Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Beyond The Vendor Questionnaire with Mike Day
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your vendor questionnaire might be perfect and you can still be exposed. The real failures increasingly live three or four tiers deep, where you do not have a contract, do not have direct oversight, and often do not even know the dependency exists. I’m joined by Mike Day, Financial Services TPRM lead at Deloitte and host of Third Party Therapy, to get practical about what third-party risk management looks like when regulators, outages, and AI-era supply chains collide.
We unpack why DORA is widely misunderstood as a documentation exercise, and why the intent is operational resilience: knowing which third parties support critical services, de-risking them, and proving you can absorb disruption. We also get specific about fourth-party and nth party risk, including how teams are combining questionnaires with monitoring tools and external data to map hidden relationships and systemic concentration risk.
AI raises the stakes on concentration: many “AI-enabled” products depend on a small set of frontier model providers, which can amplify sector-wide impact and geopolitical sensitivity. From there we move into the future of TPRM: how generative AI can accelerate SOC 2 and vendor documentation reviews, why adoption varies by maturity and governance constraints, and how to break down procurement and security silos by rethinking intake from first principles. Mike closes with a simple quick win: collect data efficiently, ask each question once, and avoid the “data buffet” that slows everything down.
Subscribe, share this with a TPRM or procurement leader, and leave a review. What part of your third-party risk program feels most “stuck” right now?
Welcome And Guest Introduction
SPEAKER_00Hello and welcome to another edition of Third Party Threateners Podcast. This edition I've got a fellow podcaster, Mike Day, from the Financial Services TPRM lead at Deloitte and the host of Third Party Therapy Podcast. He's across the pond in England. And I'm really uh glad to have him. Mike, do you want to just give a little bit of background to the listeners for you?
SPEAKER_01Thanks so much for having me on today. Really appreciate it. Yeah, so um I've been around third-party risk procurement for more years than I care to mention. So background in uh financial services, doing TPRM, doing procurement, uh, working with a number of large financial organizations, global financial organizations, and ending up specializing in third-party risk for the last 10 years, I say. I I'm I'm intrinsically nosy, very interested in what everybody's doing, uh, whether that be how they're coping with the latest regulations, how they're dealing with the latest technology. And uh yeah, I've uh I sort of turned that passion into a job now working at uh at Deloitte. So great to uh great to be part of this. Looking forward to the discussion.
SPEAKER_00Yeah, I mean me as well. Uh and what I really like is that I don't get folks international as much as I'd like. So uh it'd be great to talk with you about uh some of the regulatory aspects uh uh in your space, which is something we don't get to talk about much on my podcast. So great.
Quick Questions On DORA And TPRM
SPEAKER_00In fact, we'll we'll start off with that. We'll do the five quick questions to get to know Mike better. And the first one is actually on Dora. So what's the single biggest misconception practitioners have about the regulatory pressure like Dora?
SPEAKER_01I think the biggest misconception is probably that it's all about documentation and reporting. So a lot of focus on having documents in place, having reporting. There's the what they call the register of information, which is a big data set that needs to be provided to the regulators. And part of it is that, but a lot of it is around really driving effective risk management and knowing where your third parties are supporting really critical services to your organization and how you manage that and how you de-risk it and how you drive resilience across the board. So really turning that into turning what is quite a prescriptive regulation into effective risk management.
SPEAKER_00Perfect. Um, and if you question number two, if you could permanently ban one phrase or metric from third-party risk management reporting, what would it be?
SPEAKER_01It would be path to green, I think, which we hear all the time. Oh yeah. You know, yeah. Once you pass to green, well, probably not giving any data to any of your suppliers.
SPEAKER_00So through yellow? I don't know. Yeah, yeah.
SPEAKER_01So that that's um that's uh that's probably what I go for.
SPEAKER_00That's a good one. I like that one. Yeah, yeah. This one will be on your your podcast. What's the one surprising lesson you've learned from hosting third-party therapy?
SPEAKER_01I think it's the the fact that everybody is in the same place. Well, not the same place, but everyone's having challenges. Every everybody's got problems, everyone's struggling, everybody's trying to come up with solutions to new regulations, new threats, new complexities, and everyone's in the same boat. And that's probably something that a lot of people don't realize when they're just sitting in their own organization struggling with whatever.
