Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor.
We dig into questionnaire fatigue and the trap of treating checklists as controls. A static security questionnaire can’t tell you whether a control exists today, whether it’s sufficient for your specific integration, or whether your internal use case has quietly drifted since onboarding. We walk through concrete examples like marketing analytics tools that are low risk with anonymized data but high risk when fed PII or tied to business critical operations. The takeaway is a simple shift: stop asking “is the vendor secure” and start asking “are our use cases secure.”
Then we get practical about AI in cybersecurity and vendor risk management. Forget the hype about AI agents auto-filling 400 questions. The real value is correlation: pulling context scattered across contracts, documentation, procurement systems, emails, and Slack into one place so a human can make a defensible decision and prioritize the right actions. We also connect third-party risk to zero trust, covering privileged access management, identity-bound sessions, and just-in-time access, plus why continuous assessment matters far more than an annual review.
If you want a step you can take this week, we share a lightweight “context graph” exercise for your 10 most critical vendors that clarifies data access, dependencies, and what happens if a vendor fails. Subscribe, share this with a teammate in security or procurement, and leave a review with your biggest vendor risk blind spot.
Welcome And Guest Introduction
SPEAKER_00Hello, welcome to the next edition of Third Party Threaters Podcast. Today I have my guest is Nivanton, who is the founder of Secure OS. And as usual, I'll let the guests do their introductions.
SPEAKER_02Hi, thank you so much for having me here, Greg. And I'm Nivedan, co-founder and CEO of Secure OS. Before this, uh I will worked in infrastructure and identity security, particularly implementing zero trust for large enterprises at a company called Teleport, which is an identity access management company. I kept watching companies get identity right inside the wall and treat vendors with production access like a platform paperwork problem. That's why I started SecureOS to make uh third-party risk continuous and contextual, not just answering questions.
SPEAKER_00Yeah, that's great. Well, you know, Zero Trust is near to my heart, Levant, and I'm that second trust. Zero trust and third-party risk folks. So I'm glad to hear that. I I know you your your work with teleport, but I didn't realize it was so intertwined with zero trust. And of course, the identity and access management stuff is also one of the things that really bothers me about how we approach third-party risk. We vet our employees harder than we vet our vendors. It's it's odd. Yeah. It's
Why SecureOS Had To Exist
SPEAKER_00an odd moment. Okay, so we'll get into the five quick questions to get to know the guests better. The first question is the aha moment question. You you moved from deep infrastructure and identity engineering and places like teleport to founding CRS, as you said. What exact moment was it that you realized that you had you had to build a solution of TPR for yourself?
SPEAKER_02The aha moment was not like one moment. Like, but they have spreadsheets and SIGs, SOC2, all this, uh just to understand a vendor, which was not right to me. Uh, because they they have the vendors, as you said, they are they are giving uh so much scrutiny on the internal uh people, like, but they're not doing enough scrutiny on the vendors. Just questionnaires is not enough. Like, there is so much needs to be done there. And questionnaires becomes the control, which was not acceptable. That's why I started this company.
SPEAKER_00Good, good. Well, I'm glad you had that aha moment, by the way. That's great. We need more, we need more folks like you who are thinking about solutions in the in this space as opposed to just another product that that just you know turns turns over. It's it's great to see. On overrated best practices, having lived and breathed zero trust for years, what is one widely accepted best practice for security or compliance norm that you think is actually a distraction? So what's what people are waving their arms around that actually doesn't do anywhere?
SPEAKER_02I mean, uh I think treating a clean SOC2 as it's the lowest inherent risk. And if a vendor processes sensitive information like PIA or has privileged access, then inherent exposure is high no matter how pretty the report is. So it like thinking it's all with a vendor and uh treating the vendor risk based on the vendor reports and not understanding the use case how it's getting used, that's a uh problem. I think thinking vetting the vendors as a best practice doesn't solve much.
SPEAKER_00Yeah, yeah, yeah. All right, so the founder shift is the third question here. Uh you we had a transition come from a technical hands-on expect to run the startup as a CEO. What was the steepest uh learning curve for you?
