Your Vendors Have Vendors You've Never Heard Of

Your Vendors Have Vendors You've Never Heard Of

🎙 Craig Duckworth (host), Jowanza Joseph (guest) 👥 192 📅 August 4, 2026 ⏱ 34 min 👁 39 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

vendor risk managementOT securitysupply chaincyber insurancecritical infrastructure

Summary

In this episode of Industrial Cybersecurity Insider, host Craig Duckworth interviews Jowanza Joseph, CEO of Parakeet Risk, about third-party risk management in industrial cybersecurity. Joseph emphasizes the importance of cataloging and prioritizing vendors, noting that many organizations lack a clear view of their supply chain, including subcontractors. The discussion covers the shift in cyber insurance from checkbox questionnaires to evidence-based assessments, the challenges of OT asset visibility, and the impact of AI on vulnerability discovery. Joseph outlines three hallmarks of a strong third-party risk program: an up-to-date vendor database, a living map of entry points, and a commitment to transparency through trust centers. The conversation also addresses the cultural divide between IT and OT, the issue of responsibility without authority for CISOs, and the need for collaboration. Joseph suggests starting with vendor cataloging as a low-cost first step and discusses the future of vendor attestation standards.

146 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into third-party risk management in industrial environments. Joseph’s arguments are coherent and grounded in his professional background, though they rely on anecdotal evidence rather than empirical data. The discussion provides actionable advice, such as the importance of vendor cataloging and the need for evidence-based cyber insurance. However, the argumentation could be strengthened by referencing specific case studies or industry reports.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the conversation is based on expert opinion and industry observations rather than peer-reviewed research. No specific sources are cited, but the topics align with current industry discussions. The title accurately reflects the content, focusing on the hidden layers of subcontractors in supply chains. The adequacy between title and content is high, as the episode directly addresses this issue.

149 words

Title / Content Match

The title accurately reflects the core theme of the episode: the hidden layers of subcontractors in supply chains and the challenges of managing third-party risk.

Quality & Reliability

7/10

The discussion is based on the guest's 15 years of engineering experience and his role as CEO of a vendor risk management company. While no specific studies or data are cited, the insights align with industry trends and practical observations. The information is credible but largely anecdotal and lacks empirical evidence.

Key Moments

Cited Sources

  • Parakeet Risk — Jowanza Joseph is CEO of Parakeet Risk, a company focused on third-party risk management for industrial sectors.

Concurring Sources

Contribution & Novelties

The episode provides a practitioner’s perspective on third-party risk management in OT environments, highlighting the unique challenges of industrial cybersecurity. It offers practical advice on vendor cataloging, evidence-based cyber insurance, and the cultural divide between IT and OT. The discussion on responsibility without authority for CISOs is particularly insightful.

Pour aller plus loin :

  • NIST Cybersecurity Framework — A widely used framework for improving cybersecurity, relevant to third-party risk management.
  • ISO/IEC 27001 — An international standard for information security management, often referenced in vendor assessments.
  • CISA’s Cybersecurity Best Practices — Guidance from the U.S. Cybersecurity and Infrastructure Security Agency on securing critical infrastructure.

103 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and quality, indicating a well-rounded discussion. The technical level is moderate, making it accessible to a broad audience while still providing valuable insights for professionals.

Reliability 7/10