Prevalent’s Brad Hibbert on Rising Third-Party Risks
Brad Hibbert, chief operating officer and chief strategy officer for Prevalent, delves into why awareness of third-party risks is growing thanks to increased reliance on software-as-a-service (SaaS) applications and cloud services infused with generative artificial intelligence (AI) capabilities.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Brad Hibbard, who's Chief operating Officer and Chief Strategy Officer for Prevalent, and we're talking about third party risk and how to manage them because, well, it seems like that's in the news as of late.
Brad, welcome to the show. Yeah, great. Thanks Michael.
Thanks for having me on the show today. We've seen some incidents where, uh, security issues involving a third party vendor wound up crippling all kinds of folks, like maybe half the automotive industry or maybe, uh, some of these healthcare organizations that we see. Yeah.
Um, As we kind of work our way through this, how did we get to this situation where maybe we weren't paying enough attention to the implications of all these third party platforms that we're using, whether they're SaaS applications or some service somewhere. Did we really think through all the security issues? Yeah, look, I, I think, um, I came into Prevalent in 2019, or really, um, from a company called BeyondTrust, where I was more focused on internal risks and, and internal compliance.
And I really saw this was a space that, that, you know, organizations that I was talking to were struggling. They just didn't have any idea of the risks kind of, uh, you know, that they were dealing with every day with respect to their third party. And, uh, the space itself has been around for about 20 years, but I think it kind of came more into the compliance, uh, really around IT vendors where people had to make sure they had IT controls in place to kind of protect systems and around data privacy to make sure they were protecting, protecting access, uh, access to, to the, to the data and so on, stored in those systems.
But it's really evolved since then. Mm-Hmm. And, uh, I think what you mentioned, you know, just a number of, of organizations getting hit, not, not just with, with the, the onslaught of, of, uh, more sophisticated cyber criminals, but but also with the, so the web of moving compliance requirements around supply chain risk and around vendor risk and, and, and so on as well.
Is this something of a covid hangover? I feel like a lot of organizations went out and got a lot of third party services because, well, it was the only game in town back then, but we didn't really, uh, think through a lot of those security issues 'cause we were just trying to keep the doors open. Yeah.
I, I think, I think that's part of it. I mean, I, again, I, I think that, uh, what we saw from Covid, um, was the, the, the design and the scope of the program started to expand. When, when you think about, again, traditional, um, third party risk management, a lot of people just think of IT vendors and, and, um, and, and compliance.
Um, but when Covid hit, um, a couple things happened. One, you had people, as you mentioned very quickly, and they had to make sure that they were secure and they didn't have any internal processes to really, uh, provide that agility that the businesses were looking for, right. To kinda shift their whole business model, to work from home and, and other things and, and kind of get different suppliers on board, maybe more domestic suppliers on board to help them produce their product or, or deliver their service.
I think that was one thing that we saw. Um, the other thing that we saw, and you mentioned it ago again, the call here was that it's not just your IT vendors. You, you know, people saw that they couldn't get product, they couldn't get, uh, uh, a core, a core product or something.
Um, and some of that was just, you know, uh, maybe one of their suppliers was hit by ransomware or their supplier couldn't get things to market. And so the scope of the program started to expand beyond just I, it vendors also include suppliers. So I, I think we started to see, you know, and again, I kind of expand not just in terms of is the data secure, is the it kind of secure, uh, but also from a resilience perspective, you know, how does the resilience of my supply chain look?
And, uh, and that encompassed, you know, all sorts of different types of risks. You know, could it be illegal compliance, you know, sanctions lists, but also, uh, cyber as well. Because again, you know, uh, ransomware and others is, is hitting not just your IT vendors, but your suppliers as well, which is impacting their ability to kind of deliver the goods, uh, that get that, that our clients are, are, are, uh, relying on.
Mm-Hmm. So, yeah, I think it's, uh, I think it accelerated, I don't know if it's the hangover sec, but I think it's kind of here to stay in it. And I think you're also starting to see some of the regulations perk up since Covid, right?
You have the German supply chain, Dora, these other compliance requirements coming up. We now really driving, uh, organizations to have more visibility, uh, over their third parties. Is this gonna get a little worse in the age of ai?
Because it seems to me every time I turn around there's a new tool somebody's playing within in the organization that has some sort of AI driven capability and we're more third party tools than ever. Uh, yeah, a hundred percent. I, I think that, again, it goes down to what's the purpose of the scope of these third party programs.
And, and, um, you know, I think that's why you're starting to see, again, a lot of it's gonna be coming out in a compliance mandate. I think the EU just came on with their AI act, uh, for helping companies understand that if they implement ai, they're not, they're not just, you know, washing their hands of the, of, of their obligations, right? To make sure that they're doing things, uh, correctly and, and securely and fairly.
