Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Vendor Risk Beyond The SOC Report with Becky Newton
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
A vendor hands you a clean SOC 2 Type II report, the boxes look checked, and everyone relaxes. Then the breach happens anyway. That’s the control assurance paradox, and it’s why we sat down with Becky Newton, founder and managing partner of Newton Risk Intelligence, to get brutally practical about what third-party risk management should look like when the goal is real operational security, not paperwork comfort.
We unpack why TPRM is neither “just audit” nor “just security,” but a risk management discipline that translates vendor controls into business exposure and informed decisions. Becky explains a surprisingly common miss in SOC and ISO reviews: CUECs (complementary user entity controls). If we aren’t performing our side of the controls like access removal and internal mapping, vendors can’t truly assure outcomes, no matter how polished the report looks. We also talk about the biggest vendor red flag: inconsistency without transparency, and how to spot it across questionnaires, evidence, and documentation.
From there, we move into what actually closes the gap: understanding the service, the data, the access, and the vendor’s criticality, then backing it up with continuous conversations and operational testing. We dig into business continuity, disaster recovery, and incident response table-tops with vendors, plus how to prioritize limited resources across tiered vendor populations. Finally, we tackle AI vendor risk and AI governance, including why you should audit the system the model runs in, focus on permissions, and ask your top critical vendors what changed with AI bolt-ons and expansion.
If you want a vendor risk assessment approach that executives understand and attackers don’t laugh at, hit play, then subscribe, share, and leave a review so more teams can build stronger third-party risk programs.
Welcome And Guest Background
SPEAKER_00Hello, welcome to Third Party Threat High Podcast. My special guest today is Becky. And Becky is a friend of mine that I've only met at a couple of PPRA events as well, and I've been in some sessions with her online as well for a workshop. So Becky, why don't you introduce yourself and we'll get started.
SPEAKER_01Becky Newton. I'm the um founder and managing partner of Newton Risk Intelligence. I've spent over 20 years in risk governance and compliance, spanning from financial services all the way to global technology companies, including AI startups. Most recently, I led a global third-party risk management functional for a technology company where we focused on aligning the business risk to the vendor risk. And that was pretty successful today. I'd help organizations do AI governance, implement AI governance, and just the overall enterprise risk management. My philosophy as it relates to risk management is as risk practitioners, we're here as advisors. We're supposed to help the business understand that risk and its impact so that they can make informed decisions.
What Third-Party Risk Really Is
SPEAKER_01Great.
SPEAKER_00Thanks, Becky. So uh the first question is audit versus fair happening. Is third-party risk management fundamentally an audit discipline or an operational security discipline?
SPEAKER_01So I think it's neither by themselves. I think it's a risk management discipline, right? It gives a business a measure of what that third party or vendor or partner, however you frame it, what that measure of risk is to the company. I think audit tells us the activities around the controls. Are they in place? Are they operating effectively? And then operational security really focuses on today. Is it set up? Can we deter, can we identify and will we know if things have changed? Third-party risk management, I think, sits between those and frankly, between all of the risk pillars. Privacy is another one, where we bring those together and say, okay, here's what your profile looks like. Do you still want to make that decision or not?
The Overlooked Power Of CUECs
SPEAKER_00So what do you think is the most misunderstood control in a traditional Stock 2 ISO assessments when evaluating critical vendors?
SPEAKER_01So I think it's those user entity controls, C U E Cs we call them. A lot of people think those are fine print. And really, those are the components that we in our companies need to make sure we're performing. If we're not removing access appropriately from that vendor's profile, they can't confirm and they can't assure us that risk is covered. So it's important for us to do that. It's important, I think, at the company to map those. Make sure you, as a vendor manager, whether you're in security or in a risk function, you need to make sure you know what your company's controls are and if they're working effectively. Because that makes those soft reports more advantageous to you.
SPEAKER_00That makes sense.
Start With Service And Data Access
SPEAKER_00Spread free questionnaires or continuous monitoring scoring tools. Where do you lean first when evaluating an IRS render? Do you do spread free questionnaires or continuous scoring tools?
