Skip to main content

Jeffrey Wheatman on Silent Breaches and Third-Party Risk Management

N2K NetworksMay 23, 202516 min128 views
23 connections·33 entities in this video

Understanding Silent Breaches

  • ⚠️ A silent breach occurs when an organization is unaware of vulnerabilities within its extended supply chain, impacting its operations and data security.
  • 💡 This risk is amplified because organizations often focus on their direct vendors (third parties) without fully understanding the risks posed by their vendors' partners (fourth and fifth parties).
  • 🎯 Events like the CrowdStrike incident highlight how vulnerabilities in a single, critical vendor can have widespread, unforeseen impacts on many businesses.

Managing Third-Party Risk

  • 🧩 The core challenge is managing third-party risk effectively, as many organizations struggle even with direct vendor oversight.
  • 🔑 Concepts like concentration risk and cascading risk are crucial for understanding how multiple partners relying on the same vendor can lead to widespread failure.
  • 📈 Focusing on the biggest exposures first, rather than getting overwhelmed by the sheer number of potential risks, is a pragmatic approach.

Strategies for Risk Mitigation

  • 📚 Organizations should ask critical questions about their vendors' use of AI, software, and their own supply chain dependencies.
  • 🔍 Understanding what critical services vendors use (e.g., specific MDR providers) is key to identifying potential exposure points.
  • 🚀 A proactive approach, termed 'left of boom,' involves identifying single points of failure before they cause an incident, while 'right of boom' focuses on recovery.

Navigating Complexity and Scale

  • 🐘 The metaphor of eating an elephant "one bite at a time" emphasizes tackling manageable risks sequentially, starting with the most significant ones.
  • 📊 Prioritizing risks based on the number of exploited vulnerabilities (e.g., focusing on actively exploited CVEs over all issued ones) allows for efficient resource allocation.
  • 💰 Risk leaders should align security efforts with core business goals: revenue generation, cost management, and regulatory compliance.

Signs of Maturity in Risk Management

  • 🔄 Mature organizations move from point-in-time snapshots and questionnaires to continuous monitoring and integrated threat intelligence.
  • 🤝 Building collaborative environments where vendors' jobs are made easier leads to better overall security posture.
  • ✅ The goal is to be proactive, anticipating potential issues like ransomware or contractual breaches by understanding vendor dependencies and risks.

Optimism in Cybersecurity Conversations

  • 💬 Hope stems from improved conversations between security professionals and business stakeholders, focusing on solving problems rather than just selling solutions.
  • 💡 Vendors are increasingly focusing on addressing the actual pain points of CISOs and IT departments.
  • 📈 While the threat landscape is evolving and challenging, there's a sense of incremental progress and a move in the right direction, despite adversaries also advancing.
Knowledge graph33 entities · 23 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
33 entities
Chapters8 moments

Key Moments

Transcript59 segments

Full Transcript

Topics13 themes

What’s Discussed

Silent BreachThird-Party Risk ManagementCyber RiskSupply Chain RiskConcentration RiskCascading RiskAI GovernanceVulnerability ManagementZero-Day ExploitsContinuous MonitoringThreat IntelligenceRSAC ConferenceBlack Kite
Smart Objects33 · 23 links
Companies· 9
People· 4
Concepts· 19
Media· 1