And so, for example, if your HR department is, is using AI to go through, uh, resumes, you know, and it has some sort of bias or something in the, in the algorithms, you know, you can't just wash your hands of that. So you have to make sure that you're doing the right things on top of your third parties, um, to make sure that they're, you know, kind of not just they're securing access to those systems, but that the algorithms themselves, um, are behaving properly and, and, and if without bias and not harming certain subsets of the population. And, and when you think about all the different areas that, that the businesses are implementing ai, again, I just mentioned hr, but it could be financials and, and all sorts of things as well.
Uh, you have to have a grasp of that and make sure you understand, you know, where those are being implemented throughout your business, how it's gonna be impacted by some of these new ai, uh, compliance requirements coming on board. And then you're gonna have to demonstrate that you're doing your diligence to, to, to adhere to those, uh, uh, those compliance guidelines. Mm-Hmm.
Yeah. Um, Who's in charge of all this these days? I mean, is it the, is it the chief compliance officer?
Is it the COO who's supposed to be stepping up and kind of providing the adult supervision? Yeah, actually that's, that's, uh, almost the a hundred dollars question right there. Um, so I, you know, from, from our perspective, you know, we, we, we've come at this from more of a, um, uh, started off in the V around side vendor risk management, kind of an expanding from there.
So many of our buyers, um, tended to be more the, the security in information security groups focusing on third party risk. Again, many people start the programs with the IT vendors and IT controls. So that was a natural kind of place to, to fit.
Uh, but we are, are, you know, I think over the last couple of years we've seen that certain transition, uh, now we're seeing procurement come to the table quite a bit, again, driven from Dora and some of those other compliance requirements that I mentioned earlier. So procurement certainly has a seat at the table. In some cases they're driving the program that compliance, you know, office comes to, comes to the table as well.
So we're starting to see a kind of a shift. Um, I, I think longer term, uh, and I think if you talk to some of the analysts like Gartner, um, they're gonna tell you the trend is, you know, maybe, maybe it's gonna fit more on under compliance and more under procurement, uh, because it's just another risk that these procurement, you know, uh, uh, uh, focused, uh, sorry, risk focused procurement that teams need, needs to deal with. So I, you know, right now I think it's a bit of a mixed bag, but, but I do think we're starting to see it kind of go more towards, uh, uh, program, uh, more towards procurement as the program, uh, expands and, and more into compliance as well.
We talked a little bit about ai. Do you think we might be applying AI to assess third party risk in a way that will help us maybe get our arms around all this? Because clearly it's spun a little bit outta control, so, uh, do the huge help.
Yeah, that's a great point. You know, it's a great point as well. I, I, I think we're seeing a lot of fatigue in the market.
Like, you know, I'm not sure even ourselves, whenever we, you know, talk to a new prospect or something, we're filling out assessments every day. I know our CISOs ready to pull this area out. Um, so yeah, I, I think that the biggest challenge around this whole space is how do you scale the program efficiently, right?
If I send out a hundred assessments plus I monitoring, but I send out a hundred assessments to a hundred third parties, you have a hundred times a hundred, you know, kind of responses, 10,000 responses, somebody or something needs to analyze. And so there's certainly an opportunity to, to leverage automation and AI to, to help here. Uh, and I, I think I primarily look at it in a couple of different areas.
I think one is just helping people complete the, the, the, the, the assessments. And so for example, if I send you a, an assessment, you might have to look a little different than all the other assessments that you're getting, but really most of 'em are trying to probe specific controls. And if you do have documentation, uh, whether that be policy documentation, ISO documentation, SOC documentation, there should be a way that AI can help you pre-populate as much of those assessments as possible, right?
So here is what we think the answer is to help you kind kind of focus on, you know, validating what the AI is telling you, and then filling out the, the rest of the questionnaires that, that it can't complete. So we certainly have some technology there and we think that's gonna help vendors, you know, respond and improve the program efficiency from that perspective. Uh, and then I think the other area for AI is analyzing all of those responses that are coming in and correlating information across assessments and documents and, and, and all the monitoring solutions that, that your, that your, your, your, your clients may, may be applying to, to, to get a handle on third party risks.
So yeah, I think, I think there's a massive opportunity in, in third party risk management, um, as I think there are other areas of the business where ai, you know, AI can definitely, I think, uh, allow people to kind of scale their, their, their efficiencies and, and, and the program. Uh, so How do I do this continuously? Because to your point, somebody fills out a survey and awesome, we are compliant for 45 seconds.
And so yeah, how do I kind of keep my arms on this thing and it's ever changing? Yeah. You know, it's, it's funny, you know, so I, I go back to what's the, what's the, the purpose of the program and, and, and again, years ago, I think, um, but just on the similarity with things like vulnerability scanning.
