Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Treat Vendors As Part Of The Enterprise with Julie Giaischi
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction.
We dig into a core myth that still drives bad decisions: scaling third-party risk management based on the number of vendors. Julie explains why mature TPRM scales by risk and strategic impact, not raw volume, and why soft skills like communication and relationship building become even more critical as AI changes what “doing the work” looks like. We also unpack why standardized questionnaires can create assessment fatigue when they’re treated as a checkbox, and how evidence-based testing and continuous monitoring better reflect the real control environment.
From there, we get practical about the future: AI-powered vendor risk tools, trust portals, and the move toward near real-time assurance that can become predictive, not just reactive. We also address the governance side of AI, including the risk of feeding vendor data into frontier AI when contracts and confidentiality rules say you cannot. Finally, we break down nth-party and fourth-party supply chain risk, including a simple set of questions to identify which sub-tier providers are truly material, plus how to translate benchmarks and risk metrics into board-level messaging that supports budget and action.
If you found this useful, subscribe, share it with a risk leader who is drowning in questionnaires, and leave a review with your biggest TPRM challenge.
Welcome And Guest Background
SPEAKER_00Hello, welcome to another edition of Third Party Threateners Podcast. Today I have a special guest, Julie Gyowski, a friend and colleague of mine for a number of years now, and is the co-founder and CEO of the Third Party Risk Association. Julie, as I usually do, I'll let the guests uh expand on their introductions themselves. So please feel free.
SPEAKER_02Thank you, and thanks for having me. I really appreciate all of your support and also what you're doing with your podcast. I think it's great. And thanks for having me on. So, as Greg said, Julie Gayowski, I am the CEO and co-founder of the Third Party Risk Association. Prior to that role, I was an IT auditor for 10 plus years. And then I went into security and started a third-party security program for a large health care organization. And as I was doing that, I thought, well, I want to benchmark. I don't want to recreate the will. So let's see what's out there. Let's see what's available. And not much was. So with one of my former colleagues, we started a professional association called Third Party Risk Association in 2018, launched in 2019. I didn't move full-time to that in 2019. I actually was a third-party officer for a large bank. I wanted to learn the finance industry. And in 2022, moved full-time to TPRA, and here I am.
SPEAKER_00And for full disclosure, uh Julie and I have worked together for a number of years now and in fact taught classes together through Thurprenders Association. And it's one of the reasons why I like Hibernators the Guest, because I know she knows a lot. And so we can usually just all I learn a lot from her. And so she'll also usually pull in a lot of guests who learn a lot. So with that,
Five Fast Questions On TPRM
SPEAKER_00let's get started. We'll ask the five quick questions we usually ask to get to know the guests better. So the first one for you is what is the one major myth enterprise leaders still believe about scaling a third-party risk management program?
SPEAKER_02Yeah, I think this is a great question. Um I think the myth is that you should scale based on the number of vendors that you have. I don't think that's an accurate reflection of risk. I think you should take account of the regulations that you have to comply with, the strategy your business is really working towards, the impact third parties can have on your organization, and base scaling on risk and impact. So maybe you have thousands of vendors, but half of them are marketing lower risk vendors that you don't really need to do much with. So it really should depend on level of risk and strategic impact to your organization.
SPEAKER_00Perfect. Yeah, well said. So uh next is standard standardization versus customization. Are standardized questionnaires making third-party risk management better or just creating assessment fatigue?
SPEAKER_02Yes, the other questionnaire, my favorite, also my favorite, uh not really. So I'm gonna I'm gonna let's look at the questionnaire as it was meant to be, always meant to be, which is a control framework. So if you are using your questionnaire as more of a compliance activity, a check the box activity, you're not really using it the way it was intended. So questionnaires are supposedly control frameworks. They're supposed to be based on control frameworks, and really you are trying to understand the control environment of your third party. And so while they're helpful in understanding that part, they don't always show you what is happening in real life. So I think we are moving towards more evidence-based testing, which is the way it should have always been, with you know, AI coming into play a lot more. And I'm sure we'll talk about that. So I don't want to, I don't want to give too much there, but I think yes, questionnaires create fatigue. We should only be asking questions we really want the answers to, because if you ask too many, it's a liability to you because you have to do something with it and turn that back into a control framework.
