Heather or me. You know, there's there's the web the website on TPR also has listings for for open roles and stuff. So I know there's folks in the space who are looking for roles. So be sure to check that out and keep keep uh uh subscribing and looking for more uh hints from Third Party Threat Hunters podcasts. Thank you very much.
SPEAKER_02Thank you.