SPEAKER_02I think uh the steepest founder shift was going from I can fix the architecture to I can fix the workflows and how the organization works today. I think EPRM is a multi-stakeholder problem. Having said that, like it involves like security, procurement, legal, privacy, and
The SOC 2 Comfort Trap
SPEAKER_02also the business who's actually using the product, uh, it touches the vendor, it touches all part of it during this process. And you have to better sell a best decision and not a better control here. So bringing all of them in in this particular line over, like let's make sure it's cybersecurity oriented, not just yeah, control oriented. That's where uh yeah.
SPEAKER_00Yeah, yeah. Signal versus noise in AI. With every uh security vendor slapping AI native onto their platform, kind of like Intel inside now, it's AI inside. But what is the one genius, uh genuine problem that AI solves in vendor risk management today that works is uh what is purely marketing tough?
SPEAKER_02I mean, honestly, uh I'm I've been in touch with like 300 organizations today, like uh as part of uh after I started this company. Nobody uh just wakes up from TPRM and says, I want an AI agent, right? Out of filling the same 400 questions from is marketing. What AI can do today is like gathering and correlating context uh so a human can make a defensible decision. I think there is a very big difference in the dastric difference between the marketing uh language today with AI agents and what the agents can actually solve. It's not about generating answers for questionnaires or uh summarizing a documentation, it's way beyond that. There is a lot of uh context that organizations carry in their human brain that needs to be brought into a single platform. That is where we uh differ from the marketing flow.
SPEAKER_00Yeah. Well, and I like the correlation call out because that that was the challenge in prior to AI abilities was was doing correlation. I used BI tools, and it can be really challenging sometimes to correlate. But AI just is is just better at it because of the
What AI Actually Solves
SPEAKER_00data, the the math and data scale. Exactly. Yeah. How many documents you can correlate on your brain? Well, exactly. And then also when I did it with VI tools back in the day, um, it was a challenge building that infrastructure. A lot of the tools, like like yours and others, out of the box, it has these things sort of built in, the reporting, all that kind of stuff. So that that's where I think AI really shines, and it really does give you the ability to focus in on what's important as opposed to trying to spread yourself out like chunky peanut butter, which just doesn't work very well.
SPEAKER_01Yep. Yep.
SPEAKER_00Thank you, Navantan, for for helping us out with that. The the first is the hook question is questionnaire fatigue, right? This is the we mentioned questionnaires in the beginning. Uh, why do static first questionnaires give a false sense of security? And what does it take to shift the industry from a passive compliance review to contextural vendor intelligence, which is really kind of where your system your system sits.
SPEAKER_02I think the questionnaire can't tell you whether a control exists today. It can just do a check mark on it. It it cannot tell you
Why Questionnaires Mislead
SPEAKER_02whether the control is sufficient for this vendor. It can just say the control is there or not. This data is that like you you need to have like context and the data around like how a particular vendor is getting utilized, not just about like asking all the questions to the vendor and answering this. There is a lot of back and forth correlation between how it's getting used and then how the security posture looks for that specific use case. Take for example a marketing analytics tool. One company can use it to like just like anonymize data that can flow into that analytics tool. Another company can use the same tools and to send PIA data along with the PIA data. And the risk is drastically different between those two use cases. That's where the challenge is. The said security questionnaire doesn't solve you anything there, like it solves only the outside whatever the answers that's provided by the vendor, but the problem is inside, right? The organization.
SPEAKER_00Another example is this FOC2 says nothing about AI risk about a vendor. It just doesn't address it at all right now. There's no, there's really nothing in there in the AI's FOC2s that I can see this as this is a low-risk AI vendor or a high-risk AI vendor because they've not tuned to FOC2s to address that risk yet, to some extent, right?
SPEAKER_02Yeah, exactly. I think like the shifter is like simple. Like stop asking is the vendor secure today. Ask oh, am I using that vendor? And those use cases are secure or not. That is that is where the context matters today. It's not about just the raw data, but like how correlate the data and tell me like what is the context around and use case of a vendor.