SPEAKER_00Very well, so yeah. Um, all right, well, keep it keeping the bowl moving. I want to go on with that one, but uh, but you're right, we need to keep moving. What is the most underrated skill a modern third-party risk practitioner needs today?
SPEAKER_02Yeah. Uh soft skills, relationship building, communication, oral and written communication is still number one. And it's gonna be even more important with the enhancements AI is making to the industry because you won't be required to be such a subject matter expert anymore, but you will be required to really look at the results and understand the risk and have meaningful conversations with third parties, with your key stakeholders, with your business a lot more. So I think this skill in particular is just gonna grow in importance.
SPEAKER_00Excellent. Well, and I think frankly, it's the it's a skill that sometimes people can spit by on emails and stuff and not interact. I think this will hopefully uh give people uh the ability to do that more and do that less often and engage with their vendors. All right. I'll stop, I'll stop, get enough the soapbox. This is supposed to be about the guests. What is uh all right, in one sentence, how do you define a mature third-party risk management culture, Julie?
SPEAKER_02I would say instead of looking at it like third-party risk management, look at it like the extended risk management of your enterprise.
SPEAKER_00Oh, yes, excellent.
SPEAKER_02Yes, for third-party risk management, again, is not a siloed activity. It is an enterprise-wide activity. So the more you can integrate pieces and parts of it into your business, the more effective it will be.
SPEAKER_00Yep, yep. Excellent. And what is your this is the fun question, what's your favorite way to unwind when you're not building resources for thousands of third-party risk professionals?
SPEAKER_02I have two. So I I actually love to cook. I I am uh I've always loved to cook, particularly Italian. And if you know me, you know my husband's Italian, so there's a lot of going to Italy. That works. Yeah. I also like to golf. I'm not good. I'm not a good golfer, but uh I actually recently picked it up and it's totally fun. So okay.
SPEAKER_00And and so do you live near a quarters where you get to play often? Or of course, so that makes it even easier. All right, well, thanks for sharing your air those those five minutes. We'll get into the hoop start, which is just a way to kind of uh get into a really topical subject right away.
Questionnaire Fatigue And Compliance Theater
SPEAKER_00And this one's about practitioner burnout and questionnaire fatigue uh paradox. Security and GRC teams are drowning in thousands of multi-page questionnaires, and vendors are overwhelmed trying to answer them. Yet despite all this pit work, third-party breaches continue to hit record highs. How do committee leaders and practitioners break the cycle of sort of this compliance theater to focus on real threat hunting and risk reduction? What's those what's some of the magic sauce from that, do you think, Julie?
SPEAKER_02Yeah. So I think we should look at some of the challenges that we're facing today to understand how we can break some of these cycles or silos. So one of the biggest issues with third-party risk management is resources versus scale. So there's a big issue with having enough resources to actually do the work. And not only that, but board members, executives, regulators are asking us to do more than cyber. So it is including financial reviews, environmental social governance, operational resilience is huge this year. Um, so there's quite a bit, and it's really hard for us to scale our work. So not only that, but the other challenge is data overload. There's so much data now that we have access to, it's really hard to put it into a meaningful way so that we can better explain to the business what the risk is. So I think there's this is also because you know, third-party risk management was a compliance activity. It's kind of fragmented our our approach within our organizations. So a lot of companies think third-party risk management is one department, but it's not. It's procurement, it's legal, it's compliance, it's security. And so I think what will really help is if we come together as an organization and say third-party risk management is everyone's concern, it's everyone's risk, it's the biggest risk to the enterprise. And if you have an enterprise risk management team, they should have already found that and come together on a better approach for addressing risk. That means CISOs need to be talking to third-party risk teams more, engaging them in incident response activities, tabletop exercises need to include third parties. We really need to start at home to address some of the challenges.
