Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
The Vendor Trust Gap with Bill Haber
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your vendors are not “outside” your business anymore. When an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access. We talk with Bill Haber, co-founder and CEO of Tekrisq, about how to build third-party risk management that earns real trust instead of producing paper compliance that looks good until it fails.
We get blunt about security questionnaires: why flat, self-attested checklists create an attestation gap, why yes-no scoring collapses nuance, and how branching, point-and-click assessments can surface clearer risk signals using language vendors actually understand. We also dig into what business leaders and TPRM teams should ask for when evaluating service providers, including architecture choices, back-end tooling exposure, incident readiness, and the financial risk dimension like coverage limits and breach preparedness.
Then we move into the messiest frontier: AI in the supply chain. We break down how AI agents increase speed and blast radius, why shadow AI is spreading across organizations, and how fourth-party risk grows when your vendor’s “AI features” depend on external LLM providers and shared cloud platforms. We close with a practical action item: what continuous monitoring should mean in 2026, with EDR, logging, and vulnerability management that goes beyond point-in-time scans.
If you want a vendor risk program that’s defensible, collaborative, and built for modern supply chain security, subscribe, share this with a teammate, and leave a review with the toughest vendor question you think everyone should be asking.
Welcome And Guest Introduction
SPEAKER_01Interrupt my fan. Hello, and welcome to another edition of Third Party Threateners Podcast. Today I have Bill Harbour with me. He is a guest. I'll let Bill do the introductions like I normally do.
SPEAKER_00Thanks, Greg. Hey, uh appreciate the opportunity to uh to speak today. So yeah, I'm Bill Haber. I'm the co-founder and CEO of Tech Risk. We're based in Charleston, South Carolina. Uh my co-founder Dean's down in uh outside of Jacksonville in Ponte Vibra, Florida. And we help uh organizations with third-party risk management, uh, both preparing for that process, um, surviving that process, streamlining that process. So we work with um both business clients as well as risk managers. And we're particularly interested in focusing on the small and medium-sized businesses who are kind of pre-stock to and sometimes get left behind. We think um, you know, especially with some of the modern issues with uh paper compliance and all, that it's important to um collaborate with all of your vendors and give them the opportunity to mature their process as they go through a third-party risk program and help some of those folks who might not spend a fortune on SOC2 audits and things, but put the right resilience in place and demonstrate responsible stewardship for data and network access. So that's really what we're focused on.
SPEAKER_01Thanks, Bill, for the background.
The MSP Myth And Framework Focus
SPEAKER_01That's much better than I would have ever done. Um let me ask you five quick questions because we get to know the guest better. Um, what is the one organizational, uh major organizational myth around MSPs and outsourcing security?
SPEAKER_00I think that um, you know, that they are uh uh a collection of experts with every single framework and have the credentials in each one of those frameworks for you to pick and choose from. Um I think in reality, at least as it concerns us, we're laser focused on specific ones and specific outcomes that our clients have in mind. You know, we want to help people to do more business with larger enterprises. We want to make sure organizations are doing the things that uh reflect in reality what they're saying they're doing. We want to get away from uh all the expectations of all of these regulatory pressures and instead look at this from what's the most responsible way to protect yourselves and prove it to people and earn the business trust of folks uh in a pragmatic way that matches your business. Um and so sometimes people uh you know ask us about how we feel about different frameworks. We're laser focused on a couple of frameworks. Um and you know, we're a firm believer that if you put all the frameworks together and have a solid understanding of what each of them asks, they're all asking 80% of the same things.
SPEAKER_01I've heard things given to either borrow or steal from each other anyway, just depending on your point of view, right? Uh just for a sake of our conversation, what what what ones do you focus on mostly, Bill?
SPEAKER_00Well, we're really focused on uh the third-party risk risk associations framework.
SPEAKER_01Um That's a great one, by the way.
SPEAKER_00Yeah, we've achieved certification in that.
SPEAKER_01Um let's uh security questionnaire. So uh love
Why Questionnaires Miss Real Risk
SPEAKER_01them, hate them. Um whether you love them or hate them, what do you feel about them in giving us a true picture of security from a vendor?