People used to scan like once a year, once every two years. And like you said, that's great, but you know, you, you scan on a Friday, you know, what's this thing look like on a Monday, you know, can completely, completely different. And so I think the market's transitioning from this point in time visibility where they're looking for, for more of an authoritative source of risk that's continuously updated around their third parties.
And, um, and, and really what that means is that the programs need to evolve more from a check the box compliance to actually trying to reduce the risk. And, uh, we're certainly seeing a lot more organizations kind of making that maturity move, if you will, from, Hey, this isn't, this is the compliance checkbox anymore, but this is a, this is a significant risk to our business and it needs to be a priority and we need to move beyond that. And, uh, that's why I think, you know, organizations are looking for more sort of data driven platforms that can help pull all this information together from a data perspective, uh, and cut through the noise and help customers focus on the risks that are important to their business, uh, as opposed to just being kind of a workflow or kind of a check box reporting solution, um, maybe from days on by.
Alright. The only thing people are kinda waiting for, the proverbial elephant in the room is, um, there was this ruling around Chevron and a lot of folks were kind of scratching their heads, but the Supreme Court seems to be saying that, uh, the agencies don't have as much authority to enforce the law as they once did. And that may result in more people deciding to, uh, challenge cases.
And, uh, each case could be different. So is the whole world of compliance kinda up in the air right now because everybody's sitting on their hands trying to figure out, well, where are all these pieces gonna land now that it's been turned upside down? Yeah, I, I, yeah, it's, you know, we, we, we'll see where that kind of ends up, but, but I, I think there's more analysis to do there, but I kind of go back to the two drivers, primary drivers for people having these programs.
There's one is, it's, it's checking the compliance box, which, you know, a lot of customers do. Um, those that are more forward thinking or forward leaning that really want to move beyond the compliance check box, the reducing risk, uh, I, I think, you know, I think they're gonna move ahead with, with their programs because at the end of the day, you know, compliance is great, but if you get impacted by one of these third parties, it takes your business down that has a significant impact, not just on recovery from a, you know, a ransomware attack or something like that. So brand, you know, uh, and other types of, uh, of negative impacts to the business that, that organizations are considering.
So I, I do think it's, um, I do think people are considering that, but we certainly aren't seeing a slowdown in people that are looking to kind of get programs up and running with at scale with quality. Uh, I really try to address the risk and remediate the risk as opposed to just doing it from a compliance, uh, search checkbox perspective. All right, my friend.
So what's your best advice to folks? What are the people who are doing all this, right, doing that, others are not? Yeah, I think, you know, like, it's funny.
So we do surveys, you know, every year I think is, you know, I think the last one that we did earlier this year, about 60% of those that we surveyed were impacted by a third party data breach or significant security incident within the last 12 months. And it certainly, it is shaking, as you mentioned, kind of shaking the, these companies a little bit that to wake up to this, to this risk that they have. Um, but you know, even still, I think 80% of customers or prospects that we talk to are still using spreadsheets and, and email and sort of, you know, SharePoint and those sorts of things to try to manage the third party risk.
And so I would just say, you know, first start off with, you know, kind of what, you know, people are looking at doing third party risk management and what, what does that, what is the purpose of scope in the program? Is it kind of check a compliance box? Is it reduce risk?
Is it just around cyber risk? Or do you have to consider sort of the holistic sort of basket of ri of risks that are associated with third parties, late resilience, like you mentioned with Covid? Um, but once you have that, then I think it's just really a, I think from a, from a pragmatic perspective, you know, what, what is your inventory of your critical third parties?
You know, you'd be surprised at how many companies you talk to. They're like, wow, we don't really know. Let me go find out.
So I think start to start with inventorying to third parties to understand how many you have, you know, profile and tier those third parties to understand how many could actually have significant impact to your business in some negative way. Um, and then, you know, what kind of, from there you can start working on what types of diligence would you need to perform against those third parties that, to mitigate those risks, um, that could impact your business. Uh, and then kind of perform, perform the, you know, kind of start to perform that right size, that diligence, perform the activities.
And then most importantly, I, I think, and then where a lot of people fall down, they spend so much time gathering the data, um, which is kind of where automation, to your point, automation could really help. They don't have a lot of time to spend remediating the risks and working with vendors and, and tighten up the contracts around what risks are, are, are that they're, that they're exposing throughout this buildings process. And so I would say, you know, start slow.
You know, don't start with everything. Maybe start with your, your top, you know, 25, 50 third parties and, and just start, kind of, don't boil the ocean, but, but kind of get the program up and running, show some success and, and, and then grow it from there. Alright, folks, you heard it here.
First order of businesses, inventory, all those things that might represent risk and then determine what your real appetite is for all of that. Hey Brad, thanks for being on the show. Yeah, thanks for having me.