SPEAKER_01Neither. So I really believe in understanding the service. I think you have to understand what the service is, what the business is needing that service for, and what data that vendor is getting, and what level of access. Those are important things. And then that final one is how important is it to us? To me, that determines do we send a questionnaire? Do we do a deeper dive evidence-based assessment? And I think the most important thing is knowing who your critical vendors are and knowing what data they have and what authorities they have in your environment. Nothing else really substitutes that other than good judgment on your part. And I think however you attack it, those are the important things you make sure you know up front.
SPEAKER_00I'm gonna make sure that your program articulates that approach, right? That's anything you should do. What's the single
Red Flags And Vendor Transparency
SPEAKER_00biggest red flag you look for during a third-party risk for audit assessment?
SPEAKER_01So I think the big takeaway is it is the inconsistency without transparency from the vendor. So if they're telling you one thing and your documentation that they that they provide to you is inconsistent with that, whether you're using an AI to do that for you or yourself, or it's a questionnaire, or it's evidence, it's a stock report. Those inconsistencies, I think, are the important red flag. And that tells you, hey, we need to go back and look a little further. No company exists without flaws. So you should know that going in. They're gonna have control issues and situations. But if they don't understand their own control environment, that's the biggest risk for you, for any any company, really.
SPEAKER_00Yeah, that makes sense to me. If if if there's not a good understanding of how deep deep their pole is, they really don't really know what they're doing.
unknownRight.
SPEAKER_00What's your favorite way to disconnect when you're not analyzing controls, frameworks, and risk registers?
SPEAKER_01So uh my husband and I are big uh hiking Colorado 14ers. So the mountains that are 14,000 plus, but under 15, right? So I still need to be making um oxygen decisions when I'm up there. But if we're not doing that, we do that with our friends. We love love hiking. If we're not doing that, I'm probably searching out the next food fighter concert. I'm the old lady in the uh in the grunge outfits. If you're at a concert, that's me.
SPEAKER_00That's good. Yeah, I like that outdoorsy. All right, so let's get into the hook. The hook
Clean SOC Reports Versus Reality
SPEAKER_00is just our our first five-minute quick conversation. So let's talk about the control assurance paradox, which is clean stock reports versus operational reality. So the key scenario here is that an estimated 45% plus the breaches or security breaches originate through third front demanders who pass their annual audit or provide clean stock to type two reports. So prospect prizes are compliant, but you still got breached. How do risk leaders bridge the gap between compliance assurance, which is really passage and audit, and actual operational defenses to 15 active third-party threat activity because they are two different distinct outcomes?
SPEAKER_01Yeah, I agree. I think that the magnitude of that number really reinforces the concern, right? Um it's that zero threat preparation. You need to understand your own control environment and your own weaknesses so that you can then pair those with that vendor. The clean sock report, and it also goes with the ISO reports, right? Because they're similar, different but similar. They're a test of controls, either at a point in time or over a period of time. They're not what happened today or what's going to happen tomorrow. Operational resiliency and security gets a view of that, but again, it's still a snapshot. So I think where that gap lies is we need to be, it's relationship building. I think you have to have those continuous conversations with your vendor. It's not enough, I believe, to get the stock report and think, okay, we're done. That's that's definitely not the thing. That's a that's an informed piece of evidence that you use that you pair with your controls to see where your gaps are and fill those holes where you can. I think the scanning and all of those operational security activities give you a good today, it's X. But I think it's that continuous conversation, continuous monitoring, continuous ongoing assessments where you make that gap shrink. Understanding the service, understanding where your gaps are. Because again, we all know this. The the threat actors, the second we figure out their play, they've changed the play. So really you've got to have that open communication. And you need to test those plans. You need to test that escalation. Do I know who I'm supposed to call? Do they know I'm calling them? Those are important aspects of bridging those gaps from my perspective.
SPEAKER_00Yeah, that makes sense. All right.
From Checklists To Active Monitoring
SPEAKER_00Big question number one operation audit insights for threat hunting. That's a mouthful, I know, but let's talk about we got a couple questions around this. How can TPRM teams move beyond CISA, C-risk audit frameworks to static check a static checklist, and instead use control testing to drive active threat hunting, assess assessing so I think you know I hate static questionnaires.