SPEAKER_00Sure. So we have some uh some unique views about that, Greg, and uh we're not afraid to ruffle some feathers about that. But you know, we think the status quo of security questionnaires aren't always reducing risk and are perpetuating paper compliance. We think that it's really important to replace these flat, self-attested checklists with more intuitive, point-and-click branching risk assessments. Um, we think it's important to provide context in business English that people relate to. We're all in our industry, you know, in our own heads, talking past vendors and sometimes not aware that they just want to um get through this really painful thing they don't quite understand and answer to the best of their ability, even if they don't know what you're talking about, and you end up with garbage if you're not really careful about that. So um, you know, not only do these programs need to be designed by certified professionals using good frameworks, but um, you got to get beyond the yes-no risk classifications. Um, these are partnerships and where everybody wants to collaborate, wants true visibility, and don't want to necessarily scare folks, but get real uh information from them. So um part of that has to be triage, part of it has to be education. You got to deliver value to the vendor and you know, static um checklists and and spreadsheets, um, which is the true nature of a lot of what's out there is is a problem. Um we're using automation to get uh more reliable information. Um and we're also using uh deliberately very clear language and avoiding jargon as much as we can, um, so that um you you get a view of exactly what's going on, you make sure people understand and you get beyond what we call the attestation gap. Um we we see things like scoring gaps, binary answers that are tough to risk rank. Um you know, you can't let people just respond yes or no to the same thing.
Pragmatic Risk Readiness And ROI
SPEAKER_01Um, what's the most common operational filters that you help a business with?
SPEAKER_00Well, I think that when we start talking with clients, um, we want to understand their goals and we want to understand uh if they have a culture of security um and if the people they do business with value that and where they'd like to be. Most of them have pretty generic goals about wanting to protect themselves, um, but aren't always thinking about it in terms of am I business ready? Can I can I earn the trust of enterprise security executives? Um, and what does that mean today? What does it mean against my business and how my business is changing? So we really strongly believe in regular risk assessment to identify not only how they use technology, but where they're going with it, um, things that initiatives they have underway, um different businesses that they're getting into or expanding their business into. So we spend a lot of time really um trying to identify where people are going. And then we make really good recommendations that are specific to their business, not necessarily here's the things you all have to do, but rather, you know, here's what's pragmatic for your business, here's what you should really do in terms of having the multiple layers that are going to earn you the trust with the clients that you're interested in. And here's the ROI of doing it. And that's that's how we kind of um engage clients.
SPEAKER_01What's the best piece of advice you can give CEOs when evaluating tech vendor supply chains?
SPEAKER_00Well, whether they're evaluating it for their own purposes or being evaluated, it is um, does it pass your SNF test? Uh a lot of businesses are going through the motions, they're answering questions that may or may not uh be accurate or maybe an oversimplification. And at the end of the day, um what you're what you're saying to businesses through your risk assessments and your risk readiness and your risk posture is I'm prepared for the following situations, and I could use help in these areas, and I'm happy to collaborate with you. Those are acceptable things that I think enterprise risk managers want to hear. They want the truth, including your vulnerabilities. So don't be afraid to say, you know, strengths and weaknesses, but just make sure it's accurate and make sure that you're prepared to defend whatever that that picture of risk looks like in your organization that's being carefully documented because um you know, defending it sometimes is something you gotta do.
SPEAKER_01I like member vendors are an extension of your enterprise. No company wants to be doing everything. It it wants to focus on its core, what its core business is, and then buy the other things and services that it needs to do the rest. So, for example, a bank doesn't want to be making HR software. It wants to go buy that. So it can it can hire the people it needs and manage them. Um so so so if you treat it like an extension of your enterprise, then then you can you can you can get built. If you treat like an extension of your enterprise, you're gonna you're gonna assess it that way. You wouldn't simply send a questionnaire over to your your partner organization. You'd ask them, hey, how are you doing this?
