{"id":17439,"date":"2026-02-26T09:47:26","date_gmt":"2026-02-26T14:47:26","guid":{"rendered":"https:\/\/ndisac.org\/dibscc\/?post_type=tribe_events&#038;p=17439"},"modified":"2026-02-26T09:47:26","modified_gmt":"2026-02-26T14:47:26","slug":"sans-trust-your-vendors-do-you","status":"publish","type":"tribe_events","link":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/","title":{"rendered":"SANS &#8211; Trust Your Vendors, Do You?"},"content":{"rendered":"<p>Organizations increasingly depend on vast ecosystems of thirdparty vendors, expanding their operational capacity\u2014but also their attack surface and risk exposure. This talk challenges trustby-default approaches to vendor relationships and makes the case for a modern, thirdparty risk management (TPRM) program. We begin by framing why vendor risk matters, examine realworld breach case studies to illustrate how upstream dependencies and fourthparty links can amplify impact. The session will highlight regulatory drivers\u2014NIS2, DORA, and GDPR\u2014and translates them into practical expectations for supplychain security, continuous oversight, and incident reporting. We analyze limitations of traditional questionnaires (SIG\/CAIQ), which are static, selfreported, and often out of date, and propose a continuous TPRM lifecycle: riskbased vendor tiering, due diligence proportional to criticality, automated external posture monitoring, corrective action tracking, and secure offboarding.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Organizations increasingly depend on vast ecosystems of thirdparty vendors, expanding their operational capacity\u2014but also their attack surface and risk exposure. This talk challenges trustby-default approaches to vendor relationships and makes [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_tribe_events_status":"","_tribe_events_status_reason":"","footnotes":""},"tags":[],"tribe_events_cat":[],"class_list":["post-17439","tribe_events","type-tribe_events","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist<\/title>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist\" \/>\n<meta property=\"og:description\" content=\"Organizations increasingly depend on vast ecosystems of thirdparty vendors, expanding their operational capacity\u2014but also their attack surface and risk exposure. This talk challenges trustby-default approaches to vendor relationships and makes [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/\" \/>\n<meta property=\"og:site_name\" content=\"DIB SCC CyberAssist\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/\",\"url\":\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/\",\"name\":\"SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist\",\"isPartOf\":{\"@id\":\"https:\/\/ndisac.org\/dibscc\/#website\"},\"datePublished\":\"2026-02-26T14:47:26+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ndisac.org\/dibscc\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Events\",\"item\":\"https:\/\/ndisac.org\/dibscc\/events\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SANS &#8211; Trust Your Vendors, Do You?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ndisac.org\/dibscc\/#website\",\"url\":\"https:\/\/ndisac.org\/dibscc\/\",\"name\":\"DIB SCC CyberAssist\",\"description\":\"Cybersecurity Resources for DIB companies and suppliers\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ndisac.org\/dibscc\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist","og_description":"Organizations increasingly depend on vast ecosystems of thirdparty vendors, expanding their operational capacity\u2014but also their attack surface and risk exposure. This talk challenges trustby-default approaches to vendor relationships and makes [&hellip;]","og_url":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/","og_site_name":"DIB SCC CyberAssist","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/","url":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/","name":"SANS - Trust Your Vendors, Do You? - DIB SCC CyberAssist","isPartOf":{"@id":"https:\/\/ndisac.org\/dibscc\/#website"},"datePublished":"2026-02-26T14:47:26+00:00","breadcrumb":{"@id":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/ndisac.org\/dibscc\/events\/sans-trust-your-vendors-do-you\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ndisac.org\/dibscc\/"},{"@type":"ListItem","position":2,"name":"Events","item":"https:\/\/ndisac.org\/dibscc\/events\/"},{"@type":"ListItem","position":3,"name":"SANS &#8211; Trust Your Vendors, Do You?"}]},{"@type":"WebSite","@id":"https:\/\/ndisac.org\/dibscc\/#website","url":"https:\/\/ndisac.org\/dibscc\/","name":"DIB SCC CyberAssist","description":"Cybersecurity Resources for DIB companies and suppliers","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ndisac.org\/dibscc\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tribe_events\/17439"}],"collection":[{"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tribe_events"}],"about":[{"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/types\/tribe_events"}],"author":[{"embeddable":true,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/comments?post=17439"}],"version-history":[{"count":1,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tribe_events\/17439\/revisions"}],"predecessor-version":[{"id":17441,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tribe_events\/17439\/revisions\/17441"}],"wp:attachment":[{"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/media?parent=17439"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tags?post=17439"},{"taxonomy":"tribe_events_cat","embeddable":true,"href":"https:\/\/ndisac.org\/dibscc\/wp-json\/wp\/v2\/tribe_events_cat?post=17439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}