SPEAKER_00Yeah, I'd agree. I would say to add to that, is to say if if you're looking at your vendor pool, it's not necessarily the vendor that's really has all the most data. It may be the vendors that how they're using the data, where where the data is located. There's all of this context that Manton's mentioning that has that are pieces to that puzzle. And if you're just if you're just looking at one piece of all that, you're not getting full context. You're not gonna understand. One of the other people I've talked to recently said talked about dependencies, right? You gotta start mapping out dependencies and understanding where some of these things are dependent on each other, too, because that's another issue that we're running into here a lot a lot, right? Yeah. Okay, so um big question number one is um AI native uh third-party risk management versus contextual assurance. So AI native versus CPRM contextual assurance. Um focuses really on how is AI actually transforming third-party risk beyond just automated form filling, right? We it certainly takes away some of the drudgery. But you know, how does CQRS deliver that continuous contextual risk insights for the aesthetic uh audit scores? And then just expand on that.
SPEAKER_02Like the the the AI fills the form. It's it's good, but it's still uh a form that's getting fit. But the real transformation is collecting the context. The context, if you see, is scattered across questionnaires, documents, contracts, and then email thread that happens between the vendor and the customer, and your procurement systems, and the different stakeholders in this process procurement, compliance, cybersecurity teams, uh business teams who are using the product. So having all these different uh contexts from different places and bringing them together to a one place is going to be uh a big, big unblocker
Turning Alerts Into Priorities
SPEAKER_02for the third party risk teams because it's it's so much that these teams are carrying in their human brain today, and that needs to be brought in. So that is where the AI will help us and the agents will help us. Think about this like uh you are having a conversation when you are onboarding a vendor on Slack. Where does that data go? It just stays in the Slack. All right. What you are having a conversation in a meeting, you are able to only capture 10% of the meeting where the risks are captured. So you're not able to get that data. So that is where the AI will shine, getting all the context into one place. Yeah, that's the extraction, mapping, and monitoring all together. Right? And I agree. What is like the noise and what is needs to be avoided, what is the use case?
SPEAKER_00Well, yeah, let's let's talk about noise here. So, you know, when when you're analyzing these vendors, how do you separate operational signal from noise so the risk teams don't get alert fatigue? All the shiny bright lights can become a bit fatiguing after a while. Which ones, you know, which ones we focus on?
SPEAKER_02I think I think exactly like that there is so much noise. Like if you see the signal uh providers, there is so much alerts that that that that pops up today, and nobody knows what to do on that those alerts. Like, okay, the there is alert. But how that vendor is getting used, that can help us to answer that question, what we need to do when an alert pops in. Like if the vendor is uh purely uh for marketing, there is no PI involved or PHI involved, no sensitive data, okay, that's that we can deprioritize that. And then there is PI involved or PHI involved, and a highly critical vendor can't go uh down, or like it's uh the availability should be all nines, then yeah, then uh it's super critical. Like we have to take action on that immediately. The priority goes up. So that is where AI shines today, and that is what the real agents are capable of today. Just filling the cushioners.
SPEAKER_00Yeah, I I I build on your contextual and prioritization issue, right? In a lot of the classified teams, I always say the term risk-based approach wait way more often than probably students care to hear. But it it is important, and and and products like yours will will help with that because the noise becomes noise after a while if you're not if you're not careful about what your personal pay attention to. We talk about this. You know, what are your most valuable assets? What are your crown jewels? What do you want to protect? And those are the things that you focus on, making sure that they're not that you can prevent a breach, but that at least if there is a breach, that they're protected and and they aren't they are pilfered or or or or or destroyed or or damaged.
SPEAKER_02Right. Exactly. I mean, there is a balance between like how much rigorous you have to be for security at the same time. You don't need to be a blocker for anyone. Right. Like you need to know where to prioritize and deprioritize. Today that's yeah, I can take it over. Like, why we need to bother about it? And and it give you a more highly citable way so it knows the actual data and like gives you a very strong recommendation sound.
