<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Third Party</title><link>https://www.spreaker.com/podcast/third-party--6740712</link><description><![CDATA[If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact. Third-Party is the podcast built for the people behind the dashboards. The ones managing 5,000 vendors with a team of three. Hosted by Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley, this show unpacks what actually works (and what doesn’t) in TPRM. No fear tactics. No buzzwords. Just unfiltered conversations, sharp insights, and the occasional roast of a really bad SIG questionnaire. If you’ve ever had to explain cyber vendor r]]></description><atom:link href="https://www.spreaker.com/show/6740712/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Technology</category><copyright>Copyright Sweet Fish</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/88bcfa09aabf33880a59e3b41898c43f.jpg</url><title>Third Party</title><link>https://www.spreaker.com/podcast/third-party--6740712</link></image><lastBuildDate>Wed, 09 Sep 2026 10:23:19 +0000</lastBuildDate><itunes:author>Sweet Fish</itunes:author><itunes:owner><itunes:name>Sweet Fish</itunes:name><itunes:email>feeds@spreaker.com</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/88bcfa09aabf33880a59e3b41898c43f.jpg"/><itunes:subtitle>If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact.
Third-Party is the podcast built for the people behind the dashboards. The ones...</itunes:subtitle><itunes:summary><![CDATA[If you manage third-party cyber risk, you’ve seen it all: meaningless scorecards, black-box tools, and endless frameworks that never quite connect to business impact. Third-Party is the podcast built for the people behind the dashboards. The ones managing 5,000 vendors with a team of three. Hosted by Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley, this show unpacks what actually works (and what doesn’t) in TPRM. No fear tactics. No buzzwords. Just unfiltered conversations, sharp insights, and the occasional roast of a really bad SIG questionnaire. If you’ve ever had to explain cyber vendor r]]></itunes:summary><itunes:category text="Technology"/><itunes:explicit>false</itunes:explicit><podcast:guid>ddd0a1e2-0d66-5cdd-bbd1-4ecc027f1888</podcast:guid><itunes:type>episodic</itunes:type><item><title>Are Your Vendors Lying to You?</title><link>https://www.spreaker.com/episode/are-your-vendors-lying-to-you--75020504</link><description><![CDATA[Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells you and what is actually happening inside their environment?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable space between attestation and reality. Jeffrey wants to call it lying. Bob and Ferhat push back hard, arguing most of it is bad data, missing inventory, and answers that are aspirational rather than dishonest. From there they get into the harder problem: how do you verify anything when you cannot send an auditor into Google or Amazon, and what happens to verification itself when the answers you receive were generated by AI in the first place?In this episode, you will learn:<ul><li>Why yes or no questionnaire answers measure compliance, not the efficiency of a control</li><li>The three types of verification, from signals to behavior analysis to vendor testimony</li><li>Why every signal needs a confidence level before you decide which battles to fight</li><li>How to get real value from SOC 2 reports and where third-party audits fall short</li><li>Why most programs are built to discover and ask questions, but never to follow up</li><li>What happens to trust but verify when AI is producing the answers on both sides</li></ul>If your program collects a lot of vendor answers and verifies almost none of them, this conversation is worth your time.<br />]]></description><guid isPermaLink="false">b528749a-22d0-4bb7-aaf8-ec4c1aa934ed</guid><pubDate>Wed, 09 Sep 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/75020504/431204358_44100_2_8f8b38612318a.mp3" length="34316537" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells you and what is actually happening inside their...</itunes:subtitle><itunes:summary><![CDATA[Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells you and what is actually happening inside their environment?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable space between attestation and reality. Jeffrey wants to call it lying. Bob and Ferhat push back hard, arguing most of it is bad data, missing inventory, and answers that are aspirational rather than dishonest. From there they get into the harder problem: how do you verify anything when you cannot send an auditor into Google or Amazon, and what happens to verification itself when the answers you receive were generated by AI in the first place?In this episode, you will learn:<ul><li>Why yes or no questionnaire answers measure compliance, not the efficiency of a control</li><li>The three types of verification, from signals to behavior analysis to vendor testimony</li><li>Why every signal needs a confidence level before you decide which battles to fight</li><li>How to get real value from SOC 2 reports and where third-party audits fall short</li><li>Why most programs are built to discover and ask questions, but never to follow up</li><li>What happens to trust but verify when AI is producing the answers on both sides</li></ul>If your program collects a lot of vendor answers and verifies almost none of them, this conversation is worth your time.<br />]]></itunes:summary><itunes:duration>2145</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The AI Scanner Hype Test</title><link>https://www.spreaker.com/episode/the-ai-scanner-hype-test--74695809</link><description><![CDATA[AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game changer, or just the latest round of marketing built on fear, uncertainty, and doubt?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik pressure-test the hype around tools like Project Glasswing and the new class of AI scanners. They dig into why discovery has raced ahead of remediation, why throwing AI at the end of the process may be solving the wrong problem, and where these tools actually earn their keep today versus where the marketing gets ahead of reality. Along the way they get into prioritization, explainability, and the uncomfortable question of what happens when you can find far more than you could ever fix.In this episode, you will learn:<ul><li>Why the real story is the gap between vulnerabilities discovered and vulnerabilities patched</li><li>Where AI genuinely helps today, from discovery and attack chaining to triage</li><li>Why shifting these tools earlier in the development cycle may matter more than faster remediation</li><li>How to cut through vendor AI claims using explainability as your filter</li><li>Why prioritization, not patching everything, is the only way out of the deluge</li><li>What security leaders should expect from these tools over the next year</li></ul><br />If you have ever wondered whether the AI vulnerability hype is signal or noise, this conversation gives you a framework to tell the difference.]]></description><guid isPermaLink="false">ce37df93-d7ac-41d4-af11-5da2f08d8693</guid><pubDate>Wed, 26 Aug 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/74695809/430456133_44100_2_9c964ce50e297.mp3" length="35679502" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game...</itunes:subtitle><itunes:summary><![CDATA[AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game changer, or just the latest round of marketing built on fear, uncertainty, and doubt?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik pressure-test the hype around tools like Project Glasswing and the new class of AI scanners. They dig into why discovery has raced ahead of remediation, why throwing AI at the end of the process may be solving the wrong problem, and where these tools actually earn their keep today versus where the marketing gets ahead of reality. Along the way they get into prioritization, explainability, and the uncomfortable question of what happens when you can find far more than you could ever fix.In this episode, you will learn:<ul><li>Why the real story is the gap between vulnerabilities discovered and vulnerabilities patched</li><li>Where AI genuinely helps today, from discovery and attack chaining to triage</li><li>Why shifting these tools earlier in the development cycle may matter more than faster remediation</li><li>How to cut through vendor AI claims using explainability as your filter</li><li>Why prioritization, not patching everything, is the only way out of the deluge</li><li>What security leaders should expect from these tools over the next year</li></ul><br />If you have ever wondered whether the AI vulnerability hype is signal or noise, this conversation gives you a framework to tell the difference.]]></itunes:summary><itunes:duration>2230</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Your TPRM Program Isn't Fixable</title><link>https://www.spreaker.com/episode/your-tprm-program-isn-t-fixable--73841556</link><description><![CDATA[Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the whole thing down and start over.In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik get honest about what it takes to rebuild a TPRM program from the ground up. They dig into why the hardest part isn't the tooling, it's breaking the mental model you've been committed to for years. Drawing on the idea of creation and destruction, they walk through what they would keep, what they would throw out, and why using AI to speed up a broken process just gets you to the wrong answer faster.In this episode, you will learn:Why incremental improvement is the trap, and when a program needs a full rebuild instead of a refreshWhat the questionnaire industry is really protecting, and what could actually disrupt itThe three things Bob and Ferhat would build first if they started from scratchWhether you can outsource a TPRM program, and where that logic breaks downWhy AI model cards may replace stacks of AI questionnairesHow to shift from assess-everybody to monitor-everybody and assess by exceptionIf you have ever inherited a program you did not build and wondered whether to fix it or start over, this conversation is for you.]]