Security at AI Speed: Supply Chain Risk, Big Data & the Questionnaire Myth with Mike Johnson
The TPRM Podcast
Third-party risk management requires a shift from generic, ineffective security questionnaires toward building genuine relationships and leveraging data-driven insights. Security leaders must treat security data as a big data problem, prioritizing normalization and aggregation to enable scalable detection engineering. Modern security programs should move beyond static assessments, instead focusing on "secure by design" principles and proactive monitoring of critical infrastructure, such as API tokens. As attackers increasingly weaponize vulnerabilities at internet speed, defenders gain an advantage by utilizing internal context and data science capabilities to identify anomalous patterns. Rather than relying on superficial compliance checks, organizations should establish minimum viable security standards and foster collaboration between security and data teams to effectively manage the growing volume of security telemetry and evolving supply chain threats. Mike Johnson, CISO of Rivian, emphasizes these pragmatic approaches to navigating the complexities of modern, large-scale infrastructure security.
Sign in to continue reading, translating and more.
Open full episode in Podwise