SPEAKER_01I think they were valuable when we first started third-party risk management as a practice. It was what we knew. It's not sufficient in any way today. You need that, uh I think you need to understand audit principles and you need to understand controls and risks. And that pairs, I think, very well with the threat hunting piece of that. Um the big, big function for me is understanding the service, understanding the service, understanding where those gaps exist and continuing to monitor that and and um having the conversations where it's really appropriate. It can't be a a Ron Popeel, set it and forget it. Ongoing monitoring can't be, hey, we're gonna send the questionnaire again. It needs to be, hey, we looked and here's some things we saw. Can you help us understand what changed? It has to be an active participation process. And I think that's where we move beyond static and into really talking about those controls. We don't own the controls at the vendor, so it's hard to test them, but the more you get to know that vendor, the better the relationship develops, the more opportunity you have to see those results, and they'll share them more readily with you so that you can prepare.
SPEAKER_00You make some great points, and and and um it's fair broken record if it the fundamentals are the fundamentals, but sometimes they bear repeating one of the class for API say the word risk-based so many times I make a bit of a drinking game with the students. So
Proving Controls With Resiliency Tests
SPEAKER_00when auditing complex vendor environments, how do you verify that vendor security controls actually functional for screw through versus nearly existing on paper?
SPEAKER_01That's a really, really thoughtful question. Um I think we lose sight sometimes in TPRM about business continuity sexual recovery. Again, foundational functional activities. And it's that guy in the closet that we talk to once in a while, right? It really should be an active, again, an active participation with those folks. So I think you talk to um your BCT guys and you partner with them as it relates to that vendor. The more you develop that relationship, the more active they are in helping you do if it's just a table talk in the beginning. Hey, let's walk through what our contract says you're gonna do for us and who we're supposed to contact. Did it work out? Are they uh figuring out who to call when you pretend something went wrong? Okay, that's not ideal, but now you know, and now you guys together can fix it. And and to be fair, I've been on those calls and it's us trying to figure out, oh crap, it's not me they're calling. It's the VP of privacy. Okay, why are they being called when we have a security breach, right? Yeah, so it helps on both sides, and it's a win-win for everyone. And it's a reportable to your executives part, right? That's a huge advantage for reporting.
SPEAKER_00I tell people you you you you should be looking to partner with your your third parties to do things like BCP testing. Your BCP folks probably want to see their tests anyway, so hey, partner with them. And then we would always try, and when we would do incident the incident response testing every year, we would try and find a vendor that was going to get that would agree with us to pretend that they got breached and we were both affected. If you go to the vendor and say, hey, you're a really important vendor to us, that's the first thing you say, because they love that. And then you say, we really want to understand how if things you know go sideways for for either one of us, that we can still operate and make make our customers happy. Most most vendors will try and find a way to collaborate with you on those things because they want they want to be collaborative. They want more business.
SPEAKER_01Yeah. At the bank, when I was at the at uh a bank, I was responsible among a lot of things, business continuity. And we loved the opportunity to talk about our business continuity, to talk to our our partners, the people we were vendors to, about what we were doing and how great a job we were. So it's it's like everything else. Everyone loves to talk about what they do, give them the platform to do it.
SPEAKER_00Yeah. If you use the keywords like resiliency and regulators, you usually get people's attention too. I agree with you totally. So
Tier Vendors And Spend Effort Wisely
SPEAKER_00the last one on this big question one is how much could risk leaders prioritize limited audit resources across tiered vendor populations? Yeah, the the tier one mission critical versus the low-tier shadow IT kind of stuff.
SPEAKER_01So we um I think priority is important. A one size fits all does not fit anyone, frankly. And you have to understand your personal business. That's an important thing. You would think that everyone who works for a company understands their business, but surprisingly, most of us don't. We just sort of know what we do. So I think it's important to start there. Know what your business is, and then you know what's important to you. And you know what vendors are important to you. Um, and as a new vendor comes on, you measure them. Are they more important than the top one? Are they less? The more they are, the mission critical, the more in-depth the work is. The less important they are, the less in depth the work is. We have to be smart. We're an expense, whether we like to hear it or not. We don't bring money into the company. Risk management, cybersecurity, we're not bringing money to the bottom line. We're an expense, so we need to make sure our expense is worth it. And we leverage those resources most effectively, which is do the most work for the most risk. Do the least work for the least risk. The piece that was hard for my teams when we were really digging into that was letting go. Like, was it really that important? And what's our history with this vendor? We've had this vendor for 20 years at the bank. We had vendors that we'd used for 30 years. Nothing's happened. Let's quit treating them like they're a brand new startup. And I think that that openness and honesty with yourself and your executives goes a long way.