></description><guid isPermaLink="false">39ee3447-76a5-479f-94a4-8ab93baf555a</guid><pubDate>Wed, 12 Aug 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73841556/429585053_44100_2_6c16932d7e3fe.mp3" length="36192756" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the whole thing down and start over.In this episode,...</itunes:subtitle><itunes:summary><![CDATA[Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the whole thing down and start over.In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik get honest about what it takes to rebuild a TPRM program from the ground up. They dig into why the hardest part isn't the tooling, it's breaking the mental model you've been committed to for years. Drawing on the idea of creation and destruction, they walk through what they would keep, what they would throw out, and why using AI to speed up a broken process just gets you to the wrong answer faster.In this episode, you will learn:Why incremental improvement is the trap, and when a program needs a full rebuild instead of a refreshWhat the questionnaire industry is really protecting, and what could actually disrupt itThe three things Bob and Ferhat would build first if they started from scratchWhether you can outsource a TPRM program, and where that logic breaks downWhy AI model cards may replace stacks of AI questionnairesHow to shift from assess-everybody to monitor-everybody and assess by exceptionIf you have ever inherited a program you did not build and wondered whether to fix it or start over, this conversation is for you.]]></itunes:summary><itunes:duration>2263</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>You Can't Say No to Your Vendors</title><link>https://www.spreaker.com/episode/you-can-t-say-no-to-your-vendors--73233443</link><description><![CDATA[You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if leverage is mostly an illusion, what actually moves a vendor to fix their exposure?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dismantle the idea that third-party risk is about power and rebuild it around something more useful: collaboration. They dig into why the questionnaire-led, finger-wagging approach fails, how to communicate risk in dollars and cents that the business will actually act on, and why the relationship you build before an incident matters far more than any contract clause after one.In this episode, you will learn:<ul><li>Why "saying no" was never the CISO's job, and what the real role is</li><li>How to turn a contract into a collaboration tool instead of a weapon</li><li>Why intelligence-led outreach beats questionnaire fatigue every time</li><li>How to communicate vendor risk so business stakeholders actually respond</li><li>What to do when a hard-to-replace vendor won't budge</li><li>Why the first interactions with a vendor set the tone for the entire relationship</li></ul>If you have ever felt ignored by a vendor who has bigger customers than you, this conversation will change how you show up to the table.]]></description><guid isPermaLink="false">06dd33a0-3e7e-4ec4-864f-25f5aa69503e</guid><pubDate>Wed, 29 Jul 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73233443/428793897_44100_2_5c62fa15c79c6.mp3" length="39500067" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if leverage is mostly an illusion, what actually moves a...</itunes:subtitle><itunes:summary><![CDATA[You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if leverage is mostly an illusion, what actually moves a vendor to fix their exposure?In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dismantle the idea that third-party risk is about power and rebuild it around something more useful: collaboration. They dig into why the questionnaire-led, finger-wagging approach fails, how to communicate risk in dollars and cents that the business will actually act on, and why the relationship you build before an incident matters far more than any contract clause after one.In this episode, you will learn:<ul><li>Why "saying no" was never the CISO's job, and what the real role is</li><li>How to turn a contract into a collaboration tool instead of a weapon</li><li>Why intelligence-led outreach beats questionnaire fatigue every time</li><li>How to communicate vendor risk so business stakeholders actually respond</li><li>What to do when a hard-to-replace vendor won't budge</li><li>Why the first interactions with a vendor set the tone for the entire relationship</li></ul>If you have ever felt ignored by a vendor who has bigger customers than you, this conversation will change how you show up to the table.]]></itunes:summary><itunes:duration>2469</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Why Manufacturing Supply Chains Are Ransomware’s Favorite Target</title><link>https://www.spreaker.com/episode/why-manufacturing-supply-chains-are-ransomware-s-favorite-target--72988732</link><description><![CDATA[Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why this industry has become one of the most targeted sectors for cyber attacks. If your business depends on uptime, supply chains, or physical operations, this conversation will show you where the real risks are hiding.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore why manufacturing environments are especially vulnerable, from legacy systems and operational technology (OT) to the real-world consequences of downtime. They unpack new research showing how far behind many organizations are, why cyber attacks in manufacturing are shifting from data theft to operational disruption, and what leaders need to understand to protect production lines and critical infrastructure.<ul><li>Understand why manufacturing is a top target for cyber attacks</li><li>Learn how downtime risk outweighs traditional data breach concerns</li><li>Discover the gap between IT security and operational technology (OT)</li><li>Explore why many organizations still struggle with basic cyber hygiene</li><li>Get insights into how cyber threats are evolving across global supply chains</li></ul>Don’t risk production downtime or supply chain disruption. Learn how to identify and prioritize the cyber risks that matter most.]]></description><guid isPermaLink="false">ab96986b-4f3f-47f6-bf06-563eab927d02</guid><pubDate>Wed, 15 Jul 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72988732/427865432_44100_2_45d0e5765859b.mp3" length="32129357" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why this industry has become one of the most targeted...</itunes:subtitle><itunes:summary><![CDATA[Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why this industry has become one of the most targeted sectors for cyber attacks. If your business depends on uptime, supply chains, or physical operations, this conversation will show you where the real risks are hiding.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore why manufacturing environments are especially vulnerable, from legacy systems and operational technology (OT) to the real-world consequences of downtime. They unpack new research showing how far behind many organizations are, why cyber attacks in manufacturing are shifting from data theft to operational disruption, and what leaders need to understand to protect production lines and critical infrastructure.<ul><li>Understand why manufacturing is a top target for cyber attacks</li><li>Learn how downtime risk outweighs traditional data breach concerns</li><li>Discover the gap between IT security and operational technology (OT)</li><li>Explore why many organizations still struggle with basic cyber hygiene</li><li>Get insights into how cyber threats are evolving across global supply chains</li></ul>Don’t risk production downtime or supply chain disruption. Learn how to identify and prioritize the cyber risks that matter most.]]></itunes:summary><itunes:duration>2009</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The #1 Mistake Boards Make on Cyber Risk</title><link>https://www.spreaker.com/episode/the-1-mistake-boards-make-on-cyber-risk--72769044</link><description><![CDATA[Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well-prepared security leaders fail to get buy-in where it matters most. If you’ve ever struggled to explain risk in a way executives actually understand, this conversation will show you how to fix it.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what boards actually care about, why traditional reporting (like risk heat maps and technical metrics) often falls flat, and how to reframe third-party cyber risk in a way that drives action. Drawing from real-world experience and industry research, they explore the gap between cybersecurity teams and board-level decision-makers—and how to close it with clearer storytelling, smarter prioritization, and business-aligned messaging.<ul><li>Learn how to translate complex cyber risk into language boards care about</li><li>Discover why common tools like heat maps often fail executives</li><li>Understand the 3 things boards prioritize—and how to align your messaging</li><li>Get practical strategies for answering “bad” board questions effectively</li><li>See how better communication can directly improve organizational resilience</li></ul>Don’t risk your message getting lost in complexity. Learn how to communicate cyber risk in a way that drives real decisions.]]></description><guid isPermaLink="false">4e437904-c3a6-499c-8d71-2a8ef117d944</guid><pubDate>Wed, 01 Jul 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72769044/426820141_44100_2_9ff740883fddf.mp3" length="31195218" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well-prepared security leaders fail to get buy-in where...</itunes:subtitle><itunes:summary><![CDATA[Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well-prepared security leaders fail to get buy-in where it matters most. If you’ve ever struggled to explain risk in a way executives actually understand, this conversation will show you how to fix it.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what boards actually care about, why traditional reporting (like risk heat maps and technical metrics) often falls flat, and how to reframe third-party cyber risk in a way that drives action. Drawing from real-world experience and industry research, they explore the gap between cybersecurity teams and board-level decision-makers—and how to close it with clearer storytelling, smarter prioritization, and business-aligned messaging.