SPEAKER_00Yeah, and I think that you want to also be clear that there's high value in in doing this and doing it right. And so when um when you take the time to do it right, it saves time on the back end. There's ROI to doing this in a proper way. I actually think the cybersecurity industry and the third-party risk uh vendors would would do a much better job for business leaders in articulating the ROI of dedicating the right amount of attention to the way that they're engaging with folks on on these complex topics. Because, you know, that's what this is. How should you be able to trust me with the things I do every day? And how does that compare to my competitors? And why do I feel comfortable that I have the right things in place? And why should you do business with me? That's like a a really um, I think going forward, that's something that every business leader should be able to articulate, and most aren't.
SPEAKER_01Um all right. Well, so we'll get into the hook start, the the uh uh supposedly five-minute max, but we'll we'll see how that goes. Um
MSP Blast Radius And Better Due Diligence
SPEAKER_01hook sort of get people engaged. Um this one is again um coming from your space, mini service provider versus blast uh vendor blast radius paradox. Um service providers and IT vendors hold the keys uh to the kingdom for hundreds of client environments simultaneously, uh, making them prime farmers targets for supply chain attacks uh as a unique third-party risk organization. How can the organization how can an organization engaging an MSP get a better sense of their security?
SPEAKER_00Well, you know, it's it's kind of funny from one angle, uh your MSP or your security partner is a third party that you should treat as part of your third-party risk program, even if you may not have uh a program. This is an important one to get right. I think you want to understand where their focus is and um their strengths and weaknesses, what they do and don't do, um, how broadly they uh reach into your business, um, and what their what types of architecture they're using and what types of back-end tools are gonna have sensitive data that concerns your company, um, and how is that protected? I think that's all really um fair game, and it's important for every business to ask. Um, but I also think, you know, back to that point I was making about ROI, why do you do things this way? And how are you different with others? What are you most focused on helping us with? And why does um the security that you have in place for all of the tools that that touch our data reflect that? Um I think that's fair game for people to know.
SPEAKER_01Typically we see folks who engage with MSP, perhaps, and you you mentioned this, not perform as much due diligence and due care on the MSP as they would another vendor, perhaps. And and I liked your answer was don't just send them another questionnaire, especially for an MSP. This is a relationship. I mean, and they're they're gonna have a book of your risk, right? They're running some of your risk. And so sending them a questionnaire to your point earlier is not sufficient. You need to ask questions, you need to become a partner with them, and and that's only gonna happen through conversation, right, Bill?
SPEAKER_00Yeah, not only that, but you know, what are what else are they thinking of and and where's their where's their headspace at? What are they doing about financial risks that um you know supporting so many customers do? What types of uh insurance coverages do they have in place? What types of limits tied to incidents? I mean, in the event of um of a massive breach, how are they prepared to handle that? Are they thinking about that?
SPEAKER_01Very good questions. All of them great.
SPEAKER_00Yeah, that's that's important. We're um in at TechRisk, we help folks not only with assessing properly, but deploying the right controls and then um ensuring that risk to make sure that considering that financial risk dimension as they bring that to the folks they do business with. And that's certainly a big concern that folks need to have about the folks they entrust with their security.
SPEAKER_01How do you advise clients to evaluate their operational security posture of service providers with elevated or privileged access? Because that's really where a lot of the attacks come from, is in that privilege access phase.
SPEAKER_00Yeah. Um, however, you know, we we look at this a little bit differently. I think in reality, a lot of people are highly focused on service providers with elevated access, with you know, who they do the most business with, they have the largest contracts with. And sometimes when you ask them, how about the little guys or the smaller vendors that you have? Um, how do you address that? And they don't have good answers. Um, sometimes folks say, uh, hey, you know, we're able to look at 65% of the folks with SOC2 Plus um who are vendors, and we have really good data on them. Like, oh, that's awesome. Um, what about all those other folks that you're not looking at? And what are your strategies to be able to take a good look at all of those? So um, in short, being able to use tools that reach out to every one of those organizations and identify, at least get a baseline view of what their security culture looks like if they have one, how they're protecting themselves. You know, um, I think it's no secret and and well known today that um banging on the front door of the fortress isn't the preferred attack method of a lot of the bad guys, and getting on the bread truck that's in and out of the castle four times a day is uh is a lot easier.
SPEAKER_01Easier, yeah. That's right.
SPEAKER_00Talk to the bread trucks, you know? Who are those who are the small vendors that um are moving in and out of your business regularly? And don't forget. Pardon?
