Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Continuous Third-Party Risk Monitoring with Girish Redekar
Welcome And Guest Background
SPEAKER_00Hello and welcome to another edition of Third Party Threat Nerds Podcast. I have with me a guest today, Giddish Redekar. He's the co-founder of Sprinto. And I will let, as I usually do, let the guests introduce themselves a little bit more and tell a little more about themselves.
SPEAKER_01Thanks, Greg. I'm really excited to be here. Thanks for having me. To introduce myself, I'm a programmer and a 2X founder. Before Sprinto, I did another startup that scaled to more than 2,000 customers as an engineer founder, and I had to set up and run our own compliance program. That taught me something simple. That is, the hard part isn't reading a framework. It's about the hard part is actually about keeping hundreds of small promises. And you have to keep these promises true while your people, systems, and vendors keep on changing. So we built Sprinto to turn that recurring work into software and continuous evidence, clear ownership, and fast reaction so that no security or privacy or risk team spend uh have to spend time chasing screenshots and actually do work in terms of reducing risk.
SPEAKER_00That's what everybody's role in this as risk managers. That's our role is it's not to move paper around, it's actually to find risk and then reduce it, right? And sometimes we feel like we're just moving papers around on a deck. So that's great. Thanks for that. All right, we're gonna get into our five quick questions to get to know the guests better.
Compliance Myths And Quick Hits
SPEAKER_00Um what is one compliant question number one? What is one compliance framework myth that tech founders still fall for in 2026?
SPEAKER_01I'm I'm surprised this question is actually focused specifically on tech founders. I'm I'm squarely in that. But I feel like uh the the there's still this myth that the certification is a finish line. Um and since we are talking with tech founders, I'd like to think about this as the framework is like a test suite. It's not your product itself. Um it gives you a useful common baseline, uh, but it cannot model every way that your specific business can fail. Um so use that as a floor uh and design your uh you know design your system beyond your uh around your actual data uh and actual flows and access paths and dependence. And there's a 2026 version of this, which is sorry, which is uh AI didn't make compliance cheap. I feel that AI just made the paperwork cheap uh since you talked about paperwork. And those are not the same things.
SPEAKER_00Yeah, yeah, yeah. I think I under that one. I'll just feel in at some point. Um security questionnaires versus continuous automated evidence. Which one gives a truer picture of under risk? And I know this is probably an easy one for both of us, Kirish, but I think it's still important to ask the question.
SPEAKER_01Right. Yeah, uh, you know, the obvious answer is uh continuous evidence. Uh it does give a truer picture, but uh you know, I I I don't think uh questionnaires are completely uh useless either. Uh you know, it it's sort of like the uh the testimony, it's the context which tells you why the evidence means what it means. Um so the evidence can also have blind spots and the and the questionnaires can give you the context, the the whatever is required to thread it together.
SPEAKER_00So very good. I I uh uh just reminds me uh in my in the in the AI and third-party risk book. I'm gonna run so I'll show it to everybody. Um I actually have a uh a section that says point-in time assessments will be the death of of uh point. Oh, sorry, AI will be the death of point-in time assessments. I guess backwards. Um and the idea there is somewhat somewhat similar to you, is that it it it doesn't mean that uh questionnaires will ever go away. It just means that you don't necessarily have to rely on them anymore for all your evidence gathering and all your your information. That's that's good. I agree. I totally agree. What is the biggest mistake companies do when scaling their third-party risk program for 10 vendors to thousands? What do you think? Wrong.
SPEAKER_01I think the biggest mistake is to scale the paperwork instead of scaling the decisioning model. Um at 10 vendors, uh smart people can brute force the work. Uh, you know, thousands of vendors. Uh you need some triage-based systems, which is somehow connected to the business criticality, the data sensitivity, the amount of privilege that the vendor might have. A risk-based format, right? Yes. So you can't basically just take the same model and just scale it to thousand. Uh so I I really say that, you know, instead of scaling the paperwork, you should scale the prioritization network, uh, this prioritization system. And and that's the that's the bigger thing to do.
SPEAKER_00That's a great thing. Scale your risk, your risk management uh uh process, not not the just how you're you you said you're Penn, you you and I, I could do I could do 10 vendors and my asleep with my inside to some extent, because I've done thousands of vendors, so you're totally right. You look at a brown and paperwork if you're trying to scale it that way. Um in one sentence, how do you define continuous compliance?