SPEAKER_00Okay.
Auditing AI Systems And Permissions
SPEAKER_00So as vendors integrate autonomous AI and third-party API dependencies, uh, traditional control frameworks are really struggling to keep up. How do you audit and assess risk for vendor tools leveraging nested AI models?
SPEAKER_01So that's I don't think there's a magic bullet for this. I really don't. I think we're all learning as the systems change and the modeling changes, right? We now have the frontier, the open versus the closed. There's all these buzzwords. The the key thing is don't audit the model. Audit the system that the model is working within. Now you can't lose sight of how is it trained? All the basic things that we know. How is it trained? What data is it open? Is it closed? Right? What access does it have? That's a really important piece. What access does this AI have in our system? What's it supposed to do in our system? But I think equally important is what is it not supposed to do? We know the big stories right now of the breaches, the quote unquote rogue. Well, if you dig into that, like I'm sure everyone has, they weren't rogue. They were given inappropriate access to the internet. Those are important pieces that I think.
SPEAKER_00It was a sandbox. It wasn't really a sandbox, but there's a couple of other just the silly lily. You gave it access to the internet and said go you and said do bad things. So it went and did bad things. Another guy trained his agent to um make reservations for him at the gym. So it went and I realized that there was a waiting list for the class, so it canceled another member's another member's class so he could he could he could get a spot, which I actually thought was great.
SPEAKER_01I love that.
SPEAKER_00But again, it's it's a shame. The agents want to make the the person happy. They want to accomplish the task. And even if it's badly done, right?
SPEAKER_01I I really, really use this analogy with my family a lot. It's a very smart two-year-old. It's what it is. It's learning to talk, it's learning to lie, because it does.
SPEAKER_00Very smart two-year-old. That's a good thing. I'm gonna I'm gonna steal that.
SPEAKER_01But I think the important piece is understanding again, uh broken record, understand what its purpose is, what its purpose is not.
unknownOkay.
SPEAKER_01And when I say authority, I also include in that authority proposition, I'm including what access to data, what is that data? Those are the things you need to know. And then from there, it's sort of a natural table stakes for risk management. Should they have access? How do we, how do we know if it's inappropriate, blah, blah, blah. Right? It's all of those things. I think we've got to stop treating it as something that it's not. It's not this magic black box that's smarter than us. It's code that makes decisions based on the information that's provided.
SPEAKER_00It's it's math and it's math and data at scale.
SPEAKER_01Yes.
SPEAKER_00Yeah. It's based on the algorithms. It's the way it does seem fancy and it is a black box because I don't really sometimes understand how it gets the answer it gave me, but but yeah, you're right. It is it is nothing more than code.
unknownYeah.
SPEAKER_00And how do we treat code? How do we treat code developers? There's software development lifecycles, there's an AI development lifecycle too. But yes, yes.
SPEAKER_01It's crazy to me, but I've heard it so much in the different companies. We've lost sight of basic code development framework. Everyone's rushing because it's this new thing. It's the new train track. Okay, great, but we still have to put it on rails. We still have to clear the land.
SPEAKER_00So you're right.
Reporting Risk To Leaders With So What
SPEAKER_00So uh let's talk about then uh how can risk leaders effectively present third-party risk exposure and audit findings to see and a C-suite and board in clear business language. Because again, I think there is definitely a knowledge difference between some of those levels I've seen as well as what their goals are. And I think that's where my biggest trip up is I generally see is folks not understanding what they're trying to communicate or what the leader wants to know. So I'm interested to hear how you, what your take on that side, Becky is.
