Third Party Threat Hunters

Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS

• Gregory Rasner • Season 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 23:25

Send us Fan Mail

Vendor risk programs fail in a predictable way: we obsess over forms, feel good about a clean SOC 2, and then act surprised when a “trusted” third party becomes the fastest path to sensitive data or operational outage. Greg sits down with Nivedan, co-founder and CEO of SecureOS, to unpack why traditional third-party risk management (TPRM) and EPRM workflows often measure the wrong thing and miss what matters most: the context of how your business uses a vendor.

We dig into questionnaire fatigue and the trap of treating checklists as controls. A static security questionnaire can’t tell you whether a control exists today, whether it’s sufficient for your specific integration, or whether your internal use case has quietly drifted since onboarding. We walk through concrete examples like marketing analytics tools that are low risk with anonymized data but high risk when fed PII or tied to business critical operations. The takeaway is a simple shift: stop asking “is the vendor secure” and start asking “are our use cases secure.”

Then we get practical about AI in cybersecurity and vendor risk management. Forget the hype about AI agents auto-filling 400 questions. The real value is correlation: pulling context scattered across contracts, documentation, procurement systems, emails, and Slack into one place so a human can make a defensible decision and prioritize the right actions. We also connect third-party risk to zero trust, covering privileged access management, identity-bound sessions, and just-in-time access, plus why continuous assessment matters far more than an annual review.

If you want a step you can take this week, we share a lightweight “context graph” exercise for your 10 most critical vendors that clarifies data access, dependencies, and what happens if a vendor fails. Subscribe, share this with a teammate in security or procurement, and leave a review with your biggest vendor risk blind spot.

Support the show