Third Party Threat Hunters

The Vendor Trust Gap with Bill Haber

• Gregory Rasner • Season 2 • Episode 10

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 26:50

Send us Fan Mail

Your vendors are not “outside” your business anymore. When an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access. We talk with Bill Haber, co-founder and CEO of Tekrisq, about how to build third-party risk management that earns real trust instead of producing paper compliance that looks good until it fails.

We get blunt about security questionnaires: why flat, self-attested checklists create an attestation gap, why yes-no scoring collapses nuance, and how branching, point-and-click assessments can surface clearer risk signals using language vendors actually understand. We also dig into what business leaders and TPRM teams should ask for when evaluating service providers, including architecture choices, back-end tooling exposure, incident readiness, and the financial risk dimension like coverage limits and breach preparedness.

Then we move into the messiest frontier: AI in the supply chain. We break down how AI agents increase speed and blast radius, why shadow AI is spreading across organizations, and how fourth-party risk grows when your vendor’s “AI features” depend on external LLM providers and shared cloud platforms. We close with a practical action item: what continuous monitoring should mean in 2026, with EDR, logging, and vulnerability management that goes beyond point-in-time scans.

If you want a vendor risk program that’s defensible, collaborative, and built for modern supply chain security, subscribe, share this with a teammate, and leave a review with the toughest vendor question you think everyone should be asking.

Support the show