SPEAKER_00You you know, you you raised the nice point. I mean, I teach the cyber course, but the the issue is with just cyber risk and third party risk. Every department engages with with with third parties and vendors, and and and there's not just cyber risk associated with this. Um as you said, financial uh and and and and I think we get focused on the cyber stuff, and and I'm I love it because it's it is it is important, but it isn't the only risk we to the organization. And especially if you if you're uh an area that's concerned about nth party issues, you can get even you can get even wider after, right, Julia? I that's that's just some excellent points. Uh I I I like the focus too, getting away from I getting there there when you said a dichotomy or it's it's sort of diverged, are you referring to that like there's still the compliance theater in some organizations like like in like in finance, for example, it you still kind of have to do that, those, those things. But there's also, and you can even see it within some organizations, there's a team that's doing the sort of the real what you and I are describing, which is actually looking for risks and trying to close them, right? That's what that's yeah, okay. That's what I thought you were referring to.
SPEAKER_02You know, implementing a program. So until companies better understand that this is needed and it's not just to appease regulators, you still will have that, some of those compliance aspects.
SPEAKER_00Yeah, yeah. So that's a valid point. You're right. Until folks realize this is, and you made it the reference earlier that you know vendors are an extension of an enterprise. And so if when you treat them like that, then it becomes a natural extension of defending that enterprise. And so you work with your vendors to do. Yeah, excellent. All right, we'll get into big question number
Community Pain Points And Breaking Silos
SPEAKER_00one. This is community insights and uh elevated and the third-party risk management profession. Again, one of the things I like about Juliana and is in her role is she gets to meet with a lot of leadership and interactive. So we I can really pick her brain on some of these things that I don't normally get to talk to her about when we just are meeting for business. So the core topic here is things like key trends, operational benchmarks, bridging the gap between GRC procurement and cybersecurity. Uh, first question out the gate for this one is with thousands of risk leaders in the third party risk association community, what are the biggest operational pain points your practitioners are are voicing right now?
SPEAKER_02Yeah. You know, there's a lot. Uh we ask this question at the loudest. Yeah. Yeah, yeah, the loudest. And we ask this question every year, actually, in our year-end survey. And um, this is the most responded to question. We get thousands of responses. But I would say right now, it's just again, that resource versus scale. But really the AI piece is a big one. And it's not um, you know, how to really to assess in third-party networks, although that that is um a question, but I think practitioners are getting their hands around that more because they have the assessments, you know, they've already included some language in the contract. I think where they're getting stuck is implementing AI within their own environments. And that's kind of a corporate issue because that piece is getting stuck at the paperwork level where they're still trying to wrap their head around what what they want, what they will and will not allow AI to do.
SPEAKER_01How they will allow.
SPEAKER_02Yeah. So there's a lot that AI can help with. Again, it is also a risk, but I think with the advancement of AI, and we need just need to assume all third parties are using AI, you you won't be able to mature, manage, or even operate a third-party risk management program without this type of automation. It's just too much. Um with what we're being asked to do, it's yeah, it's impossible.
SPEAKER_00Well, and I've I've spoken recently to some other folks and there's a regulators are expecting automation. If if they if they see you do it manually, they're gonna think that you're just not doing it.
SPEAKER_02Yeah, and with that though, comes uh addressing some other challenges that I've seen, which is nth-party risk.
SPEAKER_00Oh, let's go, keep going.
SPEAKER_02Yeah, with in-party in-party risk, which I think we're gonna talk about uh yeah, you're right.
SPEAKER_00And the next in the next uh yeah, yeah. So hold your fire, sorry about that.
SPEAKER_02Yeah.
SPEAKER_00All right, that but let's get to the next question. And this in the big question number one is how are high performing organizations successfully breaking down those silos between cybersecurity procurement and risk management? We talked about that this file uh it is this filos. How do you see what organizations are doing right? How do they do it?