SPEAKER_01I think it's uh it's a state where uh an audit or a questionnaire or a customer due diligence stops being an event uh because there's nothing left to prepare.
SPEAKER_00Yeah. That's great. I I I hadn't thought of that as a definition, but I think that's a great one, actually. And then a last uh the more fun question I try to ask at the end of everybody what's your favorite way to recharge when you aren't automating complex TRC workflows? Not that exact question, but what do they have fun?
SPEAKER_01You know, uh it's going to sound bizarre and uh but oddly, I actually recharge by coding.
SPEAKER_00It's it's it's sort of like uh, you know, yeah, that does sound actually I I think it back then does sound not actually good. But hey, you know, if that's what if that's your way to kind of disconnect from your your what you do day to day, then that that's that's that's what works for you. That's great. Um that wasn't gonna be my expectation. I was thinking like you were gonna go hiking or like something like that. Do you do you go outdoors and that kind of stuff? Do you travel a bunch?
SPEAKER_01Yeah, my my wife's uh an outdoor sea person, so I do go on a bunch of hikes. But yeah, like if I want to just de-stress, uh coding helps as well.
SPEAKER_00And so what uh let's uh let's stretch that out a little bit further. What do you what like what do you code? What do you do typically?
SPEAKER_01You know, I I actually uh uh this pick like a small project. There's no roadmap, no customer, no deadline. Uh and it sort of just gives me back the joy of why I became an engineer in the first place, just to build something.
SPEAKER_00That's great. Yeah, hey, no, that's I totally get that. I I sometimes play it's not it's totally not as at your level, but I'll play video games once a while on my on my desktop because it's how I kind of originally got into computers was playing playing uh video games, that kind of stuff. So I totally totally get
The Point In Time Compliance Illusion
SPEAKER_00it. Okay, let's get into the the the meat of the subject, and we'll do the hook start. The hook start today is um the point in time and the point-in-time compliance illusion. A vendor passes a SOC to on it or answers a security questionnaire perfectly on day one. Surprise. Six months later, a misconfigured API, there's unpad zero day, unauthorized AI tool creates a massive breach of vectors. How do security leaders shift from static annual compliance checkboxes to active continuous third-party throughout it? What's some of the things that you think they could do to kind of figure out that that SOC2 isn't gonna give them that peace of mind in perpetuity?
SPEAKER_01Yeah. You know, uh one of the things to understand about point-in-time compliance and and the thing that I uh you know often pointed out to uh CISOs and and other people is that the reason that point-in-time compliance fails isn't that people are lazy or dishonest. Uh, you know, most of them are neither. It it actually fails for a structural reason. Uh and it's the fact that we build this entire system around a scheduled event. Um and you know, anything that you schedule, uh, you prepare for, right? So the preparation is the contamination. The the vendor knows uh when the audit window is going to open, or you know, the internal audit team knows when they're going to do this. Um they know uh uh so so what you end up measuring isn't security, or you don't end up measuring the control, you end up measuring their ability to get ready. Um, you know, and uh you know, like the the funny anecdote I have about this is like health inspectors figured this out decades ago, right? That's the reason why they show up unannounced. Uh you know, so that's right. But but the way we sort of do this uh this compliance, uh, and the reason it's called illusion and it looks a little performative is because uh you know, is uh you you basically announce this whole thing. And um so so then then it's it's just about how ready can you get and how quickly you can get ready. So I feel like the the important thing to understand here is that the shift isn't going from annual to quarterly or from quarterly to monthly. Uh that's just uh you know, you're just taking the same thing and trying to do it faster. Uh the shift is to uh you know uh to signals that nobody really prepares for, but they just automatically come in. And uh, you know, they are uh there's things that you can just measure. So when I say that uh you know audits or checking things should not be an event, it should just be something like it's uh it's an exhaust of what you already do. Um it's a side effect of what you already do. That's that's a real system to build. That's great.
SPEAKER_00Yeah, yeah. I I I uh I totally concur. I I think some of the issues I have with well, I think what you're trying to differentiate, let me let me take a different tack. What you're trying to differentiate is um if you if you do a compliance and you do a soccer once a year, doing it every quarter, every month isn't gonna alleviate. That's not continuous monitoring. That's just continuous compliance, which is still an event that you prepare for every month. So if you do it every month, then you know what's gonna happen is on the 20th of every month, everybody's gonna be scrambling to try to get ready for the 30th. And then they'll they'll they'll pause for another 20 days at the beginning of the next month and then start rushing to get everything ready for the audit to get on the compliance check at the end of the month. Um the there are the comp the compliance stuff and the and the continuous threat uh management is are two separate activities, is I think is what you're gonna accurate. Yeah, right. That's great. I agree. Um question number one moving beyond point in time TPRM to continuous monitoring again, continue to start from the chronological statement, but continue to build on that on that issue.
