Trust Your Vendors, Do You?

Trust Your Vendors, Do You?

🎙 Jan De Ridder 👥 70K 📅 April 24, 2026 ⏱ 48 min 👁 154 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

third-party riskvendor managementsupply chain securityregulatory compliancecontinuous monitoring

Summary

Jan De Ridder, a seasoned cybersecurity professional and SANS instructor, delivers a webcast on third-party risk management (TPRM). He begins by highlighting the growing reliance on vendor ecosystems, which expand attack surfaces and increase regulatory exposure. He cites real-world breaches like SolarWinds and Kaseya to illustrate the severe consequences of inadequate vendor oversight. The talk then examines current practices, particularly static questionnaires, and their limitations in capturing real-time security posture. De Ridder introduces a continuous TPRM lifecycle comprising five phases: planning and onboarding, due diligence, continuous monitoring, remediation and reporting, and off-boarding. He emphasizes the need for risk-based tiering, proportional due diligence, automated monitoring, and integration with procurement and legal workflows. Regulatory drivers such as NIS2, DORA, and GDPR are discussed as catalysts for robust TPRM programs. The presentation concludes with actionable steps for implementing a TPRM program, including starting small, demonstrating value, and scaling. The talk is practical and aimed at security leaders and practitioners.

156 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the importance of third-party risk management, supported by real-world examples and regulatory context. The argumentation is coherent, moving from problem identification to proposed solutions. The speaker effectively argues that traditional questionnaires are insufficient and advocates for a continuous, risk-based approach. However, some claims lack specific citations, and the presentation could benefit from more detailed case studies or data to strengthen the argument.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references several industry reports (e.g., from GitLab, Whistic, Armor Risk, SecurityScorecard) and regulatory frameworks (NIS2, DORA, GDPR), but does not provide direct URLs or detailed citations during the talk. The title accurately reflects the content, which challenges blind trust in vendors. The presentation is well-structured and aligns with the stated learning objectives.

137 words

Title / Content Match

The title is catchy and relevant, framing the core question of whether organizations can trust their vendors, which the talk addresses thoroughly.

Quality & Reliability

7/10

The talk is based on the speaker's extensive experience as a CISO and consultant, and references real-world breaches and regulatory frameworks. However, it lacks detailed citations for many claims and relies on industry reports without specific data verification.

Key Moments

Cited Sources

Concurring Sources

  • Whistic TPRM Impact Report — Referenced for statistics on third-party breaches.
  • Armor Risk Research — Referenced for high-profile breach examples.
  • SecurityScorecard Report — Referenced for third-party breach statistics.

Contribution & Novelties

The talk provides a practical framework for implementing a continuous TPRM lifecycle, emphasizing the need to move beyond static questionnaires. It integrates regulatory requirements and real-world breach examples to make a compelling case for proactive vendor risk management. The speaker’s experience adds credibility, and the actionable steps are valuable for practitioners.

Pour aller plus loin :

  • NIS2 Directive — Official text of the NIS2 Directive.
  • DORA Regulation — Official text of the Digital Operational Resilience Act.
  • GDPR — Comprehensive resource on the General Data Protection Regulation.
  • SolarWinds Attack Analysis — Overview of the SolarWinds supply chain attack.
  • Kaseya VSA Attack — Overview of the Kaseya ransomware attack.

107 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, indicating a content-rich presentation. Quality and reliability are moderate, reflecting the reliance on industry reports and personal experience. The overall balance suggests a practical, experience-driven talk suitable for security professionals.

Reliability 7/10

💬 No comments were provided for analysis.