<ul><li>Learn how to translate complex cyber risk into language boards care about</li><li>Discover why common tools like heat maps often fail executives</li><li>Understand the 3 things boards prioritize—and how to align your messaging</li><li>Get practical strategies for answering “bad” board questions effectively</li><li>See how better communication can directly improve organizational resilience</li></ul>Don’t risk your message getting lost in complexity. Learn how to communicate cyber risk in a way that drives real decisions.]]></itunes:summary><itunes:duration>1950</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Hidden Signals Predicting Vendor Collapse</title><link>https://www.spreaker.com/episode/the-hidden-signals-predicting-vendor-collapse--72562133</link><description><![CDATA[Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether forecasting vendor failure is realistic or just another false promise. If you’ve ever wondered how to identify hidden risks before they explode, this conversation delivers practical insights you can act on immediately.Hosted by Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik, this episode dives into the real signals behind vendor instability, from layoffs and geopolitical conflict to ransomware targeting patterns and operational blind spots. The team breaks down why correlation is often mistaken for causation, how attackers exploit chaos, and why most organizations still miss early warning signs. You’ll walk away with a clearer understanding of what can actually be predicted, what cannot, and how to build a smarter third-party risk strategy that goes beyond surface-level metrics.What you’ll learn:<ul><li>How to identify early warning signals of vendor failure before a breach happens</li><li>Why layoffs, automation, and global conflict can increase third-party risk exposure</li><li>The difference between correlation and causation in risk modeling</li><li>How attackers exploit chaos and weak vendor ecosystems</li><li>Why vendor self-reporting often fails and what to rely on instead</li></ul>Don’t risk missing the signals that matter. Learn how to spot risk earlier and make smarter third-party decisions before it’s too late.]]></description><guid isPermaLink="false">e4b5cf0e-591a-4f07-9ec5-2df6d1a8c206</guid><pubDate>Wed, 17 Jun 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72562133/426175205_44100_2_79469cb8e26a2.mp3" length="35709595" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether forecasting vendor failure is realistic or just...</itunes:subtitle><itunes:summary><![CDATA[Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether forecasting vendor failure is realistic or just another false promise. If you’ve ever wondered how to identify hidden risks before they explode, this conversation delivers practical insights you can act on immediately.Hosted by Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik, this episode dives into the real signals behind vendor instability, from layoffs and geopolitical conflict to ransomware targeting patterns and operational blind spots. The team breaks down why correlation is often mistaken for causation, how attackers exploit chaos, and why most organizations still miss early warning signs. You’ll walk away with a clearer understanding of what can actually be predicted, what cannot, and how to build a smarter third-party risk strategy that goes beyond surface-level metrics.What you’ll learn:<ul><li>How to identify early warning signals of vendor failure before a breach happens</li><li>Why layoffs, automation, and global conflict can increase third-party risk exposure</li><li>The difference between correlation and causation in risk modeling</li><li>How attackers exploit chaos and weak vendor ecosystems</li><li>Why vendor self-reporting often fails and what to rely on instead</li></ul>Don’t risk missing the signals that matter. Learn how to spot risk earlier and make smarter third-party decisions before it’s too late.]]></itunes:summary><itunes:duration>2232</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Mythos Hype Check: TPRM Paradigm Shift or Big Nothing Burger</title><link>https://www.spreaker.com/episode/mythos-hype-check-tprm-paradigm-shift-or-big-nothing-burger--72341679</link><description><![CDATA[A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob Maley, Ferhat Dikbiyik, and Black Kite co-founder and CTO Candan Bolukbas to break down what Mythos and Project Glasswing actually change, and what they don't.The numbers are already alarming. Forty-eight thousand CVEs published in 2025. A 43-day mean time to patch. An exploitation window that has gone negative, meaning threat actors are exploiting vulnerabilities an average of seven days before defenders even know they exist. Mythos accelerates vulnerability discovery, but as the team makes clear, discovering more vulnerabilities faster only matters if you have a program built to handle it.In this episode, you will learn:<ul><li>What Mythos and Project Glasswing actually are and why the hype may be outpacing the reality</li><li>Why the vulnerability deluge is already unmanageable with traditional CVSS-based prioritization</li><li>How the 135-day embargo window affects your third-party exposure</li><li>Why fourth-party risk, meaning what your vendors run rather than just who they are, is becoming the real blind spot</li><li>What SBOMs have to do with the future of supply chain vulnerability management</li><li>The three things security leaders should do right now to prepare their programs</li></ul>This is not a theoretical conversation. It's the one your program needs before the window closes.]]></description><guid isPermaLink="false">1327fcdb-d90d-4c59-b5b9-41ba736d169c</guid><pubDate>Thu, 04 Jun 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72341679/425459356_44100_2_f5f826f081aea.mp3" length="43650402" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob...</itunes:subtitle><itunes:summary><![CDATA[A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob Maley, Ferhat Dikbiyik, and Black Kite co-founder and CTO Candan Bolukbas to break down what Mythos and Project Glasswing actually change, and what they don't.The numbers are already alarming. Forty-eight thousand CVEs published in 2025. A 43-day mean time to patch. An exploitation window that has gone negative, meaning threat actors are exploiting vulnerabilities an average of seven days before defenders even know they exist. Mythos accelerates vulnerability discovery, but as the team makes clear, discovering more vulnerabilities faster only matters if you have a program built to handle it.In this episode, you will learn:<ul><li>What Mythos and Project Glasswing actually are and why the hype may be outpacing the reality</li><li>Why the vulnerability deluge is already unmanageable with traditional CVSS-based prioritization</li><li>How the 135-day embargo window affects your third-party exposure</li><li>Why fourth-party risk, meaning what your vendors run rather than just who they are, is becoming the real blind spot</li><li>What SBOMs have to do with the future of supply chain vulnerability management</li><li>The three things security leaders should do right now to prepare their programs</li></ul>This is not a theoretical conversation. It's the one your program needs before the window closes.]]></itunes:summary><itunes:duration>2729</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Are You Measuring the Right Risks…Or Just the Easiest Ones?</title><link>https://www.spreaker.com/episode/are-you-measuring-the-right-risks-or-just-the-easiest-ones--72082411</link><description><![CDATA[Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and why those metrics often fail to reflect real business risk. If you’ve ever wondered whether your TPRM strategy is actually driving better decisions or just producing reports, this conversation will challenge how you think about risk measurement.Hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the gap between what organizations track and what actually matters—from misleading metrics and “top vendor” lists to the struggle of communicating risk to executives who don’t see the value. You’ll learn how to rethink your approach to third party cyber risk management, move beyond surface-level reporting, and focus on the signals that truly impact your business.In this episode, you’ll learn:<ul><li>Why most third party risk metrics are based on convenience, not impact</li><li>The difference between measuring activity vs. measuring real risk</li><li>How to make risk meaningful to boards and executive stakeholders</li><li>What “good” risk metrics actually look like in practice</li><li>How to avoid false confidence from incomplete or misleading data</li></ul>Don’t risk building your strategy on the wrong signals. Learn how to measure what actually matters—and make better decisions because of it.]]></description><guid isPermaLink="false">c7afcdd7-7b6d-41b4-b549-815e951cf02d</guid><pubDate>Wed, 20 May 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72082411/424384482_44100_2_e14399df4781.mp3" length="30227643" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and why those metrics often fail to reflect real...</itunes:subtitle><itunes:summary><![CDATA[Are you measuring the right risks in your third party risk management program—or just the easiest ones? In this episode, we break down how most teams approach third party risk management metrics and why those metrics often fail to reflect real business risk. If you’ve ever wondered whether your TPRM strategy is actually driving better decisions or just producing reports, this conversation will challenge how you think about risk measurement.Hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the gap between what organizations track and what actually matters—from misleading metrics and “top vendor” lists to the struggle of communicating risk to executives who don’t see the value. You’ll learn how to rethink your approach to third party cyber risk management, move beyond surface-level reporting, and focus on the signals that truly impact your business.In this episode, you’ll learn:<ul><li>Why most third party risk metrics are based on convenience, not impact</li><li>The difference between measuring activity vs. measuring real risk</li><li>How to make risk meaningful to boards and executive stakeholders</li><li>What “good” risk metrics actually look like in practice</li><li>How to avoid false confidence from incomplete or misleading data</li></ul>Don’t risk building your strategy on the wrong signals. Learn how to measure what actually matters—and make better decisions because of it.]]