Why Questionnaires Break At Scale
SPEAKER_00Um, as companies rely heavily on SaaS platforms cloud infrastructure, uh almost all EIAs being delivered through the cloud and through SaaS, right? Where do traditional manual security questionnaires break down? And how do we try and um change that? What do what do we do to once they break down, what do we do in difference?
SPEAKER_01That's a good question. Uh I think um they they fundamentally break down and on on three axes. Um so first, uh, you know, manual security questionnaires are slow. Uh they could take a ton of time. Uh they they you know you send them over, uh somebody looks at them, they take a bunch of time to respond to it, you get it back. Um this can this process can easily go over weeks. Um the second problem that I see with this is um it's self-reported. Uh, you know, it's uh there's no real way of actually knowing what's been said is actually true on the ground or not. That's what I heard.
SPEAKER_00It's a it's a phone it in answer.
SPEAKER_01Yes. And uh so uh and uh I'll expand on each of these a bit, but uh you know the third the third bit is basically about like how it's not contextual, it's it's extremely generic. Like it doesn't matter whether you ask that question or somebody else asked that question, it doesn't matter how how you're using that particular vendor, uh, you know, the level of privilege it has in your environment, just the same set of answers. And I feel like uh you know the combination of these three things is is what makes uh manual security questionnaires as the exclusive tool to break down. So um, you know, like speaking of slow, and and I I feel like it's important to understand all three of these together and address all three of these because you could take one of these axes and try and address that, and it doesn't give you the right answer. So I'll uh you know, one of the things I I find very funny, uh uh, especially in the world that we are in today, where we are heading towards using every with everything uh or solving everything with AI, uh I find this slightly absurd world where you know uh where there's AI which is filling out a questionnaire, uh, and AI that is actually grading that questionnaire. And uh, you know, like when I look at this, this is just automation of paperwork.
SPEAKER_00Uh think about it that way, but it is not right.
SPEAKER_01Right. So exactly. So you know, if if if you just address the slow part of it, this is what you get. Basically, you're just automating paperwork. You're not actually automating uh or you're not actually creating more assurance, right? So uh I I think uh so that's one part. Like you need to make it faster, uh, but you have to also take make sure the other two things are also taken care of, which is um you know, the fact that it is self-reported, which means that uh questionnaires are still useful for things that you cannot observe directly, like uh, you know, the intended data use or the incident history or resilience or you know how an AI model is being used or governance and so on and so forth. Uh, they can definitely become a lot shorter and more targeted or you know, triggered by some material change or risk or so and so things. But um, you know, uh the evidence should carry the burden uh so that it's it's not just about what you uh you know what whether you just give like a um a self-reported answer to something, but what evidence do you have to prove to that? So that's that's an important bit of what needs to happen. And most questionnaires don't necessarily support that. So I think that's the point that needs to happen. And the third and the most important thing that I um that I say is uh especially as we move to more and more um cloud-based systems, uh we we tend to forget that uh you know, we we treat every vendor the press the same way, regardless of how they're being used inside of your environment. So we need to have a better map of what privileges this vendor has, what accesses does this vendor have. Like Sprinto in general has a large number of integrations as a software that we ourselves build. But we know for a fact that different companies use us differently. And there are places where we have a lot more access to their systems as compared to the others. But if their TPRM process does not reflect the same thing, um, then they would be asking us generic questions and getting generic answers other than something, uh, you know, our risk exposure to some of these uh customers could be higher as compared to somebody else. So speaking as a vendor, uh I can clearly see that uh, you know, we we ought to be um scrutinized differently depending on who's looking at us and at what point of time, because this itself changes as well. So I think these are the three most important things to be solved. Like, and regardless of whether you solve them by AI or or whatever whatever you do, uh it's important to look at the speed, it's important to look at the context, and it's important to make sure that you're looking at real evidence rather than just self-proclaimed answers.
