Practice, at length.
A Speak to It™ term tells you what something is. This is where the same subject is worked through properly: what good looks like, what to require, how to evidence it, and where most teams get it wrong.
289 written, 1405 more commissioned. Free to read, because a common professional vocabulary should not depend on ability to pay.
Build Pipeline Integrity
Production Environment: Secured. CI/CD Pipeline: 12 Third-Party Integrations. 7 Running on Production Credentials. 1 With Authentication Bypass.
4 min read · 13 Sep 2026
Vendor Patch Cadence Reality
Patch Policy: 30 Days. Average Actual Patch Time: 73 Days. Unpatched Critical Vulnerabilities: 4 of 14. Policy: Confirmed. Adherence: Not Measured.
4 min read · 11 Sep 2026
Artifact Registry Security
Artifact: Signed. Registry: Mutable. Write Access: 17 Accounts. Former Employee Accounts: 3 Still Active.
4 min read · 8 Sep 2026
Supply Chain Attack Detection
SOC Coverage: Excellent. Detection Infrastructure: Production-Focused. Build Pipeline: Not Monitored. Compromise: 8 Months Undetected.
5 min read · 6 Sep 2026
Branch Protection and Code Review Bypasses
Branch Protection: Configured. Admin Access: Never Revoked from Incident Response. Bypass: Direct Push to Main. Code Review: None. Hardcoded Key and Path Traversal: Introduced.
5 min read · 3 Sep 2026
Code Signing and Its Limits
Signature: Valid. Certificate: From Recognised CA. Key: Compromised 11 Months Prior. All Releases Since: Potentially Attacker-Signed.
5 min read · 1 Sep 2026
Container Image Supply Chain
Application Code: Reviewed. Container Base Image: 4 Months Outdated. System Library CVEs: 17. Critical RCEs: 2.
4 min read · 29 Aug 2026
Dependency Confusion Attacks
Internal Package: acme-internal-utils. Job Posting: Mentioned Internal Tooling. Public Registry: Attacker Published Same Name, Higher Version. 23 Applications: Compromised.
4 min read · 27 Aug 2026
Dependency Pinning vs Floating Versions
Version Spec: >=2.0.0. New Version Published Thursday: 2.4.0. Tests: Passed Thursday. Production: Deployed Different Software Friday.
4 min read · 24 Aug 2026
Vendor Development Environment Security
Production: Secured. Developer Workstations: Local Admin. Credentials in Dotfiles. Personal GitHub Accounts for Work. Malicious VSCode Extensions Installed.
4 min read · 22 Aug 2026
Vendor Security Disclosure Programmes
Disclosure Programme: Published. Report: Submitted. Acknowledged: Yes. Patched Within 7 Months: No. Advance Notice to Customers: Zero.
4 min read · 19 Aug 2026
The Future of Software Supply Chain Security
Current Programme: Current for Today. AI-Generated Code: In Vendor Pipelines Now. Post-Quantum: On the Timeline. Regulatory Acceleration: Already Landed.
4 min read · 17 Aug 2026
Infrastructure-as-Code Supply Chain Risk
IaC: Reviewed. Third-Party Terraform Modules: 14 Months Stale. Security Group: Management Ports Open to 0.0.0.0/0. Module Review: Not Conducted.
4 min read · 14 Aug 2026
Supply Chain Incident Response
IR Programme: Mature for Production Incidents. Supply Chain Playbook: None. Affected Release Identification: No Process. Customer Deployment Inventory: Not Maintained.
4 min read · 12 Aug 2026
Open Source License Risk
Platform Deployed: 18 Months. AGPL Component: Discovered by Legal. Disclosure Requirement: Potentially Applies to Vendor's Proprietary Code. Legal Review: 6 Months.
4 min read · 9 Aug 2026
Supply Chain Risk in Mergers and Acquisitions
Platform Acquired. Open-Source Dependencies: 1,247. Critical Vulnerabilities: 73. Unresolvable Due to EOL: 14. Runtime: 3 Major Versions Behind. Due Diligence: No Supply Chain Assessment.
4 min read · 7 Aug 2026
Supply Chain Security Maturity Assessment
SBOM: Level 3. SCA: Level 3. SLSA: Level 0 (Unaware). Build Pipeline Security: Level 1. Supply Chain Monitoring: Level 0.
4 min read · 4 Aug 2026
NIST SP 800-161 for Practitioners
NIST 800-161: Reviewed and Considered Aligned. Implementation Tier: Not Assessed. Controls Implemented: Not Verified.
4 min read · 2 Aug 2026
Vendor Open Source Contribution Risk
Engineer: 3 Years Trusted Contributions. Employee Status: Departed. PR: Backdoor. Merge: Approved Based on Reputation. Affected Vendors: 14.