SPEAKER_00When when I go to the third-party risk association uh conferences, I call it you you're it's it's fun to commiserate with everybody because we all have some of the same issues. What's your favorite framework or approach for communicating vendor risk to non-security executives?
SPEAKER_01I think I think verbal verbal communication, explaining, talking through, articulating. I think the danger of framework, the danger of formality and structure is that it it doesn't land with people who aren't familiar with that framework. Actually getting to know people and having a verbal conversation, I would say.
SPEAKER_00Yeah, perfect. Yeah, and business English, right? Yeah. What's your how do you recharge? What do you do to the voice?
SPEAKER_01I play a bit of football, I coach a bit of cricket during the summer, uh, and I mainly run around after my three children. Um I'm not sure if that's recharging or and relaxing, but it's it's not working.
SPEAKER_00That's doing work. So uh Yeah, yeah, exactly. Yeah, yeah. Yeah. That's easily enough. I did I did have one guest who said that that he uh he goes and actually does coding for his relaxation, which I thought was a little confusing. But that's what he does. So, you know, fully food. Yeah, yeah. That's exactly right. Yeah, yeah. All right, so we've got to get a little bit of better concept of your your mindset.
The Illusion Of Supply Chain Control
SPEAKER_00So we'll get into the hook start, which is a five-minute uh timely or something interesting to talk about. This one's the illusion of control in a multi-tiered supply chain, is the topic discussion. And we'll prompt it off with uh financial divisions spend uh millions auditing their primary vendors, yet uh major operational allergies and data breaches are increasingly, originally three or four uh tiers deep in the supply chain. How how do we move past professional vendor questionnaires and gain visibility into the nth party systemic concentration risk before regulators step in? Mike, what's your what's your thoughts on that?
SPEAKER_01So I think that's the million-dollar question that lots of organizations are really struggling with, um especially in the financial sector. Um you know, questionnaires and just outright asking the suppliers has still got a very strong presence and will continue to. I think there's a number of technology tools developing now where, whether they be from a cyber perspective, that can actually track and sort of the IP connections between companies and other companies, you know, difficult to distinguish between third, fourth, fifth parties, but just external parties, as well as data providers who can uh sort of scour the internet and identify key relationships that you may or may not have. But it's it's almost a Venn diagram of different sources being brought together to identify who your who your supply chain actually is. And I think it's increasingly complex. You know, the the start-up turn is identify your material or critical fourth parties to your critical third parties. But like you say, you know, the risk can come from any angle. It can come from anybody who's got access to your systems, anything who's got access to your data. It can be somebody who's one, two, three steps removed from you in terms of contractual relationships. And even increasingly now with the the advent of Frontier AI, you know, the speed at which these vulnerabilities can be identified and exploited through things like open source, which can be part of your software building materials within software product. You might not even know it's there from a contract, it's increasingly worrying. So, yeah, a lot of monitoring, a lot of um investigation, a lot of um uh data capture. And I think it's a two-tier problem. So the first tier is getting the information, the second tier is actually doing something with it. People talk a lot about concentration risk. Um, even the regulatory frameworks talk a lot about concentration risk. But there's a big difference between knowing that you've got that you've got 58 suppliers here, and you've got this one supplier who provides lots of services through to actually understanding the risk they pose, what could be the impact of a failure, what's the likelihood of a failure if you want to plot it on a lovely five by five framework. Um, and I think a lot of companies are still on that journey to really understand what that looks like.
SPEAKER_00I agree. I think the only thing I'd add would be you could do what the regulators here, the financial regulators in the states have done, which is uh finally, which is saying you don't have to worry so much about your nth parties, but if you ask your, you do need to ask your third parties how their third party risk program is operated, that should give you some assurances about your nth parties.
SPEAKER_01Yeah, absolutely. And that's and that's the normal approach that people are taking. It's interesting that things like regulators like Dora are starting to push that boundary because technically you can only control the relationship you have a contract with. So who are your third parties, who are their fourth parties, and how do they manage them is the normal approach. But increasingly using monitoring tools on the fourth parties. And I think this is where cross-industry is really important because you know you've got your manufacturing, your industry is a physical product, it will be managing extended supply chains for years. You know, this is second nature to them. Managing except supply chain is still relatively new to the financial sector. You know, where where can we take lessons learned from manufacturing, pharmaceutical, from retail, um, etc., to you know, the processing and the approaches that they take and bring it across into FS. Something that's very, very interesting to uh sort of try and explore.