SPEAKER_00Totally agree. I the only thing I would add would be on the context, just to just to highlight it and not not uh to to add some uh color to it for folks, is for example, you'll get a you'll get a questionnaire back and it says they they do AS256 or AS 128, let's say. But that's for the whole, that's the corporate standard. But for the product of delivering is AS256. So again, it's contextual, and I've seen this happen a number of times. So so just I think that's uh you're gonna share some great points. Um let me ask you a follow-up question on that one.
Signs A Vendor Is Drifting
SPEAKER_00What are the key indicators that a vendor security posture is degrading uh between formal audit cycles? What are some key indicators you think that uh this back on the compliance side necessarily maybe, although it can be in continuous monitoring space too? What are some of the things that you look for that says, hey, I think this vendor might be having some issues or I need to I need to lean into them a little bit more?
SPEAKER_01Right. Um I think I'd look look out for two or three categories of drift. Uh first is uh you know, some sort of uh control drift. Uh for example, if if there's a way to know that uh you know some MFA coverage has f has failed, or uh or you know, it's it's fallen beyond beneath a certain level, or the number of privileged accounts have grown, or you know, some endpoint or backup coverage is breaking somewhere, or evidence starts failing, or some some serious finding that remains unresolved, or something like that. So that's that's fundamentally like one category or one bucket of things, which is some drift in controls. Um the second thing that I'd look for is uh you know, it in any manner if there's exposure drift. Uh there's a lot of threat intelligence out there. So it could be in the form of leaked credentials, uh, you know, new internet-facing assets, uh, any active exploitation or any material vulnerabilities that are not yet solved, or reported security incident.
SPEAKER_00I didn't mean to interrupt. I was gonna you're you're I was trying to help some contextually for some of the folks listening. So you're gonna get the the first, so the second one, you'll get that mostly from your threat intelligence and and other folks, right? The first one you can get through some of the questionnaires and also from some of the tool sets and stuff like that, too. You can see control drift, uh, you can see things like that. Um sorry, uh the third one you can do.
SPEAKER_01No, that's that's great. Actually, that's useful to know. Yeah. Like the first one is is how how how you basically build into your due diligence process. The second one is basically you you sort of do out-of-band uh threat intelligence and and sort of get that information. And the third one is uh, and I feel like not enough, uh like I don't see enough of uh enough of my customers to do this as I'd like more and more of them to do this, which is uh you know, just drift in relationship in the sense that you have to understand that the way you're using the vendor, it could be changing. And this is something that you can do at very little cost. Uh you know, this this is in completely in your control. You're not dependent on the vendor. You you you can look at uh you know what's really happening with with the way you're using the vendor. Are you are you giving them more privileges? Uh are they using more agents than you than you did they did before? Are are they actually having more uh you know more access to your systems and stuff like that? Are you using them for more use cases than you did when you when you signed the contract with them and so on and so forth? So these are the sort of the three buckets of things that I would actually look at in order to know if my exposure to this vendor is improved uh is is enlarging.
SPEAKER_00I would agree. I I uh I'll add uh just a slight thing to that on the audit side or sort of actually sort of the relationship growing. What I meant was what I would uh I was jumping in was oftentimes when I was disengaging with a vendor, I would I would force my team to audit how the how they were being used internally. Because usually you keep vendors for a long time, or the relationship grows organically, and surprise surprise, they don't update the system of record with those changes. And so oftentimes if you go to disengage and you don't really have a good system of record, again to your point earlier, Gears, you're gonna disengage incorrectly. You're gonna miss some data that you should have had a certificate of instruction for, all that kind of stuff. So so to build on what Gears says, if you're gonna disengage, do the third one for sure, because that one I've seen hit people a couple of times where they've missed something because they didn't understand that, oh, we bought it originally for marketing, but guess what? The engineers are now using that tool too. Right. So, anyways, uh I wanted to build off of that.
Governing AI Agents And Privilege
SPEAKER_00Um big question number two is kind of a fun one, a little bit more the future of third-party risk management, AI integration, and nth-party visibility. I know it's a bit of a bit of a lot there to cover, but so we'll cover in a couple of questions. One is the first one is as vendors rapidly integrate AI agents and automated tools into their stacks, how can compliance risk platforms help track and govern these emerging third-party risk factors?