4 min read · 30 Jul 2026
Package Registry Trust Model
Package: Legitimate. Maintainer: Compromised via Social Engineering. Version Update: Bug Fix + Credential Harvesting. Downloads: 14,000 Weekly.
4 min read · 28 Jul 2026
Supply Chain Security in Regulated Industries
FDA SBOM Requirement: Met. Critical CVEs in SBOM: 17. VEX Documentation: Not Provided. Regulatory Review Delay: 4 Months.
4 min read · 25 Jul 2026
Reproducible Builds in Practice
500 Packages Analysed. 312: Reproducible. 188: Not Reproducible. The 188: Source Code Does Not Uniquely Determine Binary.
4 min read · 23 Jul 2026
Supply Chain Risk Quantification
Risk Ratings: High, Medium, High. Financial Exposure: Not Calculated. Board Communication: Not Possible. Investment Justification: Not Available.
4 min read · 20 Jul 2026
Programming Language Runtime Security
Platform: Well-Patched Application Code. Runtime: Python 3.9, EOL October 2025. Critical Runtime CVEs: 3. Future Patches: None.
4 min read · 18 Jul 2026
Software Bill of Materials Automation
847 SBOM Documents. 7 Formats. 93% Never Parsed. 41% Over 12 Months Old. Supply Chain Visibility: None.
4 min read · 15 Jul 2026
Software Bill of Materials , Beyond the Mandate
SBOM: Provided. Critical Vulnerabilities Listed: 14. SBOM Age: 6 Months. Vulnerability Status: Not Included. Regulator: Not Satisfied.
4 min read · 13 Jul 2026
Software Composition Analysis Gaps
SCA Configured: Main Branch, Python Only, CVE IDs Only. Uncovered: 7 Repositories, Go and Java Services, Non-CVE Issues.
4 min read · 10 Jul 2026
Third-Party SDK Risk
SDK Evaluated at Integration. Vendor Acquired 18 Months Later. SDK Updated: New Data Collection. Enterprise Privacy Policy: Not Reflecting New Collection.
4 min read · 8 Jul 2026
What Is SLSA and Why Your Vendors Should Care
SLSA Compliant: Confirmed. SLSA Level: 1. What Level 1 Means: Build Process is Documented. What It Doesn't Mean: Build Is Tamper-Resistant.
6 min read · 5 Jul 2026
Software Supply Chain for SaaS Products
Installed Software: SBOM, SCA, Provenance Verification. SaaS Platform: Same Supply Chain Risk. Visibility: None.
4 min read · 3 Jul 2026
Secrets in Source Code
Policy: No Hardcoded Credentials. Git History: AWS Key, Database Credentials, RSA Key , 31 Months. Status: Technically Still There.
4 min read · 30 Jun 2026
Sigstore and the Transparency Log Revolution
Signing Key: File on Build Server, 3 Years Unrotated. Sigstore: Free, Short-Lived Certificates, Public Audit Log. Vendor Awareness: None.
4 min read · 28 Jun 2026
Software Provenance Verification
Signature: Valid. Delivery: HTTPS. Download URL: Legitimate. Distribution Infrastructure: Compromised 3 Weeks Prior. Software: Attacker's.
5 min read · 25 Jun 2026
The SolarWinds Lessons Still Unlearned
SolarWinds: 2020. Assessment Checklist: Same Questions as 2019. Build Pipeline: Not Asked About.
4 min read · 23 Jun 2026
Threat Intelligence for Supply Chain Attacks
Threat Intel Report: Received. CI/CD and SDK Targeting: Described. Vendor Assessments Updated: No. Two Vendors Targeted: 6 Months Later.
4 min read · 20 Jun 2026
Transitive Dependency Risk
Direct Dependencies: Zero Critical Vulnerabilities. Transitive Dependency Depth 4: Critical Vulnerability. SCA Scope: Direct Dependencies. Depth 4: Out of Scope.
4 min read · 18 Jun 2026
Typosquatting in Package Registries
Legitimate Package: lodash. Typosquatted: lodash-utils. Downloads: 43,000. Production Deployments: 312. CVE: None. SCA Alert: None.
4 min read · 15 Jun 2026
Software Update Mechanism Security
Auto-Update: Enabled by Default. Certificate: Compromised 3 Months Prior. Updates Applied: Potentially Compromised. Enterprise Aware: No.
4 min read · 13 Jun 2026
VEX , Vulnerability Exploitability eXchange
SCA Findings: 312. Actually Exploitable: 23. VEX Available: No. Triage Time: 3 Weeks.
