Third Party Threat Hunters

Vendor Risk Beyond The SOC Report with Becky Newton

Gregory Rasner Season 2 Episode 8

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 24:28

Send us Fan Mail

A vendor hands you a clean SOC 2 Type II report, the boxes look checked, and everyone relaxes. Then the breach happens anyway. That’s the control assurance paradox, and it’s why we sat down with Becky Newton, founder and managing partner of Newton Risk Intelligence, to get brutally practical about what third-party risk management should look like when the goal is real operational security, not paperwork comfort.

We unpack why TPRM is neither “just audit” nor “just security,” but a risk management discipline that translates vendor controls into business exposure and informed decisions. Becky explains a surprisingly common miss in SOC and ISO reviews: CUECs (complementary user entity controls). If we aren’t performing our side of the controls like access removal and internal mapping, vendors can’t truly assure outcomes, no matter how polished the report looks. We also talk about the biggest vendor red flag: inconsistency without transparency, and how to spot it across questionnaires, evidence, and documentation.

From there, we move into what actually closes the gap: understanding the service, the data, the access, and the vendor’s criticality, then backing it up with continuous conversations and operational testing. We dig into business continuity, disaster recovery, and incident response table-tops with vendors, plus how to prioritize limited resources across tiered vendor populations. Finally, we tackle AI vendor risk and AI governance, including why you should audit the system the model runs in, focus on permissions, and ask your top critical vendors what changed with AI bolt-ons and expansion.

If you want a vendor risk assessment approach that executives understand and attackers don’t laugh at, hit play, then subscribe, share, and leave a review so more teams can build stronger third-party risk programs.

Support the show