SPEAKER_01Um You know, uh, this is so interesting. Uh I think one of the things that we all uh ought to recognize is that you're not gonna get a chance to assess your vendor's AI. It will just arrive in a product update on a Tuesday morning inside a vendor that you approved two years ago. There was no new contract, there was no new assessment, procurement never saw it. Um that's the whole problem in one sentence. Yes. Exactly. Right? So I I think uh the the thing to realize over here is that uh you know, we've we've built like this, uh we spent a couple of decades building like this system uh around uh you know identity governance for humans, uh for humans, basically. We we we understand uh you know the life cycle of joining and moving and leaving, uh, and it works. Uh but we didn't ever build this same kind of a process for an agent. Um, you know, uh so there's no lever process for an agent, there's no onboarding or uh uh you know process for an agent. So an agent uh is kind of like a vendor employee that never sleeps, that never forgets a credential, that never gets offboarded. Uh that should give us goosebumps.
SPEAKER_00And you know, uh nobody more than more than goosebumps, by the way, get us for me. Because having read the privilege access management book and and understanding that we're making thousands of agents. How are we how are we managing those credentials? And those are mostly privileged credentials, by the way. They're not generally normal user credentials. That that just scares the Jeeves out of me. That's where that's where the tax factors are going to come from, I think.
SPEAKER_01Right. And and I feel like uh that that should wake us up to the fact that um you know AI changes the unit of governance. Like we're not no longer assessing just a vendor, uh, but you're assessing uh like a capability that can see data, make decisions, and sometimes even take actions. And I think of uh, you know, uh like I think my my mental model of thinking of an AI AI agent is like a software with a badge and a set of keys. So for every material agent, you should basically be asking four questions, like which is what can it see? Uh what can it do, who can stop it, and can we reconstruct what it actually did? Uh you know, audit audit logs of those things. And and you know that translates downstream to an inventory of use cases, the model, the subprocessor lineage, and you could do a bunch of things downstream from there. Um, and you could even have a kill switch. But uh the job of a risk platform is to keep that con that inventory current uh to make sure that you collect the supporting evidence and you map it to the right controls and you you know you have a way of knowing material changes and you can route those. material changes to a countable vendor. So you know if uh since you've you've had some access and privileged access background, um you know more important than asking. Sorry, go on. No, no, please, I won't you finish your part. And you know, uh I I think the the privileged access, the PAM uh lens tells us that more important than asking which model it is is uh is to ask what keys did we hand it. You know the model can change downstream but like if if you decide what keys did you hand it then you you at least know the the blast radius of what it's going to do. That's right.
SPEAKER_00Yeah and and it's and it's a and and I but the word that keeps the the the phrase that keeps popping mind is least privilege in my mind. That that that screams that that issue because um and I heard somebody in their name say well we're just treating like service accounts. No yes there's some similarity it's a machine account but agents do a lot more than a service account. A service account is a completely different animal. And by the way there's not thousands and thousands of a a normal user can create an agent a normal user cannot create a service account that that's generally assigned for service administrators for for a reason. And so you you yeah I think we're just both trying to highlight this point that it is an issue that is I see a lot of posts on LinkedIn a lot of folks like my and in the space like Jerry Chapman and John Kinderbog and all those folks have talked about this in the zero trust space because um the permisse access management in the AI space is just not is it's not exist at the level that we should we should have it. So for everybody else that isn't scared enough please be scared now let's do the let's do the nth party question.
Nth Party Risk Without The Fantasy Map
SPEAKER_00How can security leaders maintain visibility into nth party fourth party supply chain dependencies without creating massive operational friction in particular because most of the folks that are uh you're buying a SaaS software from that has now AI capabilities in it, most of them are not building their own LLM models they are purchasing tokens from one of the big four or five or six and and so it is so the AI stuff that you're getting is in the party to some extent. So that's that's even becomes even more complex. So with that setup Kitish let me let you answer the question.
SPEAKER_01You know um this is something that I've tried to solve uh within my company as well and I feel like um uh the both extremes are wrong in the sense uh you know uh one extreme is obviously wrong which says that don't don't don't worry about it but I feel that the other extreme is also equally wrong where you know we might actually make uh um you know perfect uh the enemy of good what I mean by that is um the honest answer is that full nth party mark mapping is probably a fantasy and chasing it uh is how good programs die. Uh you know you'll you'll spend years building a family tree that's wrong the day you finish it.
SPEAKER_00Yeah totally keep going I want to hear more on what you're gonna say.