></itunes:summary><itunes:duration>1890</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Why Automation Is Creating More Cyber Risk</title><link>https://www.spreaker.com/episode/why-automation-is-creating-more-cyber-risk--71888781</link><description><![CDATA[Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and what that means for your TPCRM program. If you’re relying on automation to scale vendor risk assessments, this conversation will help you avoid costly blind spots and make smarter decisions.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the real tradeoffs between speed and accuracy in TPCRM, exploring how automation can both strengthen and weaken your risk posture. They discuss the dangers of over-relying on data, where AI-driven decisions fall short, and why human judgment still plays a critical role in identifying real risk. This episode is essential for anyone responsible for vendor risk, cybersecurity, or compliance who wants to scale effectively without sacrificing confidence in their decisions.In this episode, you’ll learn:<ul><li>How automation in TPCRM can unintentionally increase risk</li><li>The hidden tradeoffs between speed and accuracy in vendor assessments</li><li>Why more data doesn’t always lead to better decisions</li><li>Where AI and algorithms fall short in real-world risk scenarios</li><li>How to balance automation with human judgment for better outcomes</li><li>Practical ways to improve visibility and decision-making in your TPCRM program</li></ul>Don’t risk scaling bad decisions faster. Learn how to balance automation and accuracy to protect your business.]]></description><guid isPermaLink="false">48911ad7-3278-477d-8ee9-9f4a84e1cc03</guid><pubDate>Wed, 06 May 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71888781/423425254_44100_2_14dbd42c05c6c.mp3" length="32841977" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and what that means for your TPCRM program. If you’re...</itunes:subtitle><itunes:summary><![CDATA[Automation vs Accuracy in TPCRM is one of the biggest challenges in modern third-party risk management. In this episode, we break down how the push for faster automation is impacting accuracy, and what that means for your TPCRM program. If you’re relying on automation to scale vendor risk assessments, this conversation will help you avoid costly blind spots and make smarter decisions.Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the real tradeoffs between speed and accuracy in TPCRM, exploring how automation can both strengthen and weaken your risk posture. They discuss the dangers of over-relying on data, where AI-driven decisions fall short, and why human judgment still plays a critical role in identifying real risk. This episode is essential for anyone responsible for vendor risk, cybersecurity, or compliance who wants to scale effectively without sacrificing confidence in their decisions.In this episode, you’ll learn:<ul><li>How automation in TPCRM can unintentionally increase risk</li><li>The hidden tradeoffs between speed and accuracy in vendor assessments</li><li>Why more data doesn’t always lead to better decisions</li><li>Where AI and algorithms fall short in real-world risk scenarios</li><li>How to balance automation with human judgment for better outcomes</li><li>Practical ways to improve visibility and decision-making in your TPCRM program</li></ul>Don’t risk scaling bad decisions faster. Learn how to balance automation and accuracy to protect your business.]]></itunes:summary><itunes:duration>2053</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>How to Calculate the Real Cost of a Third-Party Breach</title><link>https://www.spreaker.com/episode/how-to-calculate-the-real-cost-of-a-third-party-breach--71552796</link><description><![CDATA[Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about risk and start putting real numbers behind the potential cost of a third-party breach. If you want security leaders, executives, and boards to take third-party cyber risk seriously, you need to understand how to quantify its financial impact.Many security teams still rely on qualitative risk language like “high,” “medium,” or “critical,” but those labels rarely drive action. Jeffrey, Bob, and Ferhat break down why calculating the financial impact of a third-party breach is essential for communicating with executives, prioritizing vendors, and securing the right investments in risk management. From understanding uncertainty to building models that are accurate enough to guide decisions, this conversation offers practical insight into how leading teams estimate breach costs and translate cyber risk into business language.In this episode, you’ll learn:<ul><li>Why calculating the financial impact of a third-party breach is critical for executive decision making</li><li>How security leaders translate cyber risk into dollars, euros, or pounds</li><li>Why “something bad could happen” is not enough to justify cybersecurity investment</li><li>The difference between precision and usefulness when modeling cyber risk</li><li>How risk quantification helps prioritize vendors and third-party exposures</li><li>Why boards and executives respond better to financial risk than technical risk language</li></ul>Don’t risk letting third-party cyber risk remain invisible to leadership. Learn how to calculate the real financial impact of a third-party breach and turn risk conversations into decisions that protect your organization.<br />0:00 Introduction &amp; Teaser0:50 Welcome &amp; Episode Overview2:01 Guest Introduction: Jack Jones &amp; the Origin of FAIR7:17 Challenges to Implementing Risk Quantification10:57 Wrap-Up with Jack Jones11:23 Calculating Financial Impact of a Third-Party Breach25:54 Precision vs. Accuracy in Risk Models30:01 Research Roundup: Cybersecurity Outlook 202636:44 Agree or Disagree39:41 Outro &amp; Next Episode Preview]]></description><guid isPermaLink="false">224569fd-3000-47f1-9141-a9eaec476220</guid><pubDate>Wed, 22 Apr 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71552796/422198686_44100_2_35722f6644e98.mp3" length="38417135" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about...</itunes:subtitle><itunes:summary><![CDATA[Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about risk and start putting real numbers behind the potential cost of a third-party breach. If you want security leaders, executives, and boards to take third-party cyber risk seriously, you need to understand how to quantify its financial impact.Many security teams still rely on qualitative risk language like “high,” “medium,” or “critical,” but those labels rarely drive action. Jeffrey, Bob, and Ferhat break down why calculating the financial impact of a third-party breach is essential for communicating with executives, prioritizing vendors, and securing the right investments in risk management. From understanding uncertainty to building models that are accurate enough to guide decisions, this conversation offers practical insight into how leading teams estimate breach costs and translate cyber risk into business language.In this episode, you’ll learn:<ul><li>Why calculating the financial impact of a third-party breach is critical for executive decision making</li><li>How security leaders translate cyber risk into dollars, euros, or pounds</li><li>Why “something bad could happen” is not enough to justify cybersecurity investment</li><li>The difference between precision and usefulness when modeling cyber risk</li><li>How risk quantification helps prioritize vendors and third-party exposures</li><li>Why boards and executives respond better to financial risk than technical risk language</li></ul>Don’t risk letting third-party cyber risk remain invisible to leadership. Learn how to calculate the real financial impact of a third-party breach and turn risk conversations into decisions that protect your organization.<br />0:00 Introduction &amp; Teaser0:50 Welcome &amp; Episode Overview2:01 Guest Introduction: Jack Jones &amp; the Origin of FAIR7:17 Challenges to Implementing Risk Quantification10:57 Wrap-Up with Jack Jones11:23 Calculating Financial Impact of a Third-Party Breach25:54 Precision vs. Accuracy in Risk Models30:01 Research Roundup: Cybersecurity Outlook 202636:44 Agree or Disagree39:41 Outro &amp; Next Episode Preview]]></itunes:summary><itunes:duration>2402</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Vendor Sprawl Is Out of Control (Here’s How the Best Teams Fix It)</title><link>https://www.spreaker.com/episode/vendor-sprawl-is-out-of-control-here-s-how-the-best-teams-fix-it--71179952</link><description><![CDATA[Vendor sprawl is out of control, and most organizations have far more third-party vendors than they realize. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the growing problem of vendor sprawl and why it has quietly become one of the biggest sources of cyber risk. If your organization relies on dozens or hundreds of third parties, this conversation will help you understand how vendor sprawl creates hidden exposure and what the best teams are doing to manage it.As companies adopt more SaaS tools, cloud services, AI platforms, and specialized vendors, visibility and control become harder to maintain. Jeffrey, Bob, and Ferhat break down how vendor sprawl happens, why simply adding more tools does not solve the problem, and how leading security and risk teams are changing their approach to third-party risk management. From rogue applications to overlapping tools and hidden dependencies, this episode explores practical strategies for regaining visibility and prioritizing the vendors that actually matter.In this episode, you’ll learn:<ul><li>Why vendor sprawl is accelerating across modern organizations</li><li>How hidden third parties introduce unexpected cyber risk</li><li>The difference between vendor visibility and real vendor risk management</li><li>Why adding more tools can sometimes make the problem worse</li><li>Practical ways security teams are prioritizing the vendors that matter most</li><li>How AI and automation are changing third-party risk management</li></ul>Don’t risk letting vendor sprawl quietly expand your attack surface. Learn how leading teams are taking back control before hidden vendor risk becomes the next breach.]]