SPEAKER_01Solar winds, right? Yep. Of course, I I used solar winds when I was an IT administrator years ago. I I probably wouldn't have thought about uh solar winds being a target until it was a target. And it changed my perspective. Bad actors targeted solar winds, not because they wanted solar winds, but because they wanted access to the three other agencies, the Microsoft and all the other people who used solar winds, right? Excellent point, uh Bill. Right spot on. Um, how can security teams bridge the gap between high-level regulatory frameworks and real-world operational threat hunting when monitoring vendor dependencies? Um,
Bridging Compliance With Real Security
SPEAKER_01regulators are focused kind of on compliance, the way the regulations are written. Whereas compliance isn't enough to do threat hunting and to do real security. How do we bridge that gap better?
SPEAKER_00Well, look, a a lot of folks aren't going to be um uh aware of uh really specific framework things, but you've got to build that into the workflow of how you engage them. You know, I I mentioned that uh one of the uh frameworks that we work closely with, third-party risk association, um, you know, has specific process to um be able to engage people pretty deeply and meaningfully in in certain areas. And it's you know uh very risk-dependent looking at the inherent risk of different companies and deciding what's appropriate for for the risk classification that you anticipate, you know, you're gonna see. Um but uh bridging the gap is is having a thoughtful program that um really uh speaks to their unique risks and gives them the opportunity to share what they are doing, aren't doing, or even that they don't know. We we believe that uh giving folks uh the ability to respond to some of these things with I'm not sure, and then turning that into actionable follow-up and getting to a point where um not only you get clarity on that, but you can even put triage in place and help them to get where they need to be. Um I think we've got to remove a lot of the um the fear of this process out of it by engaging folks in, you know, let's find out what you still need to do to have the full trust of our organization. And we have resources in place to help you do that. So I think being able to, you know, not only follow the frameworks, but have a can-do attitude about um how you can convert them to where you need them to be is a good way to structure a program. That's great.
SPEAKER_01I commend you on picking up a third-party risk associations uh framework, right? It's a good framework yourself. Um
AI Agents And Shadow AI Exposure
SPEAKER_01big question number two is about supply chain resilience, AI. Um, as vendors rapidly integrate AI tools and automated agents into their core platforms, how should organizations adapt their due diligence and continuous risk monitoring?
SPEAKER_00Well, so this is the question of the day, right? Um AI is an explosion of risk in a million directions at the same time. Um and we think that organizations have to be really careful about this. Um you know using AI agents has to be uh done in a in a very careful way because they combine you know those autonomous decision-making capabilities with very sensitive data, and they move at machine speeds so they can execute extremely fast. Like it makes it really hard for human teams, human security teams to catch up with what's going on. Um you know, we are using tools um ourselves that are um using AI to put more scale into the way we uh engage folks. Um but you know, this is tricky. You know, we are, for example, um we've added a dimension to our risk assessments that has a shadow AI component. Um and we've seen some unbelievable answers out of clients we engage where they say, Oh, we have you know two main uh tools that we're using uh that have AI models in place. And we'll do a shadow AI check and realize, you know, you guys have 19 software apps that you are using across all of the uh the different employees. And we don't even know how many cloud-based ones there are, but we recommend that we find out and they're shocked. Um and the risk here comes in a lot of different layers. Like, for example, um, you know, we see a lot of marketing and sales teams uh putting really sensitive competitive differentiators into AI models to maybe fine-tune the way that they're positioning their products, but they're not realizing that you know, they're giving that data away with not fully licensed or sometimes free tools that are consuming that. And the next guy who asks about their organization can understand that. Um, you know, the uh the Navy used to say uh uh loose lips sink ships. Um loose lips with the use of AI is is going crazy and exploding. We see that with our clients, and we think they gotta be very, very slow about adopting AI and put really strong guardrails in place about who's using things unofficially or in unlicensed ways.
SPEAKER_01Aaron Powell Yeah, I think the shadow AI is almost worse than the shadow IT because it's uh it's almost uh it's a ubiquitous idea in almost every product, even if it should necessarily be in there or you don't want it. And a lot of them can't have the ability to turn it off, too, which is kind of disappointing.