SPEAKER_00Yeah, I agree. All right, well, yeah, I think we've uh we got the hook uh laid out pretty well. So we'll
From Compliance To Operational Resilience
SPEAKER_00get into big question number one, which is the evolving third-party risk management uh practice in financial services from checkbox audits to checkbox audits to DORA and the systemic risk. And the focus here is how uh global financial regulations like DORA and UK operational resiliency rules, uh and fourth party concentrations are uh forcing a complete overhaul of third-party risk programs in some cases. Where they're paying attention. But the discussion points here, let's start off with how do you think financial services uh firms are shifting from passive compliance to active operational resilience under DORA and regional mandates? Like how how do you see that evolving?
SPEAKER_01I I think um I think first of all, I think companies are evolving at a slightly different speed depending on the maturity and capability. The regulatory pressure brings board level focus, as does you know, high-profile cyber outages. In the UK, we've had some Jacky or Land Rover recently, which is probably the most high-profile one, but we've had a number of others as well, Mark's and Spencer's um uh recently, and that really gets people focused. So that means a board level focus on this. I think most organizations have gone through a a sort of journey, mature focus of trying to get to grips with who they who they use, who their third parties are. There's a compliance phase where they're trying to get compliant with the latest regulation, whether that be Dora, whether that be um SS221 for the UK, whether it be OSFE, MAS, whatever. And then they get into a, okay, we're compliant, but how do we be effective? How can we optimize? How can we drive and use this data to be become more resilient, but also not to hold the business up because the reality is that a lot of these compliant processes are clunky, you know, uh things, which can take a number of days, weeks, probably months to get a new supplier on board. So, how can that be shortened and how can it be reduced in cost? So I think a lot of companies are coming out at that end now. There's still a fair chunk going through the compliance piece as well.
SPEAKER_00Perfect. On the fourth party concentration challenge, this is even more acute now with AI being delivered heavily through fourth party services, right? Most of the products you're buying that include AI, most of them don't have their own LLM models. They're buying LLM stuff from one of the big providers. So this fourth party concentration is becoming more acute with the use of AI. How can what's your advice for organizations to better detect concentration risk?
SPEAKER_01Yeah, I mean, first of all, it's you're absolutely right. I mean, the AI capability is probably concentrated with four or five specific providers globally. And that brings with it a risk in terms of um, you know, not only you know failure being having a systematic impact on a sector, on a country, et cetera, but also being more sensitive to geopolitical challenges. So you you know, if you look at you know some of the restrictions around the use of mythos that have been brought in because of, you know, for for non-US organizations, so it can be affected by political changes, you know, tariffs, etc. So it's a very real risk that people need to think of. You know, there's obviously there's diversification, which is the main uh solution to it, but you're somewhat limited in terms of what you can diversify to when you've only got four or five capabilities. So this is one of the reasons why path to green is my least liked phrase, because in many cases there isn't a path to green. It's how you manage that risk proportionately. So yeah, it's diversification. It's identification first, and then once you've identified it, you can then diversify it.
SPEAKER_00I like that you're right. I like that because it's more about resiliency than a path to green, isn't it, Mike?
SPEAKER_01Yeah, absolutely. Yeah, no, absolutely. It it's it's understanding how you use it, what you use it for, and what you will do if it fails. But then we're starting, you know, that's almost like the old risk management approach. The the newer way of thinking about it is how do you engineer it into a resilient situation so that those failures don't happen rather than just you know identifying a risk bread just to go, I'll think if it falls over where we've got a problem, how do you engineer it resiliently moving forward? And that's a lot of a number of organizations are now really trying to think about that. Um I I think the other thing about concentration risk and and and um AI is the flip side is that as I said, I mentioned mythos earlier, concentration of the remedial technology as well. So if you're gonna use frontier AI to protect yourself, then you've got a very small concentration of providers who can do that. So it's not just you know the the the providers of the services you're trying to scan or assess, but the actual scanning and assessing technology itself is also somewhat limited and uh and subject to change.
SPEAKER_00So that's very excellent points. I'll wrap up the big question. One with the the last point here is uh is on tiering, and we need to re-evaluate how we do tiering here in the space with a uh no, and moving beyond sort of generic uh vendor classifications uh to worse-based threatened forms or context-based of how we we we look at a vendor tiering as opposed to just simple, they have a lot of data versus they don't have a lot of data, is what I'm getting at. So uh what are your thoughts on that, Mike?