SPEAKER_01So uh you know like I I again think of it uh as less of a mapping problem than more of a concentration problem. So you know uh so instead of trying to draw like the orc chart of your supply chain uh just try to find the load bearing walls uh you know so uh you're for for systematic uh so if if if you basically systematically go about it and find critical vendors and trace three things right yes just three things one level deep uh where sensitive data goes and where privileged access flows and you know what downstream failure can stop a critical business service or something like that. Then look for a concentration and single points of failure. So you can support that with some material subprocessor change notifications or contractual flows downstream, et cetera. But I feel like the the the the mental image I have the metaphor that I have is you know instead of trying to map every road in the country just map the bridges uh that your business can't afford to lose so if if you're if you're like a military general like these are the important choke points that you you you really need to be worried about rather than getting just lost in the woods uh about this whole thing.
SPEAKER_00Yeah I I I totally the the the exponent the 10th party becomes an exponential issue right if you have 12 party 12 third let's say you only have 12 third parties and they each have 12 important third parties of their own you're already at 144 vendors and you only started with 12. And most people have more than 12 vendors. So immediately you can see the exponential issue. The recommendation I like came from uh for a while from the the three letter agencies the FRB OCC and well four letter FTIC um uh for a while they made us required when I was working on space you had to go out chase the nth parties now they say and I this this has always been my suggestion is and I think you're building off it is get to see if your third party has a good third party responsibility program. If they manage their third parties correctly then your fourth parties are they're they're they're good as both right that's your uncle as they say right with your pito as they say so you're good. So I I totally agree it if you don't worry about it at all you're you're with on three graveyard if you try and chase everything you you're never gonna you're right the the you're gonna your program's gonna die because you're gonna be chasing uh stuff that just isn't a value to some extent too um assess your vendor's third party risk program and and and listen to what Chris said I think that was great that's a good one yeah um let me ask the the last one um on this in this big question too which is how do you advise risk leaders to present automated compliance and vendor risk metrics to executive boards to demonstrate real
Board Metrics That Prove ROI
SPEAKER_00ROI? Because I think that's something that we sometimes miss with this space. We forget to show our work. Yeah because we're we're we're we're almost like insurance we don't we we're only used if something bad goes we're only notice that something bad goes wrong right to some extent.
SPEAKER_01How do we demonstrate that we're providing value as practitioners in this space um yeah I think the uh so so I I've funnily being on the both on the uh creating and the receiving end of this whole uh this whole equation so I I've seen uh our own reports and I have to sort of uh look at it from a board's perspective and I feel like the standard board that's right yeah you're in you're in the you're in both positions now aren't you yeah and and you know like uh what I've seen is like the the standard board slide uh reports activity right uh it talks about assessments that are completed questionnaires that were returned the percentage of vendors that we reviewed um and it it sometimes sounds like a fired department sort of reporting on how many hydrants it expect in it inspected uh you know what the what the board really wants to know is uh how fast can you put out a fire uh you know and and how many buildings did actually burn and if if if if that happened, right? So I think um uh the the uh the the one question on uh you know what should be the North Star that the team sort of works on is uh I I I would basically ask the team to to to give two numbers and defend them all here uh before I get to the ROI bit and the two numbers I'd say is basically the time to know um you know like uh from a vendor incident that actually started for us to being aware of it how long does it typically take and and you know that that should be a the yes to for us to basically be able to uh to to track and and the other one is basically just time to revoke or time to respond like uh you know from a decision to uh where you think that you need to do something with the vendor maybe you want to pull a skill switch on them or you don't need to cut a vendor um and you'd make that decision from that decision point to uh to what it how long it takes to uh you know the vendor's access actually being dead um and both of these are relatively measurable and they both can be drilled but but that actually uh you know sort of tells you how good your program really is. It does but and and and you know just to sort of distill it down to uh to your ROI um you know that there are just two uh sort of things that I typically look at and two currencies. One is the amount of risk that is reduced. And I I know there are two schools of thoughts on whether you want to report that in dollars or in some other metric. I personally have no opinion on that. But the second metric that I would also look at in terms of ROI is uh you know how much time did you return um back from your TPRN program, which would otherwise be like an extremely onerous activity and and how how uh you know the just the amount of time it takes to actually do those things for regulatory reason or otherwise. So basically if if you could um you know if if you could basically put these two metrics uh then the ROI should be relatively simpler to understand for anybody who looked at it.