></description><guid isPermaLink="false">a462544d-0a5f-47c6-bdec-c907d7de83f3</guid><pubDate>Wed, 08 Apr 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71179952/421506200_44100_2_a5bad502650b2.mp3" length="37395643" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Vendor sprawl is out of control, and most organizations have far more third-party vendors than they realize. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the growing problem of vendor sprawl and why it has quietly become...</itunes:subtitle><itunes:summary><![CDATA[Vendor sprawl is out of control, and most organizations have far more third-party vendors than they realize. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the growing problem of vendor sprawl and why it has quietly become one of the biggest sources of cyber risk. If your organization relies on dozens or hundreds of third parties, this conversation will help you understand how vendor sprawl creates hidden exposure and what the best teams are doing to manage it.As companies adopt more SaaS tools, cloud services, AI platforms, and specialized vendors, visibility and control become harder to maintain. Jeffrey, Bob, and Ferhat break down how vendor sprawl happens, why simply adding more tools does not solve the problem, and how leading security and risk teams are changing their approach to third-party risk management. From rogue applications to overlapping tools and hidden dependencies, this episode explores practical strategies for regaining visibility and prioritizing the vendors that actually matter.In this episode, you’ll learn:<ul><li>Why vendor sprawl is accelerating across modern organizations</li><li>How hidden third parties introduce unexpected cyber risk</li><li>The difference between vendor visibility and real vendor risk management</li><li>Why adding more tools can sometimes make the problem worse</li><li>Practical ways security teams are prioritizing the vendors that matter most</li><li>How AI and automation are changing third-party risk management</li></ul>Don’t risk letting vendor sprawl quietly expand your attack surface. Learn how leading teams are taking back control before hidden vendor risk becomes the next breach.]]></itunes:summary><itunes:duration>2338</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>What You Should NEVER Automate in Risk Programs</title><link>https://www.spreaker.com/episode/what-you-should-never-automate-in-risk-programs--70870107</link><description><![CDATA[TPCRM automation is rapidly becoming a priority for risk teams, but automating the wrong things can quietly increase exposure instead of reducing it. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the reality of TPCRM automation and what you can safely automate versus what should never be automated inside a third-party cyber risk program. If you are responsible for managing vendors, cyber risk, or compliance, this conversation will challenge the assumption that more automation always leads to better outcomes.Automation promises speed and efficiency, but when organizations automate processes they do not fully understand, they often end up accelerating broken workflows and hiding critical risk signals. The hosts break down where automation truly helps risk teams scale and where human judgment, visibility, and traceability must remain at the center of decision-making.In this episode, you will learn:<ul><li>What TPCRM automation actually means and why many programs misunderstand it</li><li>The biggest mistake organizations make when automating risk workflows</li><li>Why automating a broken process makes risk programs worse</li><li>Where automation can genuinely improve efficiency in TPCRM programs</li><li>The decisions that should never be fully automated</li><li>Why visibility and traceability matter when AI and automation are involved</li></ul>Don’t risk automating the wrong parts of your cyber risk program. Learn how to apply TPCRM automation the right way before it creates new blind spots.]]></description><guid isPermaLink="false">80f14f06-2d65-43ad-be28-7805dc6ee138</guid><pubDate>Wed, 25 Mar 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70870107/420588350_44100_2_aaee99bc197b5.mp3" length="36132570" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>TPCRM automation is rapidly becoming a priority for risk teams, but automating the wrong things can quietly increase exposure instead of reducing it. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the reality of TPCRM...</itunes:subtitle><itunes:summary><![CDATA[TPCRM automation is rapidly becoming a priority for risk teams, but automating the wrong things can quietly increase exposure instead of reducing it. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik unpack the reality of TPCRM automation and what you can safely automate versus what should never be automated inside a third-party cyber risk program. If you are responsible for managing vendors, cyber risk, or compliance, this conversation will challenge the assumption that more automation always leads to better outcomes.Automation promises speed and efficiency, but when organizations automate processes they do not fully understand, they often end up accelerating broken workflows and hiding critical risk signals. The hosts break down where automation truly helps risk teams scale and where human judgment, visibility, and traceability must remain at the center of decision-making.In this episode, you will learn:<ul><li>What TPCRM automation actually means and why many programs misunderstand it</li><li>The biggest mistake organizations make when automating risk workflows</li><li>Why automating a broken process makes risk programs worse</li><li>Where automation can genuinely improve efficiency in TPCRM programs</li><li>The decisions that should never be fully automated</li><li>Why visibility and traceability matter when AI and automation are involved</li></ul>Don’t risk automating the wrong parts of your cyber risk program. Learn how to apply TPCRM automation the right way before it creates new blind spots.]]></itunes:summary><itunes:duration>2259</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Is Cybersecurity Regulation Actually Dangerous?</title><link>https://www.spreaker.com/episode/is-cybersecurity-regulation-actually-dangerous--70589146</link><description><![CDATA[Is cybersecurity regulation actually dangerous? In this episode, we examine whether cybersecurity regulation is improving real security or quietly making organizations less safe. If you have ever wondered whether compliance helps or hurts your defenses, this conversation breaks down what cybersecurity regulation gets right, where it fails, and how leaders should think about risk beyond checklists.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik debate the regulation paradox facing modern security teams. They explore when compliance drives better risk management, when it becomes a dangerous distraction, and why outdated or overly prescriptive rules can pull focus away from real threats. The discussion covers audits, fines, regulatory fragmentation, and the growing gap between fast moving technology and slow moving regulation.What this episode covers:<ul><li>Whether cybersecurity regulation actually improves security outcomes</li><li>How compliance can become a checkbox that misses real risk</li><li>When regulation helps CISOs secure budget and attention</li><li>Why outdated and overly prescriptive rules can increase exposure</li><li>The difference between managing audits and managing real risk</li></ul>Don’t risk confusing compliance with protection. Learn how to think critically about cybersecurity regulation and focus on what actually makes organizations safer before regulation becomes a liability instead of a safeguard.]]></description><guid isPermaLink="false">468819b0-a36a-4001-b51e-b534ebd7ed87</guid><pubDate>Wed, 11 Mar 2026 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70589146/419622501_44100_2_bb0a3f3a58e5c.mp3" length="53943483" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Is cybersecurity regulation actually dangerous? In this episode, we examine whether cybersecurity regulation is improving real security or quietly making organizations less safe. If you have ever wondered whether compliance helps or hurts your...</itunes:subtitle><itunes:summary><![CDATA[Is cybersecurity regulation actually dangerous? In this episode, we examine whether cybersecurity regulation is improving real security or quietly making organizations less safe. If you have ever wondered whether compliance helps or hurts your defenses, this conversation breaks down what cybersecurity regulation gets right, where it fails, and how leaders should think about risk beyond checklists.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik debate the regulation paradox facing modern security teams. They explore when compliance drives better risk management, when it becomes a dangerous distraction, and why outdated or overly prescriptive rules can pull focus away from real threats. The discussion covers audits, fines, regulatory fragmentation, and the growing gap between fast moving technology and slow moving regulation.What this episode covers:<ul><li>Whether cybersecurity regulation actually improves security outcomes</li><li>How compliance can become a checkbox that misses real risk</li><li>When regulation helps CISOs secure budget and attention</li><li>Why outdated and overly prescriptive rules can increase exposure</li><li>The difference between managing audits and managing real risk</li></ul>Don’t risk confusing compliance with protection. Learn how to think critically about cybersecurity regulation and focus on what actually makes organizations safer before regulation becomes a liability instead of a safeguard.]]