SPEAKER_01No, I I would agree entirely. I think tiering um has evolved over time in conjunction with technology and capability. You know when when all of this has been going on Excel spreadsheets, you had to have a simplified way of tiering your suppliers. You know, you had your top tier, your middle tier, your bottom tier, and this is what we did with them. Because it was it was almost impossible to do anything but that. You had to do something that would focus the mind and would allow you to report effectively. Now we've got technology tools that can be smarter. You can have, you know, you can calculate risk with different risk domain levels and sub-risk domain levels. So you can have your data risk, your cyber risk, your AI risk, your resilience risk, et cetera. You can have your criticality in there, and therefore, as a result of that, you can create more tailored ongoing treatment standards that are really focused on the risk that that relationship poses and that are dynamic as well. So as incidents happen, as things happen, you tailor it up and down. You know, it looks nice, you've got a nice pyramid with segmentation. And there's still a need for that for reporting and for reporting to the board, because you can't just say, oh, we've got a big cluster of suppliers and it's all on something different. So you have to be able to say, you know, here's where we are, but you you can now get to the point where you can report your exposure from an AI, you can report your exposure from data, you can report your exposure from cyber. You know, they are overlapping, they're not all the same. So, you know, I think it's a function of the technology that we can now get to that point. And I think you'll only see that increase with the use of AI that can enable it to be a much more um straightforward and simpler for the user. Because a lot of times it's down to an end user who's not necessarily an expert in this to manage these relationships. And so the more help you can give them through technology tools to say you've got to do this, gotta do that, or even better, do it for them and bringing them back the actionable outcomes, the better.
SPEAKER_00Excellent. All right, so big question number two is the future of third party risk management.
AI Concentration Risk And Smarter Tiering
SPEAKER_00Well, let's get on crystal ball out and uh talk about AI automation and moving up the value chain. Focus here is on how AI, dynamic risk monitoring, and unified operating models are uh transforming third party risk management into a uh uh really a strategic business enabler. Um, I I see some of that change, thought process happening now. It's you know, 10 years ago is we were a cost center. We're still a cost center, but I think folks are also starting to understand that that third party risk management team is crucial to making better decisions strategically on where organizations want to go. So that's the setup. The discussion points on it are uh let's first talk about how generative AI and risk operations. How are AI tools being deployed to process complex vendor documentation, extract SOC2 findings, and accelerate assessment workflows? How do you see that being implemented? It or do you see it uniformly? Is it based on maturity?
SPEAKER_01So I think this is one where I'm mentioning some of the main use cases, you know, consumption of data, smart assessments, you know, pulling in software reports and translating them to a control framework. Also, the other case use cases, more chatbot-based um interaction with end users to really understand what a service is actually doing from an internal perspective. In terms of adoption, I think it's varying by industry. The finance sector is fast-paced but also risk perverse. So quite often the technology is there, but the ability for companies to consume it, not the willingness, because the demand is there and the you know, the the inclination and arguably the budget is there, but the ability to jump through the risk governance hoops to prove that it is reliable, to prove that it is, you know, it is meeting all of the requirements, is often, you know, getting in the way of it. So, you know, I've I've spoken to a number of technology providers, and they're not necessarily careering down the approach of just put AI over everything, because they know their customers are not ready. So they need to be able to provide a tool that can be turned on at the pace the customer is ready for. Whereas for other companies, you know, I just a completely AI-based solution. And so if somebody's buying something new, they can adopt it. But everyone's running at a different pace in smaller companies, smaller FS organizations are actually usually a bit easier to get through and be able to adopt AI a lot quicker than maybe your global banks and insurance companies where there's a lot more hoops to jump through to be able to get that in.
SPEAKER_00Yep. No, excellent. All right, bridging uh procurement security and risk. Uh how do we break down better organizational stylos to integrate third-party risk into initial procurement wise, like around then treating it sort of as a, to your point, as a roadblock or as a as a something that that slows us down, right? What what what are some of the ways that you think people can break stylos down a little bit better?