SPEAKER_02When they're working together, and I know that's simple, but not really it it absolutely it's not simple to do. It's probably just more simple to say, but there are some companies that are really understanding this is an enterprise-wide activity and leaning into that and uh having that top-down approach. And um, I'm starting to see more teams come to even our events. So it's not just vendor management or or third party waste management, it's their legal teams, their procurement teams, their security teams. And I'm so excited when security comes too, because they should have been there all along, right?
SPEAKER_01They're much factor, uh sometimes they get a little too focused internally.
SPEAKER_00Yeah, you're right. Yeah, yeah, yeah. Oh, believe me, I had the discussions when I first started on Roll 8. How are you gonna get third parties to do anything, right? Because I was, you know, I didn't, I never did. Believe me, you can do it. It's it's it in works. That's those are good ones. And you you mentioned two top-downs. So I I I was gonna ask that. I I would assume that the ones that are successful are the ones where the leadership says, we need to get this done, work together, figure it out.
SPEAKER_01Probably, right?
SPEAKER_00Yeah, yeah, yeah. All right. Now the last question on this one is uh what are the most effective ways that third-party experience programs shift from being viewed as a cost-centered bottleneck to a strategic business enabling blur? That's a common one because our teams usually are resource constrained, and we're fighting, we seem like we're fighting the constant battle to you know keep resources and money coming flowing in. What how how do successful teams do that?
SPEAKER_02Yeah, it's it's not easy either, but it's moving from that compliance activity to making it more of a strategic activity. So, meaning you're really aligning your business outcomes to the program. You're allowed the growth, the innovation, the speed at which business is being done. Um, you're aligning it and you're growing you're maturing your program in line with it because that then allows you to one, not become the bottleneck, but two, to actively drive decisions, to allow your business to actively drive decisions. So the risk tiering is in line with um innovation and business objectives. You're embedded in various departments. So procurement, legal security, they all understand their role that they have to play in it. Decisions are enabled versus like a control, like you're just not looking at controls and if they're effective, but you're enabling decisions. You're looking at this as being an enabler. So you're providing clear risk uh insights, whether that be through metrics and reporting or or however, and allowing the business to take that information, ingest it, and really use it. So moving from more reactive to proactive and eventually predictive.
SPEAKER_00You're showing your work. You're showing that you're actually finding risk and yeah, the value, right? Because if you if you are viewed as just a cost center, then that's a cost center that can be looked at in a fairly negative way, unfortunately, for you. So that's great. You're right. And we uh we do talk about that a lot, Julie, in the classrooms that we do and other stuff.
SPEAKER_02But when we're recording sections, part of that, you really have to change your language. You have to instead very well done this, you're changing it to say, we are helping you. TPRM is a service, and we are ensuring that the risk of the you know being in a relationship with this third party is reduced. And, you know, it's a requirement, yes, of the company and maybe even due to regulators, but honestly, it's just good practice. It's make sure that we don't have reputational damage, that we're not gonna go under financially, that we are gonna have strong security controls, that that third party isn't the weakest link. So making it more of a benefit and a value, even in the way you market your program, can be I agree, I agree.
SPEAKER_00All right, moving on to big question number two.
AI Tools And Nth Party Governance
SPEAKER_00We're right on time here. The future of third party risk management standards, AI and nth party governance. That's where the nth party was coming in. And then the core topic there is talking about adapting industry frameworks for continuous monitoring, fourth party visibility, and AI adoption. The first question here is as member organizations grapple with fourth nth party supply chain dependencies, what strategies are prove proving the most effective or realistic for tracking hidden sub-tier risk?
