New daily monitor TPRM and supply chain incidents with practical hot fixes
Cyber · Third-Party Risk · Supply Chain

Gabriel
Hasik

Helping CISOs, risk teams, and boards understand third-party, supply chain, regulatory, and AI risk. I write practical briefings on the dependencies, controls, and evidence security leaders need when risk moves outside the perimeter.

Updated Daily Daily TPRM & Supply Chain Incident Monitor: new vendor, cyber supply chain, logistics, and supplier-continuity signals. Open monitor --
Open daily monitor Read latest briefing Work with me
Cybersecurity Third-Party Risk Supply Chain Security AI Governance
Scroll
01 — About

I work at the intersection of cybersecurity, third-party risk, and supply chain resilience, helping organizations understand, assess, and manage the risks that come with relying on vendors, partners, and complex ecosystems. Whether it’s a gap analysis against NIS2, a compliance assessment under DORA, or building a practical Identity and Access Management (IAM) framework, my focus is always the same: making security work in the real world, not just on paper.

This site is where I think out loud. You’ll find writing on risk management, third-party security, compliance, and the tools and ideas that help turn complex requirements into practical programs.

When I’m not focused on security and risk, I’m probably tending the garden, training for my next Ironman, or spending quality time with my family.

02 — Writing

Selected Articles

Board Governance September 2026

What Boards Actually Need to Know About Third-Party Cyber Risk

A board-level view of third-party cyber risk: critical dependencies, evidence, decisions, escalation, and resilience.

Risk Data September 2026

Why Supplier Risk Is a Data Problem Before It Is a Compliance Problem

Supplier risk programs fail when supplier, service, evidence, ownership, and dependency data are fragmented across tools and spreadsheets.

Third-Party Risk September 2026

The Hidden Cost of Vendor Questionnaires

Why vendor questionnaires consume so much effort and how to redesign them around risk decisions rather than document collection.

NIS2 & Supply Chain August 2026

NIS2 and the Extended Supply Chain: When Your Small Supplier Becomes Your Biggest Risk

How NIS2 expectations cascade through supplier ecosystems and why small suppliers can create large cyber risk.

Third-Party Risk August 2026

From Checkbox to Culture: Building a Third-Party Risk Program That Actually Works

A practical guide to building a third-party risk program that moves beyond questionnaires and creates real supplier risk governance.

Governance August 2026

Cybersecurity Is Now a Board Problem — Personal Liability Under NIS2 and DORA

NIS2 and DORA move cybersecurity governance into the boardroom. Management teams need evidence that they understand cyber risk, supplier dependencies, resilience, and incident response.

AI Supply Chain May 2026

AI Is Now a Supply Chain Risk — and Most Boards Can't Answer Basic Questions About It

AI has quietly become one of the most concentrated, least-governed supply chains in the enterprise — and many organizations still cannot explain which models, providers, agents, and data flows they depend on.

Supply Chain April 2026

The Supply Chain is Now The Biggest Cyber Threat - Here's What The Numbers Say

The supply chain is now the primary way enterprise cyber risk materializes - here's what the numbers, the incidents, and the attackers themselves tell us about it.

Cyber April 2026

What Regulators Now Require for Supply Chain Security

Regulators, critical suppliers, and the uncomfortable truth that third-party risk is no longer procurement paperwork but a core security and resilience obligation.

View all articles --
03 — Monitoring & Intelligence

Recurring Industry Monitoring

TPRM September 2026

Third-Party Risk Intelligence Briefing - September 2026

CRA reporting, update integrity, supplier API credentials, federated identity and cloud resilience translated into concrete control actions.

Supply Chain September 2026

Geopolitical Supply Chain Risks - September 2026

Hormuz disruption, energy supply, UK Iran sanctions, trade divergence and rare-earth concentration with actionable decision triggers.

TPRM August 2026

Third-Party Risk Intelligence Briefing - June to August 2026

A recurring monitoring stream focused on vendor incidents, control weaknesses, concentration risk, regulatory expectations, and operational signals that matter to third-party risk and resilience teams.

Supply Chain August 2026

Geopolitical Supply Chain Risks - June to August 2026

A recurring monitoring stream focused on sanctions, regional instability, trade restrictions, chokepoints, strategic dependencies, and geopolitical developments that can materially affect suppliers, logistics, and operational resilience.

TPRM May 2026

Third-Party Risk Intelligence Briefing - May 2026

Critical third-party risk signals covering software supply chain compromise, AI Act transparency deadlines, DORA enforcement, NIS2, cybersecurity M&A, and vendor concentration risks.

Supply Chain May 2026

Geopolitical Supply Chain Risks - May 2026

Geopolitical supply chain risk signals covering sanctions pressure, semiconductor dependencies, Red Sea disruption, China exposure, and resilience measures for critical vendors.

TPRM April 2026

Third-Party Risk Intelligence Briefing - April 2026

Vendor incidents, supplier control gaps, regulatory pressure points, and notable third-party risk signals observed during April 2026.

View all monitoring --
04 — Tools

Practical Tools

Supplier Risk Interactive

Supplier Risk Data Mapper

Map a critical service to supplier, owner, data, access, evidence, contract, issue, and dependency information, then export a prioritised action register.

GRC Calendar Excel

A Practical GRC Calendar for CIOs and CISOs

A lightweight annual operating calendar for recurring GRC, supplier risk, resilience, audit-readiness, and board reporting activities.

View all tools --
05 — Projects

Where I've Made an Impact

01

Energy Sector

Led a NIS2 gap analysis, mapping regulatory requirements alongside ISO 27001, ISAE3402, and SOC2 to the organization's internal control environment — a critical step in understanding supply chain exposure.

NIS2 ISO 27001 SOC2
02

Crypto & Digital Finance

Assessed DORA compliance for a cryptocurrency and digital finance company, focusing on operational resilience in a space where third-party dependencies are evolving faster than regulations.

DORA Operational Resilience Third-Party Risk
03

Utilities

Performed a combined NIS2 and NIST gap analysis, advising on practical strategies to close compliance gaps across vendor-dependent infrastructure.

NIS2 NIST Gap Analysis
04

Banking & Financial Services

Oversaw the IT components of external financial statement audits, digging into access management, incident response, and change management processes — all areas where third-party risk often hides in plain sight.

IT Audit IAM Incident Response
05

Export Banking

Conducted IT and SWIFT audits, revising internal policies that directly impact how third-party transactions and communications are secured.

SWIFT IT Audit Policy Review
06

Retail

Developed and formalized IAM policies, strengthening the security posture across a supply chain that depends heavily on external partners and systems.

IAM Policy Design Supply Chain Security
07

Professional Services

Guided the implementation and certification of ISO 27001:2022, building a security management system designed to scale with third-party growth.

ISO 27001:2022 ISMS Certification
06 — Newsletter
07 — Contact

Working on something in the risk space?
Let's talk.