SPEAKER_01Yeah, yeah, I agree. I think I, especially young in my career, I wanted to tell them all the things I knew, and they just didn't care. And and as I learned and matured in in the process, really what I think is important when you're communicating things is is exactly what you said. You need to understand what they need. And if you have to ask it, that's okay. In fact, that shows you're you're preparing and you're thoughtful in what you're gonna present to your boss or your or the executives. But what I try to talk to my teams about is it's about the so what. We we didn't win the game, so what? What does that mean? We don't get to go to the playoffs, or we have another game because the so what? They didn't have MFA set up and they have access to our deepest secrets. Again, an executive doesn't care because they're not thinking in those terms, they're not thinking in the action level that we're at. They're thinking about how does that impact the bottom line? How does that impact my risk preference or my risk tolerance or exposure? It's really about exposure, let's be honest. Everyone cares about the exposure they or the company are under. So think about what happened when you're communicating third-party risk. Think about what happened, what matters, and why. It's the so what. If you keep it to those very structured things, they will love you.
SPEAKER_00I like the statement you make about asking because I've I've always given the same direction that there's no harm in asking. In fact, you you don't try and channel what you think the exact ones, because it's probably wrong. You're you're hugely wrong. And if you can't get to this the person, if they're high enough up, they usually have a chief of staff or somebody, uh, an EA, somebody that that can say, hey, I'm getting ready to present to this person or this this group, and I need to know what they care about. If all else fails, come with some mock-ups and see which one sticks to the wall better than the others, or spaghetti. But be prepared that you're gonna you may go down rat holes, because that that that's the challenge if you don't if you don't have a pregame warm-up, as it were, right? Then you know what you're gonna be playing the game for. That's great, I really like that. Let's give everybody the after-action report. We're getting up on time.
Tomorrow’s Quick Win For TPRM
SPEAKER_00What is the one immediate control check or audit action of risk practitioners reform tomorrow, uh Wednesday, um, as it were, to strengthen their TPRM framework?
SPEAKER_01I think I think probably the quickest hit for tomorrow would be look at your inventory, pull out the top 20 critical vendors. And this this holds true whether you're doing continuous ongoing monitoring or not, regardless of your industry, it's best practice and it's generally regulated in most industries in some capacity. But assuming you are or you're not, go to those those, let's say top 20 critical vendors and and ask them has anything changed as it relates to AI expansion, bolt-on, whatever. It's a win-win for you for a couple of reasons. AI is a big topic right now, it gives you insight into potential blind spots you've had. It's not uh on purpose that vendors don't communicate or business units don't communicate to you. It's it's just they're doing business. So don't wait for them. Be action, be an action change for one person. Go ask the question tomorrow. Go ask them, get that back, and then you have a couple of options here. You get to say to your executives, hey, AI is changing rapidly. We looked at our critical vendors, we found no changes. However, we're gonna continue this through our portfolio and as part of our continuous or ongoing monitoring. Or you can say, hey, blah, blah, blah, AI is changing. We found some areas where it had expanded without communication. Here's what we're doing to address that. Here's the impact.
SPEAKER_00By the way, I think you're gonna use, you know, you're gonna get more of path two than path one.
SPEAKER_01So too.
unknownRight.
SPEAKER_00I think so too. But but if you get lucky enough to get path one, let me know that you'll be few and far between. What was occurring to me as you're saying it one is I think it's a great idea. Go out and just pick your top 10, top 20, whatever the number that you think you can consume, and figure out what's changed, because something probably has changed. And and get ready to make adjustments based upon that. And what also hit me was I think the seventh or eighth interview I've done now on this season, and I asked pretty much the same question, and always get a different answer, but all the answers are really good. So, what
Closing Takeaway And Subscribe
SPEAKER_00I what I would encourage listeners to do is continue to listen because if you listen to this and I drop this every Tuesday, every Wednesday you've got some good idea you can go back to your desk with and figure out something else to kind of tackle the week with. But yeah, great idea, Becky. So thanks for being a guest on the on the show. You've given us some great insight, uh, especially with your your background and your practice. It's really uh great that you could share. Any last thoughts you want to share with the the audience before we go?
SPEAKER_01My big takeaway would be information creates awareness, judgment creates confidence, and good reporting gives leaders both of those. Be that person that provides that good information.
SPEAKER_00That's great. Thanks. That's great. Thank you very much, thank you very much, Pequit. Thanks for watching this episode of the Third Party Threaters Podcast. Tune in for other episodes and also subscribe, please.