Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Short: The most dangerous assumption in third-party risk with Michael Rasmussen
•
Gregory Rasner
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Michael Rasmussen explains why the biggest mistake in third-party risk is assuming you already know who your suppliers are and what risk they bring. Rather than focusing only on contract size or spend, he argues for measuring value at risk, because small vendors can create outsized operational or security impact.
Key topics
Michael Rasmussen says the most dangerous assumption is that an organization already knows its third parties and the risk they bring.
- He describes how his supplier third-party risk workshop has focused on a key question: how do you measure value at risk?
- He challenges the common practice of using contract size or spend as the main proxy for risk.
- He gives a practical example: a small supplier that delivers a critical widget may not cost much, but if it fails, manufacturing stops.
- He points to the Target breach as a reminder that a non-obvious vendor can become the doorway into a major incident.
- He notes that an HVAC vendor helped open the path to one of the largest credit card breaches in history.
- He emphasizes that identifying who your vendors are and what risk they bring is not simple