4 min read · 11 Jun 2026
Zero Trust for Software Supply Chains
Network: Zero Trust. Dependencies: Pulled Without Publisher Verification. Build Agents: Broad Credentials. Software Updates: Server Identity from HTTPS Certificate Only.
5 min read · 10 Jun 2026
Software Supply Chain Security
SLSA, SBOM, and the Hidden Risk in Every Line of Code You Trust
6 min read · 9 Jun 2026
Vendor Access Creep Over Time
Original Access: Read-Only Names and Emails. Three Years Later: Five Data Categories. Four Expansions: Zero TPRM Reviews.
4 min read · 8 Jun 2026
TPRM Programme Automation and Its Limits
Automation Deployed. Efficiency: Doubled. Assessment Quality: Same as the Unvalidated Questionnaire Responses It Automated.
4 min read · 7 Jun 2026
TPRM Board and Executive Reporting
Board Report: Assessments, Tiers, Findings, Heat Map. Board Question: Biggest Unmanaged Risk Right Now? Answer: Not in the Report.
4 min read · 6 Jun 2026
TPRM as a Business Enabler
Procurement: 2-Week Deadline. Standard Assessment: 4-6 Weeks. Risk-Tiered Assessment: 8 Days. Finding: Identified and Remediated Before Go-Live.
5 min read · 5 Jun 2026
Cloud Provider Shared Responsibility in TPRM
AWS: SOC 2, ISO 27001, FedRAMP. Enterprise Cloud Configuration: Public Buckets, Excessive Permissions, Logging Disabled.
4 min read · 4 Jun 2026
Continuous Monitoring vs Point-in-Time Assessment
January Assessment: Accurate. March: Cloud Migration. June: Ransomware. September: CISO Departed. November: Still January's Data.
4 min read · 3 Jun 2026
Contract Security Requirements Enforcement
Security Addendum: Comprehensive. Enforcement: Three Years, Never Exercised. Encryption at Rest: Not Implemented.
4 min read · 2 Jun 2026
Vendor Data Handling Agreement Gaps
Data Sharing Agreement: Specifies Categories, Retention, Purpose. Model Training Use: Not Prohibited. Vendor Policy Change: Discovered Through Alert Service.
4 min read · 1 Jun 2026
Due Diligence Depth vs Vendor Tier
SOC 2: Confirmed Exists. Fourteen Controls Tested by Policy Review Only. Due Diligence: Checked the Box.
4 min read · 31 May 2026
Critical Vendor Exit Strategy Planning
Acquisition Notice: 6 Months to Support End. Exit Strategy: None. Integration Inventory: None. Evaluated Alternatives: None. Timeline: 7 Years of Integration to Unwind.
4 min read · 30 May 2026
Vendor Financial Health as TPRM Signal
Revenue Shock: 38% Customer Loss. Security Team: -40%. SOC 2: Deferred. Pentest: Cancelled. Last Assessment: 8 Months Ago, Low Risk.
4 min read · 29 May 2026
Fourth-Party Risk Blindness
ERP Vendor: Thoroughly Assessed. AWS, Auth Provider, AI Vendor, Hosting Provider: Not Assessed by Anyone.
4 min read · 28 May 2026
The Future of TPRM , From Assurance to Intelligence
847 Vendors Assessed. 2,341 Questionnaires. 1,847 Findings. Predictive Model: Not Built. Intelligence Waiting to Be Used.
5 min read · 27 May 2026
Geopolitical Risk in Vendor Selection
Data: EU-Hosted. Engineering Team: Jurisdiction with Government Access Law. Data Location: Protected. Data Access Personnel: Not.
4 min read · 26 May 2026
Vendor Incident Notification Failures
Breach: Tuesday. Discovered: Wednesday. Contract: 72 Hours. Notified: Monday. News Article: Friday. Enterprise Found Out: Friday.
4 min read · 25 May 2026
Inherent Risk Tiering
200-Question Questionnaire. Law Firm: Same as Cloud Platform. 180 Not-Applicables. 40 Missing Architecture Questions.
6 min read · 24 May 2026
TPRM for Mergers and Acquisitions
Acquisition Closed. Integration: Day One. TPRM Assessment of Acquired Vendor Portfolio: 18 Months Later. 12 Unassessed Critical Vendors Connected to Enterprise Network.
4 min read · 23 May 2026
Managed Service Provider TPRM Complexity
MSP: Thoroughly Assessed. MSP Subprocessors: 23. Subprocessors with Production System Access: 6. Assessed by Enterprise: 0.
4 min read · 22 May 2026
TPRM Programme Maturity Models
Self-Assessment: Level 3. Regulator: Level 3 for Tiering and Documentation. Level 1 for Monitoring, Fourth-Party, and Exit Planning.
