Cyber Security In Focus
Managing third-party risk has always been complex. Add AI into the supply chain, and the rules change entirely. In this episode, Katie Watson sits down with Chris Thornberry, Information Security Manager and DPO at Oleeo, an HR Tech SaaS platform serving major UK public sector organisations and global financial services institutions. With over six years navigating security at the intersection of GRC and technical resilience, Chris brings a grounded, pragmatic perspective on what robust third-party risk management actually looks like in practice. Chris and Katie dig into why certifications like ISO 27001 and SOC 2 are no longer enough on their own, what transparency really means when you're assessing an AI supplier's entire ecosystem, not just the supplier themselves, and how to avoid shadow AI taking hold before you've had the chance to assess it. They also cover the dual challenge of operating as both a data processor and a data controller, how to build a security culture that stops bottlenecks before they start, and why Chris uses data as his North Star when evaluating any new tool or vendor. If you're responsible for third-party risk and feeling the pressure of AI reshaping your supply chain, this is a practical conversation worth your time.
11 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y forma parte de la comunidad de Cyber Security In Focus!