SPEAKER_02Yeah, I think tools are helping a lot with this now. There's tools that uh will do nth party discovery. So you give them a list of your third parties and they can look for downstream, upstream um relationships. And not only that, but these tools can also tell you if there's geopolitical issues or um if there's uh you know tariffs or some other kind of regulation that you know you need to be aware of, or that you know, data resides there. And some of them even tell you if they're using AI. So the tools are getting a lot better. If you are not using a tool that does that, though, because we get the nth party question quite a bit. What I do is I say you need to focus on your higher-risk third parties, so your critical, your highs. You need to make sure you're only focused on material nth parties, so not every you know, nth party, because then you're just focusing on nth parties. And the way that you focus on material is you ask four questions. You ask, will they have will the nth party have access to my data or house it? Will they have direct or indirect contact with customers? Is there any regulatory impact or and or will they now forget the last one, impact with customers, impact, oh yeah, will they be providing a product or service that is material to what I'm receiving from my third party? Meaning, is it critical? So if one of those is a yes, then they may need to be on your list. Now, from an evaluation perspective, there's really only two things, maybe three things you can do. One, you can evaluate your third party's third-party risk management program. You can ask if they've evaluated that specific nth party and if there's any findings and if they were, you know, cleared or or improved upon. The second thing you can do is if you have leverage with your third party and they are more collaborative, you can work with them to have the nth party complete your assessment, give you the evidence you need and complete your assessment. I have done that before.
SPEAKER_00I've done it as myself as well. Yep.
SPEAKER_02Yep, yep. So it does work. And then the last way is to use the tools that you have. So continuous monitoring tools, risk intelligence tools, news alerts, things like that, whatever you have at your disposal to help continuously monitor.
SPEAKER_00I agree. That's great. How is rapid adoption of AI vendor tools, speaking of vendor tools, uh forcing a redesign of assessment frameworks and best practices? Because I do see that as well. I wonder what you're seeing in the in the space.
SPEAKER_02Yeah, I think what we're really seeing with regards to AI is more proactive risk management. So what what these tools are, what the enhancements to TPRM are really doing is taking that assessment, the questionnaire, turning it back into a control framework, obtaining near real-time information from third parties. And by the way, a lot of third parties are also creating trust portals to help with this. We've heard about those. Yep.
SPEAKER_00We'll talk about that at the end here a little bit. I will we'll we'll pick that that back up with some of the stuff that your your organization is doing on this.
SPEAKER_02Because we just created the trust portal guys. Yeah, yeah.
SPEAKER_00Yeah.
SPEAKER_02So taking that information, evidence-based information, and correlating it to the control frameworks to look for real risk instead of just implied risk. And not only that, but they can also now uh take the information and compare it, the internal network information and compare it to external threats, to say you are more or less likely to have an incident because you're vulnerable to an existing threat. So it's getting more predictive as well. So I think we're just gonna see more and more advancement in that area, especially with a gentic AI, where it won't only just find things, it will do things. So it will start to improve workflows, it will start to improve policies.
SPEAKER_00That's great.
SPEAKER_02Yeah.
SPEAKER_00I I I this is where I it's it's nice that the tools are finally doing what give us the ability to do what we should have been doing all along, which was fret hunting as opposed to compliance hunting, which you know didn't get us anywhere. Uh I love it. So yeah, I I see the same thing as well. I I see people, the paperwork's still flying around, but it's being used in different ways now, right? Um because the because AI can take uh data and math at scale, it really is able to just say, okay, fine, give me all that stuff and I'll I'll here's the answer, right? And anyway, so I love it.
SPEAKER_02I'll just say there is a risk with this as well, because I have seen an increased number of practitioners use frontier AI to ingest data instead of using it.
SPEAKER_00Yeah, yeah. I'm sorry, Julie, you're right. You're gonna talk about the people that are using frontier. Really?
SPEAKER_02Yeah, yeah. Oh, a lot. A lot. Uh, be careful of that because you might have contracts in place that where the vendors have said my information won't go in AI. So Even if it's tools or frontier. So just be mindful of that.
SPEAKER_00Yeah, yeah. I would I I'm sorry, I I just to me that's sort of like uh stepping on the third rail in front of the metro. I just wouldn't think about doing it. So when you said somebody to it, why would you do that? Yeah, of course we are. Yeah, that's a great I didn't think about even doing that. I I yeah. Uh all right. How can risk executives effectively translate community benchmarks from risk metrics into board level messaging? This was a good one for you, I think.