></itunes:summary><itunes:duration>3372</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Real Meaning of “C” in TPCRM</title><link>https://www.spreaker.com/episode/the-real-meaning-of-c-in-tpcrm--70266361</link><description><![CDATA[What puts the “C” in TPCRM? As third-party risk management evolves, leaders are asking what the “C” in TPCRM really means, and why cyber risk now has an outsized impact on every other risk. We unpack what puts the “C” in TPCRM, why cyber is more than a checkbox, and how misunderstanding it can quietly put your entire business at risk.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down the shift from traditional TPRM to TPCRM and explain why cyber risk can’t be treated as just another compliance item. From operational disruption and resilience to cascading supply-chain failures, the conversation explores how cyber risk intersects with financial, operational, and enterprise risk, and why boards and executives need a clearer, more connected view.What this episode covers:<ul><li>What the “C” in TPCRM actually stands for… and what it doesn’t</li><li>Why cyber risk isn’t just about data breaches or compliance</li><li>How cyber creates cascading impact across operations, finance, and supply chains</li><li>Why treating cyber as a point-in-time risk leaves organizations exposed</li><li>How leaders should think about cyber in business and boardroom terms</li></ul>Don’t risk treating cyber as a checkbox while it quietly drives your biggest exposures. Learn how to understand the real “C” in TPCRM and protect your business before cyber risk turns into operational and financial damage.]]></description><guid isPermaLink="false">d3e2864b-0700-4f3b-8777-b2e284d6122e</guid><pubDate>Wed, 25 Feb 2026 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70266361/418661702_44100_2_2d9b8e174e484.mp3" length="40434206" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>What puts the “C” in TPCRM? As third-party risk management evolves, leaders are asking what the “C” in TPCRM really means, and why cyber risk now has an outsized impact on every other risk. We unpack what puts the “C” in TPCRM, why cyber is more than...</itunes:subtitle><itunes:summary><![CDATA[What puts the “C” in TPCRM? As third-party risk management evolves, leaders are asking what the “C” in TPCRM really means, and why cyber risk now has an outsized impact on every other risk. We unpack what puts the “C” in TPCRM, why cyber is more than a checkbox, and how misunderstanding it can quietly put your entire business at risk.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down the shift from traditional TPRM to TPCRM and explain why cyber risk can’t be treated as just another compliance item. From operational disruption and resilience to cascading supply-chain failures, the conversation explores how cyber risk intersects with financial, operational, and enterprise risk, and why boards and executives need a clearer, more connected view.What this episode covers:<ul><li>What the “C” in TPCRM actually stands for… and what it doesn’t</li><li>Why cyber risk isn’t just about data breaches or compliance</li><li>How cyber creates cascading impact across operations, finance, and supply chains</li><li>Why treating cyber as a point-in-time risk leaves organizations exposed</li><li>How leaders should think about cyber in business and boardroom terms</li></ul>Don’t risk treating cyber as a checkbox while it quietly drives your biggest exposures. Learn how to understand the real “C” in TPCRM and protect your business before cyber risk turns into operational and financial damage.]]></itunes:summary><itunes:duration>2528</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Whose Breach Is It Anyway?</title><link>https://www.spreaker.com/episode/whose-breach-is-it-anyway--69971323</link><description><![CDATA[Whose Breach Is It Anyway? When a vendor gets breached and data is exposed, whose breach is it anyway, and who actually pays the price? In this episode, we break down why finger-pointing after every breach is becoming the default response and what that means for real security outcomes. You’ll learn how shared data creates shared damage, and how leaders can respond smarter when third-party risk becomes a crisis.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable truth behind vendor breaches, accountability, and transparency. From supply-chain incidents to public disclosure, they explore why blame doesn’t fix breaches. And what actually helps organizations recover, protect customers, and reduce future risk.What this episode covers:<ul><li>Why “whose breach is it anyway” is the wrong question—and the better ones to ask</li><li>How finger-pointing delays response and increases long-term damage</li><li>The hidden risks of third-party and supply-chain breaches</li><li>When transparency helps—and when it can backfire</li><li>Who ultimately bears the cost of a breach: vendors, companies, or customers</li></ul>Don’t risk repeating the same mistakes after your next vendor incident. Learn how to move past blame, protect your customers, and respond to breaches the right way…before shared damage becomes permanent damage.]]></description><guid isPermaLink="false">a0a211c1-10bd-46c2-aa3f-9edac946c9eb</guid><pubDate>Wed, 11 Feb 2026 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69971323/417758046_44100_2_9fad7ff062776.mp3" length="40936175" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Whose Breach Is It Anyway? When a vendor gets breached and data is exposed, whose breach is it anyway, and who actually pays the price? In this episode, we break down why finger-pointing after every breach is becoming the default response and what...</itunes:subtitle><itunes:summary><![CDATA[Whose Breach Is It Anyway? When a vendor gets breached and data is exposed, whose breach is it anyway, and who actually pays the price? In this episode, we break down why finger-pointing after every breach is becoming the default response and what that means for real security outcomes. You’ll learn how shared data creates shared damage, and how leaders can respond smarter when third-party risk becomes a crisis.In this episode of Third Party, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dig into the uncomfortable truth behind vendor breaches, accountability, and transparency. From supply-chain incidents to public disclosure, they explore why blame doesn’t fix breaches. And what actually helps organizations recover, protect customers, and reduce future risk.What this episode covers:<ul><li>Why “whose breach is it anyway” is the wrong question—and the better ones to ask</li><li>How finger-pointing delays response and increases long-term damage</li><li>The hidden risks of third-party and supply-chain breaches</li><li>When transparency helps—and when it can backfire</li><li>Who ultimately bears the cost of a breach: vendors, companies, or customers</li></ul>Don’t risk repeating the same mistakes after your next vendor incident. Learn how to move past blame, protect your customers, and respond to breaches the right way…before shared damage becomes permanent damage.]]></itunes:summary><itunes:duration>2559</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Biggest Lie in Cybersecurity</title><link>https://www.spreaker.com/episode/the-biggest-lie-in-cybersecurity--69643238</link><description><![CDATA[<br /><br /><br /><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><br />]]></description><guid isPermaLink="false">38638961-88a2-44cd-a663-fa366d7dcc0f</guid><pubDate>Wed, 28 Jan 2026 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69643238/416862557_44100_2_b89e7c2d3722.mp3" length="38240756" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>



- 


- 


- 


- 


- 


- 


</itunes:subtitle><itunes:summary><![CDATA[<br /><br /><br /><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><ul><li><br /></li></ul><br />]]></itunes:summary><itunes:duration>2391</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Truth About AI in Risk Management</title><link>https://www.spreaker.com/episode/the-truth-about-ai-in-risk-management--69436003</link><description><![CDATA[AI risk models are changing how organizations assess vendors, quantify cyber risk, and make high-stakes decisions, but most leaders don’t truly understand what’s happening under the hood. In this episode, AI risk models are stripped down and stress-tested to reveal where automation adds clarity, where it creates blind spots, and why overconfidence in models can quietly increase risk. If you’ve ever struggled to explain or defend an AI-driven decision, this conversation delivers the context you’ve been missing.Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this episode of Third Party explores why all models are inherently flawed, how AI amplifies both insight and uncertainty, and why human judgment still matters in third-party risk management. The hosts unpack real-world examples from vendor scoring, cyber risk quantification, and executive decision-making to show why explainability, defensibility, and adaptability matter more than perfect accuracy.Don’t risk trusting models you can’t justify. Learn how to use AI without surrendering accountability before the wrong decision gets made for you.]]></description><guid isPermaLink="false">36e4d81b-4e55-451f-a665-3686dc93b3dd</guid><pubDate>Wed, 14 Jan 2026 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69436003/415951652_44100_2_2315a852946ff.mp3" length="41597386" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>AI risk models are changing how organizations assess vendors, quantify cyber risk, and make high-stakes decisions, but most leaders don’t truly understand what’s happening under the hood. In this episode, AI risk models are stripped down and...</itunes:subtitle><itunes:summary><![CDATA[AI risk models are changing how organizations assess vendors, quantify cyber risk, and make high-stakes decisions, but most leaders don’t truly understand what’s happening under the hood. In this episode, AI risk models are stripped down and stress-tested to reveal where automation adds clarity, where it creates blind spots, and why overconfidence in models can quietly increase risk. If you’ve ever struggled to explain or defend an AI-driven decision, this conversation delivers the context you’ve been missing.Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this episode of Third Party explores why all models are inherently flawed, how AI amplifies both insight and uncertainty, and why human judgment still matters in third-party risk management. The hosts unpack real-world examples from vendor scoring, cyber risk quantification, and executive decision-making to show why explainability, defensibility, and adaptability matter more than perfect accuracy.Don’t risk trusting models you can’t justify. Learn how to use AI without surrendering accountability before the wrong decision gets made for you.]]></itunes:summary><itunes:duration>2600</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Why 2026 Might Be the Hardest Cyber Year Yet</title><link>https://www.spreaker.com/episode/why-2026-might-be-the-hardest-cyber-year-yet--69258856</link><description><![CDATA[The 2026 cybersecurity predictions are here, and they’re more urgent than anyone expected. In this episode, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what’s coming in the next 12 months, why AI risk is accelerating faster than anyone projected, and how security leaders can stay ahead instead of getting blindsided. If you want clarity (not hype) this conversation delivers real insight into the future of cyber, AI, and third-party risk.From AI vendors collapsing, to entry-level security roles disappearing, to third-party breaches overtaking direct attacks, the trio unpacks the shifts already shaping 2026. You’ll hear exactly what CISOs, boards, and security teams must rethink, and why the old playbook won’t survive what’s coming next.In this episode, you’ll learn:<ul><li>The biggest 2026 cybersecurity predictions and why experts expect things to get worse before they get better</li><li>How AI risk is accelerating beyond traditional time horizons</li><li>Why 50% of AI vendors may shut down in 2026, and what that means for your organization</li><li>The real reason third-party breaches will outnumber direct attacks</li><li>Where automation is being used incorrectly, and where it should be deployed</li><li>Why boards still aren’t asking the right questions (and the questions they must ask in 2026)</li><li>How AI is reshaping cybersecurity roles—from entry-level to the C-suite</li></ul>2026 won’t reward teams who wait. Don’t risk falling behind. Learn what’s coming and how to prepare today.]]></description><guid isPermaLink="false">e4e19249-de4b-4d9d-8485-4ba3a92ba501</guid><pubDate>Wed, 31 Dec 2025 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69258856/414591029_44100_2_401f7ec54ea2.mp3" length="49495561" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>The 2026 cybersecurity predictions are here, and they’re more urgent than anyone expected. In this episode, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what’s coming in the next 12 months, why AI risk is accelerating faster than...</itunes:subtitle><itunes:summary><![CDATA[The 2026 cybersecurity predictions are here, and they’re more urgent than anyone expected. In this episode, hosts Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik break down what’s coming in the next 12 months, why AI risk is accelerating faster than anyone projected, and how security leaders can stay ahead instead of getting blindsided. If you want clarity (not hype) this conversation delivers real insight into the future of cyber, AI, and third-party risk.From AI vendors collapsing, to entry-level security roles disappearing, to third-party breaches overtaking direct attacks, the trio unpacks the shifts already shaping 2026. You’ll hear exactly what CISOs, boards, and security teams must rethink, and why the old playbook won’t survive what’s coming next.In this episode, you’ll learn:<ul><li>The biggest 2026 cybersecurity predictions and why experts expect things to get worse before they get better</li><li>How AI risk is accelerating beyond traditional time horizons</li><li>Why 50% of AI vendors may shut down in 2026, and what that means for your organization</li><li>The real reason third-party breaches will outnumber direct attacks</li><li>Where automation is being used incorrectly, and where it should be deployed</li><li>Why boards still aren’t asking the right questions (and the questions they must ask in 2026)</li><li>How AI is reshaping cybersecurity roles—from entry-level to the C-suite</li></ul>2026 won’t reward teams who wait. Don’t risk falling behind. Learn what’s coming and how to prepare today.]]></itunes:summary><itunes:duration>3094</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>This Is Why Third-Party Risk Never Ends</title><link>https://www.spreaker.com/episode/this-is-why-third-party-risk-never-ends--69095717</link><description><![CDATA[Third-party risk management is broken, and this episode of Third Party shows you exactly why. Discover the five biggest mistakes companies make when managing vendors and compliance programs, and learn how to fix them before they cost you trust, money, and reputation. If you work in cybersecurity, compliance, or risk, this episode gives you the roadmap to move from “checkbox” protection to real security that lasts.In this episode, Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley break down:<ul><li>Why annual assessments fail the moment they’re finished</li><li>How dashboards and “pretty charts” create dangerous blind spots</li><li>The truth about compliance vs. real security</li><li>What “set it and forget it” gets wrong about cyber risk</li><li>How culture—not tools—decides whether your organization stays secure</li></ul>Whether you’re leading a TPRM team, building a compliance framework, or managing vendor relationships, this episode gives you actionable insight and real-world fixes from experts who’ve seen it all.Don’t risk another blind spot. Learn how to transform compliance checklists into true security confidence—before your next breach does it for you.]]></description><guid isPermaLink="false">8b42c12b-63e5-425f-99ff-1cbda0b12bcd</guid><pubDate>Wed, 17 Dec 2025 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69095717/414260761_44100_2_7d134f50927e3.mp3" length="48756609" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Third-party risk management is broken, and this episode of Third Party shows you exactly why. Discover the five biggest mistakes companies make when managing vendors and compliance programs, and learn how to fix them before they cost you trust, money,...</itunes:subtitle><itunes:summary><![CDATA[Third-party risk management is broken, and this episode of Third Party shows you exactly why. Discover the five biggest mistakes companies make when managing vendors and compliance programs, and learn how to fix them before they cost you trust, money, and reputation. If you work in cybersecurity, compliance, or risk, this episode gives you the roadmap to move from “checkbox” protection to real security that lasts.In this episode, Jeffrey Wheatman, Ferhat Dikbiyik, and Bob Maley break down:<ul><li>Why annual assessments fail the moment they’re finished</li><li>How dashboards and “pretty charts” create dangerous blind spots</li><li>The truth about compliance vs. real security</li><li>What “set it and forget it” gets wrong about cyber risk</li><li>How culture—not tools—decides whether your organization stays secure</li></ul>Whether you’re leading a TPRM team, building a compliance framework, or managing vendor relationships, this episode gives you actionable insight and real-world fixes from experts who’ve seen it all.Don’t risk another blind spot. Learn how to transform compliance checklists into true security confidence—before your next breach does it for you.]]></itunes:summary><itunes:duration>3048</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>How to Beat Ransomware Fatigue</title><link>https://www.spreaker.com/episode/how-to-beat-ransomware-fatigue--68847100</link><description><![CDATA[Ransomware fatigue is real, and it’s putting organizations at risk. In this episode of Third Party, hosts Bob Maley, Ferhat Dikbiyik, and Jeffrey Wheatman unpack why ransomware fatigue has become as dangerous as ransomware itself. They break down how constant headlines and endless alerts are numbing CISOs and executives, and why ignoring this “background noise” could open the door to your next major breach.From the psychology of cybercrime to the economics that keep ransomware alive, the hosts explore how attackers have evolved, why small and mid-sized businesses are increasingly targeted, and what real risk management looks like beyond compliance. You’ll learn how fatigue happens, how to fight it with automation and process, and how to strengthen both your internal culture and your third-party ecosystem.]]></description><guid isPermaLink="false">0dc1ae12-c663-4d5b-9669-9dd91b47a402</guid><pubDate>Wed, 03 Dec 2025 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68847100/412497389_44100_2_8630e9b9fdfb.mp3" length="48216188" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Ransomware fatigue is real, and it’s putting organizations at risk. In this episode of Third Party, hosts Bob Maley, Ferhat Dikbiyik, and Jeffrey Wheatman unpack why ransomware fatigue has become as dangerous as ransomware itself. They break down how...</itunes:subtitle><itunes:summary><![CDATA[Ransomware fatigue is real, and it’s putting organizations at risk. In this episode of Third Party, hosts Bob Maley, Ferhat Dikbiyik, and Jeffrey Wheatman unpack why ransomware fatigue has become as dangerous as ransomware itself. They break down how constant headlines and endless alerts are numbing CISOs and executives, and why ignoring this “background noise” could open the door to your next major breach.From the psychology of cybercrime to the economics that keep ransomware alive, the hosts explore how attackers have evolved, why small and mid-sized businesses are increasingly targeted, and what real risk management looks like beyond compliance. You’ll learn how fatigue happens, how to fight it with automation and process, and how to strengthen both your internal culture and your third-party ecosystem.]]