SPEAKER_00Yeah, yeah, agree. All right, moving on to big question number two, and and again, Sonya, you and I are both really familiar with zero
Zero Trust For Third Parties
SPEAKER_00trust, because it is the only real strategy that that most of it that is known today to really reduce your risk of impact from a breach. It won't prevent a breach, but it will reduce the impact of a breach. Zero trust means vendor risk. I wanted to give people because I really think you should look at zero trust for your third-party risk. Drawing on your identity and cloud security background and about that, how should zero trust principles like privileged access management, just for time access be applied to third-party integrations and SASP for all? That's a lot to deal with. You lived and breathed this as an engineer for a while.
SPEAKER_02Yeah. Um, so zero trust is also like very close to my heart uh because that's one super robust strategy in cybersecurity, and practice needs to be practiced by every single organization in the world and the planet. No, no doubt about it. So, in when it comes to third party and zero trust, like what zero trust means, like no standing privilege access on the SAS crawl that you mentioned, no, no, and and no credentials shared, no, no passwords, like getting away from passwords and anything that is shareable, it's it's the best one. And definitely identity bound sessions, making sure who was identity uh whose identity is for login and uh for vendor specifically, but uh in uh in accessing those vendors today, like the SaaS uh vendors, or like even some privileged access is needed for databases and uh virtual missions, uh all that comes under the zero trust. When it comes to third parties, some of the SaaS is also still third parties, right? Like we are uh the the same principle can be applied for like how we are vetting those vendors, right? That is where the continuous assessment comes in. Like when we are continuous authorization is in part of zero trust where we authorize an individual, whether they can access it or not, based on like just in time access. Like, okay, can I give them access for a critical database? Not all the time. The similarly, we can do a continuous assessment on the vendor today with AI. Like that is where the key is. Like, can we continuously assess? Because you you have approved a vendor today, they are through a procurement. When are we going through an assessment next? Their next anniversary date.
SPEAKER_01No, it that we can't wait for their next anniversary date. Yeah.
SPEAKER_00You don't check on your partner once a year, you you see them every day and say how are you doing, right? Yeah. Exactly. Think of it, think of it as yourself like a doctor. You're not gonna just see your patient once a year, you're gonna check on your patient at least once a day, hopefully do rounds, you know, check and see if they're still alive, right?
SPEAKER_02Yeah, exactly. So I I would uh say like the continuously checking what has materially changed with the vendor. The vendor can swap their subprocessor with something that's not acceptable. Today people start some open source models, that's not uh uh that's not good. So those are should be like contextually analyzing and quickly assessing those vendors as needed today. And it's humanly impossible to do it if you're doing it manually. That's that's the sad part. That's the sad part. But the good part is yeah, I can help with that.
SPEAKER_00Well, and and by the way, regulators will not be happy with a manual process. They will they will require you to have an automated process workflow because they will they will know that if you have a manual workflow, you're not following it consistently because it's manual.
SPEAKER_01Yep, agreed.
SPEAKER_00Yeah, yeah, yeah. On a follow-up to that, what's the biggest misstep enterprises make when granting third-party vendors infrastructure data access?
SPEAKER_02I think like what what happens today is they they have basically uh given approval for that vendor. But what changes after that, when they were doing assessment, the internal use case is to just use it to let's say like a marketing email was sent over that email provider, uh, but today they are sending PHI information in a healthcare company, which drastically changes. So the internally how they are using it should be also monitored, monitored, not just like externally on the vendor, how what is their risk posture. Their risk posture is basically only 20% of the risk. The risk posture is like how we are getting used, what are the knobs and the uh that we are turning on, turning off. That matters a lot.
