Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Short: Map your critical dependencies before it's too late
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Michael Rasmussen shares a practical way to begin third-party and dependency risk work without getting lost in an enterprise-wide transformation. The focus is on one business-critical service, the people who know it best, and a small set of questions that reveal where resilience and risk really live.
In this short segment, he outlines a simple, actionable approach for identifying dependencies across vendors, cloud platforms, AI systems, data sources, and subcontractors. The goal is to understand what matters most, what could fail, and what to do next if a dependency becomes unreliable.
Key topics
- Start with one critical business service instead of trying to map the entire enterprise at once.
- Choose a service that directly affects customers, operations, revenue, or regulatory obligations.
- Bring the right stakeholders into the room, including the business owner, security, risk, technology, and procurement.
- Identify every dependency behind that service, including third parties, cloud platforms, AI systems, data sources, and subcontractors.
- Ask what information and access each dependency has.
- Examine what could fail, be compromised, or behave unexpectedly.
- Define the intelligence signals that would tell you the risk is changing.
- Decide in advance what action to take if a dependency becomes unavailable or untrustworthy.
- Use the dependency map as a focused starting point rather than a massive transformation program.