></itunes:summary><itunes:duration>3014</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Dark Side of Cyber Report Cards</title><link>https://www.spreaker.com/episode/the-dark-side-of-cyber-report-cards--68535563</link><description><![CDATA[Too often, businesses rely on simple grades or one-page summaries without the context needed to make informed decisions. In this episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore the dark side of cybersecurity report cards and vendor risk scores. The hosts break down why these scores can mislead, how conflicting results create confusion, and why transparency and context are critical for managing third party risk effectively. They share stories from their own experiences, discuss the dangers of oversimplifying complex risks, and outline how organizations can move from blame and black-box scoring to measurable, transparent practices that drive real resilience.]]></description><guid isPermaLink="false">44ee561c-0284-4416-8dfb-90566404de77</guid><pubDate>Wed, 12 Nov 2025 11:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68535563/410796356_44100_2_ce7421e0a3d3d.mp3" length="44452048" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Too often, businesses rely on simple grades or one-page summaries without the context needed to make informed decisions. In this episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore the dark side of cybersecurity report...</itunes:subtitle><itunes:summary><![CDATA[Too often, businesses rely on simple grades or one-page summaries without the context needed to make informed decisions. In this episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore the dark side of cybersecurity report cards and vendor risk scores. The hosts break down why these scores can mislead, how conflicting results create confusion, and why transparency and context are critical for managing third party risk effectively. They share stories from their own experiences, discuss the dangers of oversimplifying complex risks, and outline how organizations can move from blame and black-box scoring to measurable, transparent practices that drive real resilience.]]></itunes:summary><itunes:duration>2779</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>AI’s Seismic Impact on Cybersecurity</title><link>https://www.spreaker.com/episode/ai-s-seismic-impact-on-cybersecurity--68330996</link><description><![CDATA[In today’s episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dive into how artificial intelligence is reshaping third party risk management.  From generative AI tools to shadow AI, they explore both the opportunities and dangers of adopting AI across vendor ecosystems. The hosts discuss automation, governance councils, AI-driven vulnerabilities, and whether risk teams can truly scale with these new technologies. Listeners will gain insight into how CISOs, cyber risk managers, and security professionals can leverage AI as a partner rather than a replacement, while also preparing for the new attack surfaces it introduces. If you’re interested in third party cyber risk, AI governance, or the future of vendor security, this conversation will help you understand where things are headed and what to watch out for.]]></description><guid isPermaLink="false">d87033dd-3b77-482e-ad4b-1d47f576ea83</guid><pubDate>Wed, 29 Oct 2025 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68330996/409897720_44100_2_96d795b11e8bb.mp3" length="42699127" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>In today’s episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dive into how artificial intelligence is reshaping third party risk management.  From generative AI tools to shadow AI, they explore both the opportunities and dangers...</itunes:subtitle><itunes:summary><![CDATA[In today’s episode of Third Party, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik dive into how artificial intelligence is reshaping third party risk management.  From generative AI tools to shadow AI, they explore both the opportunities and dangers of adopting AI across vendor ecosystems. The hosts discuss automation, governance councils, AI-driven vulnerabilities, and whether risk teams can truly scale with these new technologies. Listeners will gain insight into how CISOs, cyber risk managers, and security professionals can leverage AI as a partner rather than a replacement, while also preparing for the new attack surfaces it introduces. If you’re interested in third party cyber risk, AI governance, or the future of vendor security, this conversation will help you understand where things are headed and what to watch out for.]]></itunes:summary><itunes:duration>2669</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Cybersecurity Metrics Boards Actually Care About</title><link>https://www.spreaker.com/episode/cybersecurity-metrics-boards-actually-care-about--68147757</link><description><![CDATA[Cybersecurity metrics are one of the biggest challenges when reporting to executives and the board. In this episode of Third Party, Jeffrey Wheatman, Bob Maley and Ferhat Dikbiyik break down the cybersecurity metrics your board actually cares about. Not vanity numbers, not meaningless dashboards, but the ones that drive real business decisions. If you’ve ever struggled to get your board to engage with your risk reports, this conversation will show you exactly how to bridge the gap.Whether you’re building your next board report, preparing for a budget conversation, or trying to get leadership buy-in, this episode gives you the exact strategies to make cybersecurity a business priority.]]></description><guid isPermaLink="false">c63eb93a-9d7e-49c7-8ec8-65e568c2cd27</guid><pubDate>Wed, 15 Oct 2025 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68147757/409030677_44100_2_4c6ccd3059537.mp3" length="39960658" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Cybersecurity metrics are one of the biggest challenges when reporting to executives and the board. In this episode of Third Party, Jeffrey Wheatman, Bob Maley and Ferhat Dikbiyik break down the cybersecurity metrics your board actually cares about....</itunes:subtitle><itunes:summary><![CDATA[Cybersecurity metrics are one of the biggest challenges when reporting to executives and the board. In this episode of Third Party, Jeffrey Wheatman, Bob Maley and Ferhat Dikbiyik break down the cybersecurity metrics your board actually cares about. Not vanity numbers, not meaningless dashboards, but the ones that drive real business decisions. If you’ve ever struggled to get your board to engage with your risk reports, this conversation will show you exactly how to bridge the gap.Whether you’re building your next board report, preparing for a budget conversation, or trying to get leadership buy-in, this episode gives you the exact strategies to make cybersecurity a business priority.]]></itunes:summary><itunes:duration>2498</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>You’ve Been Lied to About Cyber Risk Scores</title><link>https://www.spreaker.com/episode/you-ve-been-lied-to-about-cyber-risk-scores--67967692</link><description><![CDATA[If you manage third-party cyber risk, you already know the pain of black-box scores and endless frameworks that miss the point. In this episode, hosts Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik expose the problem nobody talks about: lack of transparency. From regulatory pressure to boardroom confusion, they break down why today’s vendor risk assessments fail to deliver clarity and what to do about it.]]></description><guid isPermaLink="false">fca5813d-83f4-491d-af44-01dbdd54062d</guid><pubDate>Wed, 01 Oct 2025 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67967692/408149697_44100_2_863bbe333e526.mp3" length="33963780" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>If you manage third-party cyber risk, you already know the pain of black-box scores and endless frameworks that miss the point. In this episode, hosts Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik expose the problem nobody talks about: lack of...</itunes:subtitle><itunes:summary><![CDATA[If you manage third-party cyber risk, you already know the pain of black-box scores and endless frameworks that miss the point. In this episode, hosts Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik expose the problem nobody talks about: lack of transparency. From regulatory pressure to boardroom confusion, they break down why today’s vendor risk assessments fail to deliver clarity and what to do about it.]]></itunes:summary><itunes:duration>2123</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f23a76e1a3a94b2dc969d34560d5d57b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Untold Story of Third Party Risk</title><link>https://www.spreaker.com/episode/the-untold-story-of-third-party-risk--67794948</link><description><![CDATA[Third Party is on a mission to pull risk out of the shadows and strip away the jargon, noise, and black-box tools that leave leaders guessing. It’s about clarity, not fear.Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this show blends decades of expertise with curiosity and candid conversation to reframe third party risk in plain English.Whether you’re a CISO, risk manager, or simply someone tasked with owning risks you can’t even see, this show helps you cut through the theater, see what really matters, and make decisions with confidence.]]></description><guid isPermaLink="false">2fd0cff1-0c72-4571-aed9-5f2ee98e6116</guid><pubDate>Wed, 17 Sep 2025 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67794948/407598890_44100_2_f43777617cd9d.mp3" length="1026088" type="audio/mpeg"/><itunes:author>Sweet Fish</itunes:author><itunes:subtitle>Third Party is on a mission to pull risk out of the shadows and strip away the jargon, noise, and black-box tools that leave leaders guessing. It’s about clarity, not fear.Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this show blends...</itunes:subtitle><itunes:summary><![CDATA[Third Party is on a mission to pull risk out of the shadows and strip away the jargon, noise, and black-box tools that leave leaders guessing. It’s about clarity, not fear.Hosted by Bob Maley, Jeffrey Wheatman, and Ferhat Dikbiyik, this show blends decades of expertise with curiosity and candid conversation to reframe third party risk in plain English.Whether you’re a CISO, risk manager, or simply someone tasked with owning risks you can’t even see, this show helps you cut through the theater, see what really matters, and make decisions with confidence.]]></itunes:summary><itunes:duration>65</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5b412f2945fea85d7b445c83e9666629.jpg"/><itunes:episodeType>trailer</itunes:episodeType></item></channel></rss>