4 min read · 21 May 2026
Open Source as a Third-Party Risk
Commercial Vendors: 847 Assessed. Open-Source Libraries: 847 Unassessed. Critical Vulnerability: 14 Applications Affected. Inventory: None.
3 min read · 20 May 2026
Outsourcing Risk vs Outsourcing Responsibility
Activity Outsourced. Liability Limitation: $240K Contract Value. Regulatory Fine: $1.8M. Accountability: Not Outsourceable.
4 min read · 19 May 2026
TPRM Ownership and Accountability Gaps
Critical Finding: Open 6 Months. TPRM Team: Business Owner's Responsibility. Business Owner: No Technical Authority. Vendor: No Formal Request Received.
4 min read · 18 May 2026
TPRM Programme Metrics & KPIs
Assessments: 847. Questionnaires: 2,341. Completion Rate: 94%. Risk Reduction: Not Measured.
4 min read · 17 May 2026
TPRM Questionnaire Design Failures
187 Questions. 14 Days to Complete. 6 Hours to Review. 40 Questions Genuinely Informative. 147: Noise.
4 min read · 16 May 2026
Vendor Security Questionnaire Fatigue
14 Questionnaires in Q4. 340 Hours. 3-Person Security Team. 3 Weeks Displaced. Same Facts: 14 Formats.
4 min read · 15 May 2026
Tiered Reassessment Frequency
Marketing Agency: Annual Reassessment. Cloud Data Platform: Also Annual Reassessment. Risk: Not Equivalent. Cadence: Identical.
4 min read · 14 May 2026
Regulatory Mapping in TPRM
TPRM Programme: SOC 2 and NIST CSF Aligned. DORA Gap Analysis: 40% Not Covered. Regulation: Changed. Programme: Same.
4 min read · 13 May 2026
Inherent vs Residual Risk Confusion
Inherent Risk: High. Controls: Strong. Residual Risk: 2/10. Breach: In System Not Covered by the Controls Assessed.
4 min read · 12 May 2026
Vendor Resilience Testing and Tabletop Exercises
Vendor SLA: 99.9%. Manual Fallback: Documented. Tabletop Result: 4 Processes With No Fallback. Estimated Recovery: 11 Days.
4 min read · 11 May 2026
Right-to-Audit Clauses in Practice
Right-to-Audit: Negotiated into Every Critical Contract. Exercised: Once in Four Years. Audit Quality: 'Unlikely to Withstand Regulatory Scrutiny.'
4 min read · 10 May 2026
Risk Acceptance Governance
Critical Finding: Escalated. Business Owner: Signed Acceptance. Finding: Closed. Risk: Unmanaged for Two Years. Outage: 36 Hours.
4 min read · 9 May 2026
Vendor Risk Appetite Alignment
Finding: No MFA on Admin Accounts. Cost to Fix: $47K. Business Owner: Accepted Risk. Risk Framework: Prohibits This Acceptance.
4 min read · 8 May 2026
Vendor Risk Register Accuracy
Risk Register: 312 Entries. Last Full Review: 8 Months Ago. Offboarded Vendors Still Listed. New Vendors Missing. Three Breaches Unupdated.
4 min read · 7 May 2026
SaaS Security Posture vs Traditional Vendor Assessment
SOC 2: Confirmed. SSPM Scan: 312 Inactive Accounts, 23 Over-Privileged, 14 Unrotated API Tokens. Same Vendor. Different Picture.
3 min read · 6 May 2026
Subprocessor Visibility
DPA Subprocessors: 12. Production Subprocessors: 18. The Six Gap: Background Check API, Fraud Detection, Cloud Logging.
4 min read · 5 May 2026
Vendor Business Continuity & Resilience
Uptime SLA: 99.9%. BCP Tested: Never Asked. Backup: Same Region. Recovery Time: 11 Days. SLA: 4 Hours.
4 min read · 4 May 2026
Vendor Concentration Risk
43% Revenue through One Vendor. 67% Infrastructure: One Provider. 81% Support: One Platform. Each Green. Together: Existential.
4 min read · 3 May 2026
Vendor Inventory Completeness
TPRM Inventory: 847 Vendors. Procurement Master: 2,341. The Gap: 1,494 Vendors Nobody Was Managing.
7 min read · 2 May 2026
Vendor Offboarding Risk
Contract: Closed. API Keys: Active. User Accounts: Two Remaining. Data Extract: Still at Vendor. IP Allowlist: Never Removed.
4 min read · 1 May 2026
Vendor Onboarding Security Gates
Contract Signed Monday. Production Data Access: Sunday. TPRM Notified: Previous Friday. Assessment: Three Weeks Later.
4 min read · 30 Apr 2026