Fourth-Party Risk And Continuous Monitoring
SPEAKER_01Um a follow-up on that is um what strategies do you recommend for managing fourth party risk without overwhelmingly in internal risk and security teams? Uh and the intent there just for everybody's edification is a lot of the AI uh capabilities that are being delivered through the tools that you're assessing are actually coming as nth parties, right? They're the the the company or the service party you're buying the product from doesn't necessarily have their own LLMs. They're buying the LLM capabilities from somebody like Anthropic or whatever. I forget all the anyways. I don't want to miss between those names anyways, but they're meant they're providing As an F party. And so we always struggle as practitioners with the F party problem because it becomes exponentially problematic. So, Bill, with all that setup, what do you think?
SPEAKER_00Well, look, we think it's really important, even for smaller businesses, um, to pay attention to this. There's a trust dimension that's really easy to underestimate. Um, if you're selling into bigger companies, you're gonna increasingly be someone else's third party. Um, so learning who do you rely on downstream? Um, engaging your clients in that or or your partners in those types of discussions. And you don't need this big enterprise program to get this right. Um, have talks to come to an understanding about what vendors actually matter. You don't need to map every tool that your business touches. Uh ask your vendors who they rely on, they're mission-critical vendors that um they can't uh deliver without. Um and then looking at shared dependencies. You know, if you're all on the same cloud platform, for example, or you all use the same payment tools, um, you know, think through some of those things. Um and have your answer ready when when your customers ask, I think is is a very important thing to think through. Um get help where it makes sense and be pragmatic about it. Um, you know, starting to get ahead of that is a is a great idea. Maybe if you don't have any security folks on staff looking at a virtual CISO or a fractional leader to help kind of identify these things, can be money well spent. And um, that's what I'd say.
SPEAKER_01Very good. Bill, thanks. All right, we're at the we're at the at the bottom of the 30 minutes here, roughly. So we're gonna start the after-action report. What is the one immediate tactical action item a security or TPRM leader should implement tomorrow to audit uh high access service providers and reduce supply chain risk, Bill?
SPEAKER_00I think it's really important to uh robustify uh continuous monitoring. Good job. Um I think what passes for continuous monitoring today is is oftentimes uh pretty lightweight. Um we're a big fan of uh endpoint detection and response. Um we're um always comparing that as well as vulnerability scans and things to um logging and being able to aggregate that data to get a really good perspective of what's going on and being able to share that data um with the right folks. Again, um the more that vendors can collaborate with larger enterprises they work with and candidly share what's going on, the more trust they're gonna earn, the better they're gonna work together, investing in better tools that um not only perform in real time, but you know, let's talk about using AI. Real positive use of AI in a lot of these systems is keeping up with the threats that AI is generating from outside and finding unique ways to isolate information and and respond is uh a great capability. We work with an EDR vendor who has some great capabilities in that area, so I think that's important. I agree.
SPEAKER_01Well, and and I have a small section in the book and in the AI and third-party risk book that actually says um point-in-time uh AI will be the death of point-in-time assessments. Uh and uh it's a bit tongue-in-cheek because I think there will always be the questionnaires will always be around because of the need for compliance and and other issues. But to your point, the tooling now has become to the point where it's sending a uh asking for a vulnerabilities, uh, vulnerability scan once a year, that's not continuous monitoring. That's a point-in-time assessment. Continuous monitoring is continual. Now, that doesn't mean that you're doing it 24-7, 365. I understand people have sleep and that kind of stuff. And you may not have a sun never assessed kind of shop. But it does mean that you have tooling that's looking for vulnerabilities and issues almost continuously, not once or twice a year. That's an excellent point. And and so please don't conflate continuous monitoring with point-y-time assessments. Uh Bill, thanks again for being a guest. It was really great learning about your business and your perspective on all these things right down the baseline. So you're perfect. Um great talking with you. Yeah, you as well. Sorry to talk over you, Bill.
SPEAKER_00No, appreciate the opportunity to be on your podcast.
SPEAKER_01Let's get to you or your partner back on for uh a demo of your third-party product, and that we would love to see that.
SPEAKER_00Yeah, for sure.
SPEAKER_01Okay, great.