SPEAKER_02Yeah, and I think this is I think more companies should do this, honestly. I don't think we benchmark enough. I think we actually have resources available on the TPR website from our service provider members. So our service providers, who are the backbones of our you know, companies, the TPRM tools, the GRC tools, they do annual surveys where they're asking about risk domains you cover or new technology that you might use or the functionality of it or budgets or you know how big your teams are or where they exist. And I think you could use, and we have the survey responses on our website and using that information, really reviewing it, using it, can help shape conversations with your executives and your board to really explain not only where you're at, but where others are at in your industry. And that can help with budgeting, that can help with increased innovation, because if you're just sharing where you're at and you don't know where others are at within your industry and also outside of your industry, it's not going to show the full picture of what is possible. So benchmarking with where you're at with a maturity model. And by the way, TPRA just released a free maturity model, and that is in line with our guidebook. If you're interested, you can just download it. Congratulations. I think you can see that.
SPEAKER_00Those are an easy thing to do, Julius, for congratulations on that.
SPEAKER_02Thank you. Yeah. And then uh so that's the benchmarking piece. And then with regards to um risk metrics, I think we've been doing this. If you are reporting to your board, some programs still are not reporting to their board. I think it should be a requirement because it is an enterprise risk. But some of the things that you can really start to look at aren't just how many assessments you do, but it's also looking at emerging risks and how they're a threat to you based on the information that you have. So looking more predictively at things coming and where you're at as a program.
SPEAKER_00Yeah, I agree.
SPEAKER_02A good overview.
SPEAKER_00Let's do the after-action report
After Action Steps To Automate
SPEAKER_00then. So um, for those who stayed through this whole thing or skip through the chapters and stayed for this part, we always do one what's one immediate tactical step a third-party risk management or security risk leader can take this week to automate vendor risk monitoring or reduce manual overhead, Julie.
SPEAKER_02Mm-hmm. Yeah, I I have a few things to note here.
SPEAKER_00Please more than one slide.
SPEAKER_02Yeah. Mm-hmm.
SPEAKER_00Let's just let's stop it there. And then we'll do the next part.
SPEAKER_02In order to automate vendor risk monitoring, you need to understand the risk you're trying to monitor for. I think one thing that we can get kind of bogged down in is um I have these tools, they they can alert me. There's, you know, there's scores and there's bells and there's whistles and there's things that keep you know coming, you know, alerting me on, but really what is the risk to your company? And in order to understand that, you really need to learn your business. I think that's so key, especially now. So the key to assessing risk meaningfully is to understand the the critical areas of your business, the the it critical infrastructure to your organization so that you can more proactively set these alerts to be meaningful. So yeah.
unknownAll right.
SPEAKER_00That's great. What about reducing manual overhead? What's the what's the technical step folks can do to reduce manual overhead?
SPEAKER_02You say I think smarter, not harder.
SPEAKER_00Excellent. Uh yeah, yeah, that's excellent. That's excellent.
SPEAKER_02Staying curious about emerging risks, focus on um thinking critically about how you can improve from TPRM from an automation standpoint, from a um business uh strategy standpoint, from relationship standpoint. Uh once you start thinking, having that critical mindset and kind of backing up and looking at the whole picture instead of getting in the weeds, it's always going to improve manual workloads.
SPEAKER_00I totally agree. I work harder, not smart, I work smarter, not harder, you know, a risk-based approach, right? That's building that same approach that you and I talked about. That's my threat point, that's my take on it. Um, Julie, we're right up on time,
Wrap Up And Thanks
SPEAKER_00which is great. Uh thanks for being a guest. And I'll probably bug in in my third season to come on again and share what what happened in 2027 and what you're doing in 2028 of it. So keep doing what you're doing. Appreciate the partnership and and and spreading the good word on third party risk. Uh and thanks for being a guest. Thank you, Greg. Always a pleasure.