SPEAKER_00It does. And and that's again, it's it's a contextual issue. It also speaks to the continuous monitoring and assessing what a vendor is doing. And what you're talking about is that vendor relationships grow organically usually. They don't grow. And oftentimes, if you are looking at a vendor relationship from the start when it was initiated to what it is now, years or even six months later, those often are different because you found new uses for the vendor, you didn't think about when you first engaged. And how many times does the business come back and say, hey, wait, we've got to tell you we're doing that something different now? They they almost never do that because they're too busy doing their business. So you're right. It's it's it's important. Use tools to find that. There, there are certainly uh ways to do that, automated processes to assess that you're on. We're gonna wrap up with the Threat Hunter's debrief
Build A 10 Vendor Context Graph
SPEAKER_00and ask you, uh, for what's the one practical step a risk for secure leader can do to eliminate questionnaire bottlenecks and implement continuous vendor risk monitoring?
SPEAKER_02I think with with continuous monitoring and the continuously uh contextualizing, I would say forget about picking up a platform. One practical step would be this week, or like take a week, take 10 vendors, more critical ones. And for each, write a one paragraph, what they do, what they can access, like what they touch internally, like what kind of data, who have access to that particular vendor? And uh what happens if they fail? And then that's a context graph.
SPEAKER_00That's a great that's a great question, by the way, that nobody asks enough, right? What happens with that vendor when they run a business? Because yeah, and if it's a critical vendor, that that's a that's a really really good resiliency question, right?
SPEAKER_02Exactly. Yeah. I mean, but well also remove the vendor pedigree from there. We know what happened when CrowdStrike had an endpoint bug, right? And airlines halted for at the moment. I was trying to check into a hotel and couldn't check in. Yeah. Even I was in the boat, like trying to uh board a plane and I was on the terminal for like a whole day.
SPEAKER_00Really? I see, yeah, I see. And I mean so you and I were traveling today and we're affected by it. And and you look at AWS outage, you know, was that last year where you know the whole internet seemed to break just because one one data center in the US East went went went went off offline for a little bit and everything just kind of went bonkers.
SPEAKER_02Exactly. Like that there are so many trusts that go into it. So try to model it. Try to model this with just pen and paper and try to bring that. That is the context graph. And how much you can do on this 10 vendors, try to do that, and then from there, ask 20 questions that matches their use cases. What happens when a subprocessor changes? Is that going to affect their use case and model that with your use case? That will be a good place where you'll be able to see what level of risk that goes through. And in this whole process, don't bring questionnaires, don't bring any any any of your controls, just like check marking controls. You need controls, but more context is needed along, right?
SPEAKER_00You can take the context now and apply the controls over it and see what how you feel about it. But the contact, but the controls without the context are are just they're just paper. Yeah, exactly. I get your point. That's an exact excellent point.
SPEAKER_02Exactly. And and here, this is exactly where AI is useful. It gathers the context and it also models the risk for you. So you know what decisions to take on top of that. What how can I make that vendor obligated? I can make them obligated. And then what what what kind of compensating control can I have since I'm taking this risk? Definitely we are taking risk by onboarding every single vendor. So, what compensating control is needed? So, those are the things. Like I would suggest everyone to do that uh after this podcast and try how that looks. That will tell you uh what is needed next.
SPEAKER_00Yeah, yeah. I I agree. And and and and 10 is a reasonable number, even if you get thousands of vendors, that's a it's a number most people can get their head around. Let's say you have more than 10 critical vendors, then do 10 this week and do the next 10 the other week and and so forth, and get yourself kind of your universe of critical vendors understood and mapped out. And I think you I would sleep better at night knowing that. At least you you kind of know what the how the depth of the pool is, right, as opposed to it's just deep, which isn't helpful.
SPEAKER_01Yeah. Yes, I agree. Okay.
SPEAKER_00Well, that was a great uh rundown. I uh really it was great meeting you uh on the podcast. So thanks for being agreeing to be a guest about uh we'll uh we'll include some links to to Secure OS as well as uh ways to get in touch. And uh we'll look for uh the next guest on the podcast, Third Party Threaten Arts Podcast. Please subscribe and uh I'll look for more updates. Thanks a lot. Thank you so much, Greg.
SPEAKER_02Thanks for having me.