SPEAKER_01So I think I'm not sure how popular this opinion is, and this is very much my opinion. So historically, TPRM has been a subset of procurement. So, you know, procurement own the interaction that somebody wants to buy something, they go into a procurement process or tool, and then at some point during that process, a TPRM process is kicked in place. TPRN is the scope and the breadth of TPRM is growing beyond the scope of procurement in a lot of organizations. You know, the the risk associated with doing a zero-value proof of concept versus the commercial value is completely different. They were starting to see TPRM being focused on non-traditional suppliers, on inter-group suppliers, which in some organizations is outside the scope of PRM. So I actually think what needs to happen is that those roles need to swap, that TPRM becomes the first step that people go through when they want to engage a third party, and then that can trigger procurement and sourcing activity and contracting on that subset of relationships that are required. That's being very sort of black and white, you've got TPR and procurement. What you actually want to do is bring the two together into a seamless whole. That means that you're
AI Automation And Rethinking Procurement
SPEAKER_01got a supplier onboarding process and you're looking at those different stages. The reality is though that they are usually separate processes, separate teams, separate technology tools in there. But yeah, I think that that changing the role and putting them, putting them first and also adapting to technology. The reason that it's seen as a blocker, the reason it's seen as a risk and an overhead is because of the time it takes and the effort it takes. So the shorter you can make that, the quicker you can make it, the better. And I think uh the use cases we're seeing for AI right now are the ones that are making an existing process quicker. What we need to start doing is rethinking the process and rethinking the approach. And AI is going to be able to fuel that. I I often liken it to the uh Henry Ford quote that I'm probably getting it wrong, but if you ask people what they wanted, they'd ask for faster horses. They wouldn't think of a car. So, you know, what we're talking about here is speeding up a TPRM process that's been around for years. You know, we have the opportunity to rethink of it from first principles, you know, and power that by AI in a very different way.
SPEAKER_00All right, so let's uh let's ask the next question, uh uh kind of build off of that one. Um, if we're gonna reverse the roles a bit, where does TPRM report into? Do you think it reports on a chief risk officer? Does it report into legal? Does it report into the CISO? What's the and I know it may depend on the size of the organization on excess, so there's no like a set answer, but what's in an ideal world, where do you think that third party risk could report into?
SPEAKER_01My experience is always somewhere better to put TPRN than wherever it is at the top at that point in the party.
SPEAKER_00Yeah, yeah, yeah. Totally agree by that one, yeah.
SPEAKER_01I I my from all my experience, the I think the best place to put it would be under a COO from an operations perspective. The thing about why third party risk has the word risk in it, I don't see it as a true risk organization. It's operationalizing everybody else's risks. To my mind, there's actually no such thing as a third-party risk. There's a third-party cyber risk, there's a third party data risk, there's a third-party resilience risk. So it's taking everybody else's risks and and applying it to third parties. So, um which is why quite a lot of people in TPRM have a bit of a I'm not quite sure if I'm line one or line two.
SPEAKER_00Yeah, yeah, yeah.
SPEAKER_01Yeah, exactly. They just know they're not line three, that's all they know. So yeah, COO seems to be often. I think it does it does rely on very close working relationships across all those areas risk, legal, finance, CIO, etc. It's it's an enabler across all those areas, and that's where the skill lies in terms of developing those relationships.
SPEAKER_00All right, we're gonna wrap up the podcast with the quick win for practitioners.
Quick Win And Closing Requests
SPEAKER_00What's the one step that security risk teams can take today to streamline vendor intake without sacrificing governance, Mike?
SPEAKER_01I think it's around efficient data collection, asking every question only once of the person who knows it at the time they know it, rather than asking multiple questions multiple times or expecting everybody to know it up front before anything happens, which is a way of pushing yourself down the line. So, yeah, I I think efficiency in in data collection, um, and really challenging yourself to ask the questions that matter. Don't get stuck in what I call the data buffet, which is oh, wouldn't it be nice if I had that and that and that and that? And before you know it, your data's overflowing and you can't carry it back. That's an efficient, effective challenge for your data collection.
SPEAKER_00Yeah, very good. All right. Well, again, thanks for uh being a guest. Mike, it's been a pleasure. If you like the podcast as a listener, please subscribe. I I could always use more subscribers and provide feedback. If you have a question that you'd like to have me ask a guest, feel free to submit it in the comments. Thanks again, Mike. Oh, yeah. Thank you very much for having me.