Helping CISOs, risk teams, and boards understand third-party, supply chain, regulatory, and AI risk. I write practical briefings on the dependencies, controls, and evidence security leaders need when risk moves outside the perimeter.
Updated Daily Daily TPRM & Supply Chain Incident Monitor: new vendor, cyber supply chain, logistics, and supplier-continuity signals. Open monitor --I work at the intersection of cybersecurity, third-party risk, and supply chain resilience, helping organizations understand, assess, and manage the risks that come with relying on vendors, partners, and complex ecosystems. Whether it’s a gap analysis against NIS2, a compliance assessment under DORA, or building a practical Identity and Access Management (IAM) framework, my focus is always the same: making security work in the real world, not just on paper.
This site is where I think out loud. You’ll find writing on risk management, third-party security, compliance, and the tools and ideas that help turn complex requirements into practical programs.
When I’m not focused on security and risk, I’m probably tending the garden, training for my next Ironman, or spending quality time with my family.
A board-level view of third-party cyber risk: critical dependencies, evidence, decisions, escalation, and resilience.
Supplier risk programs fail when supplier, service, evidence, ownership, and dependency data are fragmented across tools and spreadsheets.
Why vendor questionnaires consume so much effort and how to redesign them around risk decisions rather than document collection.
How NIS2 expectations cascade through supplier ecosystems and why small suppliers can create large cyber risk.
A practical guide to building a third-party risk program that moves beyond questionnaires and creates real supplier risk governance.
NIS2 and DORA move cybersecurity governance into the boardroom. Management teams need evidence that they understand cyber risk, supplier dependencies, resilience, and incident response.
AI has quietly become one of the most concentrated, least-governed supply chains in the enterprise — and many organizations still cannot explain which models, providers, agents, and data flows they depend on.
The supply chain is now the primary way enterprise cyber risk materializes - here's what the numbers, the incidents, and the attackers themselves tell us about it.
Regulators, critical suppliers, and the uncomfortable truth that third-party risk is no longer procurement paperwork but a core security and resilience obligation.
CRA reporting, update integrity, supplier API credentials, federated identity and cloud resilience translated into concrete control actions.
Hormuz disruption, energy supply, UK Iran sanctions, trade divergence and rare-earth concentration with actionable decision triggers.
A recurring monitoring stream focused on vendor incidents, control weaknesses, concentration risk, regulatory expectations, and operational signals that matter to third-party risk and resilience teams.
A recurring monitoring stream focused on sanctions, regional instability, trade restrictions, chokepoints, strategic dependencies, and geopolitical developments that can materially affect suppliers, logistics, and operational resilience.
Critical third-party risk signals covering software supply chain compromise, AI Act transparency deadlines, DORA enforcement, NIS2, cybersecurity M&A, and vendor concentration risks.
Geopolitical supply chain risk signals covering sanctions pressure, semiconductor dependencies, Red Sea disruption, China exposure, and resilience measures for critical vendors.
Vendor incidents, supplier control gaps, regulatory pressure points, and notable third-party risk signals observed during April 2026.
Map a critical service to supplier, owner, data, access, evidence, contract, issue, and dependency information, then export a prioritised action register.
A lightweight annual operating calendar for recurring GRC, supplier risk, resilience, audit-readiness, and board reporting activities.
Led a NIS2 gap analysis, mapping regulatory requirements alongside ISO 27001, ISAE3402, and SOC2 to the organization's internal control environment — a critical step in understanding supply chain exposure.
Assessed DORA compliance for a cryptocurrency and digital finance company, focusing on operational resilience in a space where third-party dependencies are evolving faster than regulations.
Performed a combined NIS2 and NIST gap analysis, advising on practical strategies to close compliance gaps across vendor-dependent infrastructure.
Oversaw the IT components of external financial statement audits, digging into access management, incident response, and change management processes — all areas where third-party risk often hides in plain sight.
Conducted IT and SWIFT audits, revising internal policies that directly impact how third-party transactions and communications are secured.
Developed and formalized IAM policies, strengthening the security posture across a supply chain that depends heavily on external partners and systems.
Guided the implementation and certification of ISO 27001:2022, building a security management system designed to scale with third-party growth.
Working on something in the risk space?
Let's talk.