SPEAKER_00Yeah I agree. Thanks for that Garish I I hadn't put it as a perspective I I I do agree that a lot of folks tend to just present here's how many fires we put out or here's here's the number of fire items we we we counted as you you I think that's a great analogy as opposed to saying how fit we are as a fire department and here's the fires we actually here's how long it took us to get to the fire and here's how long it took us to put the fire out um and then to get back to the station and put all the equipment back together. Right. We all as as practitioners can understand where that where that analogy leads leads for us in terms of a breach or an incident or or an outage whatever it is that you want to do. I think um those are great um methods to present to a board. One of the reasons why I push this issue I think is because most people organizations are not well funded or well staffed generally you know they're usually teams of one or two. You see bigger teams in some organizations and so they also have to fight for resources. And so I I really want to advocate the listeners and folks in the space to listen to what are said and and and others in the space to make sure that you're you're advertising your work. Because if you think that the senior leaders know what you're doing they they just don't they have it's not that they don't care it's just that they're busy. Right? And they have thousands of other employees potentially or hundreds of so you do have to show your work. And they they won't they won't roll their eyes, I promise you. They they want to see what you're doing. Okay.
One Practical Step To Do This Week
SPEAKER_00We'll wrap up that last question. The after-action report we always try and leave listeners who braved the whole session um with one immediate tactical step a TPRM or security leader can take this week to automate vendor risk monitoring and reduce manual overhead finish is your your question.
SPEAKER_01Wow um I think I'll I'll I'll go back to something I I passingly mentioned before. If I had to do something in in a week uh no budget no procurement uh nothing else involved uh what I'd do is I just pick my three most important SaaS vendors uh three most important SaaS platforms maybe your uh you know your CRM your your code host uh or uh your identity provider or whatever is like the three most important systems and I just look at every single third party uh that has uh an API token or credential or an OAuth uh you know connected to that. Right. So I I'd and for each of those third parties uh what I'd simply do is write down three things. One, uh you know, what scope does it have? You know who owns it and uh when was the if if it's like an API based thing though so when was the token last rotated when was the credential last rotated and so on and so forth. So it's it's a surprise.
SPEAKER_00Yeah be careful what you ask for.
SPEAKER_01Two years exactly you know the the funny thing is like this is something that you could do in a in in an afternoon to be honest. And and you know the but with the fact is that most teams cannot fill that table. And and and and the the reason I ask for the owner is that you know it's it's very easy to sort of come up with a process to say that hey I'm gonna revoke everything that has no owner. You either have to basically say that hey I own this particular connection and you'll you'll randomly find integrations from vendors that you stopped using or paying two years ago. That's actually lying somewhere in there. You know and and you start seeing like a long tail of things which are just incidents waiting to happen. But that that's the simplest thing I could do. Like it it doesn't take you know it's it's all within my control.
SPEAKER_00Yeah exactly and and and for the listeners and for you going to um I always ask this one question at the end and I always get a different answer. And I don't think that's all the answers are great. I mean there's none of the answers are wrong. They're they're right. What I want to emphasize for the listener is if you tune in every week you're gonna get something practical to do this every week to say oh I've been oh this week I'm gonna go and look at my three top SaaS founders. I forget what the last guest said but he or she has something different and on that Tuesday you could pick on Wednesday or Tuesday you could pick that up and do that. I think it's a great way for folks I like the idea of picking up the top three SAS vendors because most of our stuff is SaaS anyways. So you're probably going to find some important stuff you need to pay attention to that's probably gotten missed.
SPEAKER_01So I all love that and I'm glad you asked that question though uh sorry I was just saying that I'm glad that you asked that question because we can all sit here and and talk about massive programs that take such a large amount of time to build and and they take consensus and and you know coordination across multiple people but having something actionable that I can do uh in a short period of time is is really valuable as well.
SPEAKER_00I think so too and I'd like I'd like to give readers some listeners something to walk away with if they could say okay I'm gonna try that see how that works for me. All right
Wrap Up And Where To Learn More
SPEAKER_00we're uh we're at the end of the end of the end of this podcast into this session I want to thank everybody for tuning in and really uh thank this has been a great conversation we went longer than I expected but that's been that's been because we I think we've been had such a great uh conversation about things tune in for the next uh podcast uh please do subscribe and uh check out uh goddish's uh uh website uh sprito. Is it spritto.co.com sorry sprito.com and we will uh uh see you soon thanks a lot for being a guest Giddish thanks for having me Greg