DeepDive

Practice, at length.

A Speak to It™ term tells you what something is. This is where the same subject is worked through properly: what good looks like, what to require, how to evidence it, and where most teams get it wrong.

289 written, 1405 more commissioned. Free to read, because a common professional vocabulary should not depend on ability to pay.

Third-party oversight

Build Pipeline Integrity

Production Environment: Secured. CI/CD Pipeline: 12 Third-Party Integrations. 7 Running on Production Credentials. 1 With Authentication Bypass.

4 min read · 13 Sep 2026

Third-party oversight

Vendor Patch Cadence Reality

Patch Policy: 30 Days. Average Actual Patch Time: 73 Days. Unpatched Critical Vulnerabilities: 4 of 14. Policy: Confirmed. Adherence: Not Measured.

4 min read · 11 Sep 2026

Third-party oversight

Artifact Registry Security

Artifact: Signed. Registry: Mutable. Write Access: 17 Accounts. Former Employee Accounts: 3 Still Active.

4 min read · 8 Sep 2026

Third-party oversight

Supply Chain Attack Detection

SOC Coverage: Excellent. Detection Infrastructure: Production-Focused. Build Pipeline: Not Monitored. Compromise: 8 Months Undetected.

5 min read · 6 Sep 2026

Third-party oversight

Branch Protection and Code Review Bypasses

Branch Protection: Configured. Admin Access: Never Revoked from Incident Response. Bypass: Direct Push to Main. Code Review: None. Hardcoded Key and Path Traversal: Introduced.

5 min read · 3 Sep 2026

Third-party oversight

Code Signing and Its Limits

Signature: Valid. Certificate: From Recognised CA. Key: Compromised 11 Months Prior. All Releases Since: Potentially Attacker-Signed.

5 min read · 1 Sep 2026

Third-party oversight

Container Image Supply Chain

Application Code: Reviewed. Container Base Image: 4 Months Outdated. System Library CVEs: 17. Critical RCEs: 2.

4 min read · 29 Aug 2026

Third-party oversight

Dependency Confusion Attacks

Internal Package: acme-internal-utils. Job Posting: Mentioned Internal Tooling. Public Registry: Attacker Published Same Name, Higher Version. 23 Applications: Compromised.

4 min read · 27 Aug 2026

Third-party oversight

Dependency Pinning vs Floating Versions

Version Spec: >=2.0.0. New Version Published Thursday: 2.4.0. Tests: Passed Thursday. Production: Deployed Different Software Friday.

4 min read · 24 Aug 2026

Third-party oversight

Vendor Development Environment Security

Production: Secured. Developer Workstations: Local Admin. Credentials in Dotfiles. Personal GitHub Accounts for Work. Malicious VSCode Extensions Installed.

4 min read · 22 Aug 2026

Third-party oversight

Vendor Security Disclosure Programmes

Disclosure Programme: Published. Report: Submitted. Acknowledged: Yes. Patched Within 7 Months: No. Advance Notice to Customers: Zero.

4 min read · 19 Aug 2026

Third-party oversight

The Future of Software Supply Chain Security

Current Programme: Current for Today. AI-Generated Code: In Vendor Pipelines Now. Post-Quantum: On the Timeline. Regulatory Acceleration: Already Landed.

4 min read · 17 Aug 2026

Third-party oversight

Infrastructure-as-Code Supply Chain Risk

IaC: Reviewed. Third-Party Terraform Modules: 14 Months Stale. Security Group: Management Ports Open to 0.0.0.0/0. Module Review: Not Conducted.

4 min read · 14 Aug 2026

Third-party oversight

Supply Chain Incident Response

IR Programme: Mature for Production Incidents. Supply Chain Playbook: None. Affected Release Identification: No Process. Customer Deployment Inventory: Not Maintained.

4 min read · 12 Aug 2026

Third-party oversight

Open Source License Risk

Platform Deployed: 18 Months. AGPL Component: Discovered by Legal. Disclosure Requirement: Potentially Applies to Vendor's Proprietary Code. Legal Review: 6 Months.

4 min read · 9 Aug 2026

Third-party oversight

Supply Chain Risk in Mergers and Acquisitions

Platform Acquired. Open-Source Dependencies: 1,247. Critical Vulnerabilities: 73. Unresolvable Due to EOL: 14. Runtime: 3 Major Versions Behind. Due Diligence: No Supply Chain Assessment.

4 min read · 7 Aug 2026

Third-party oversight

Supply Chain Security Maturity Assessment

SBOM: Level 3. SCA: Level 3. SLSA: Level 0 (Unaware). Build Pipeline Security: Level 1. Supply Chain Monitoring: Level 0.

4 min read · 4 Aug 2026

Third-party oversight

NIST SP 800-161 for Practitioners

NIST 800-161: Reviewed and Considered Aligned. Implementation Tier: Not Assessed. Controls Implemented: Not Verified.

4 min read · 2 Aug 2026

Third-party oversight

Vendor Open Source Contribution Risk

Engineer: 3 Years Trusted Contributions. Employee Status: Departed. PR: Backdoor. Merge: Approved Based on Reputation. Affected Vendors: 14.

4 min read · 30 Jul 2026

Third-party oversight

Package Registry Trust Model

Package: Legitimate. Maintainer: Compromised via Social Engineering. Version Update: Bug Fix + Credential Harvesting. Downloads: 14,000 Weekly.

4 min read · 28 Jul 2026

Third-party oversight

Supply Chain Security in Regulated Industries

FDA SBOM Requirement: Met. Critical CVEs in SBOM: 17. VEX Documentation: Not Provided. Regulatory Review Delay: 4 Months.

4 min read · 25 Jul 2026

Third-party oversight

Reproducible Builds in Practice

500 Packages Analysed. 312: Reproducible. 188: Not Reproducible. The 188: Source Code Does Not Uniquely Determine Binary.

4 min read · 23 Jul 2026

Third-party oversight

Supply Chain Risk Quantification

Risk Ratings: High, Medium, High. Financial Exposure: Not Calculated. Board Communication: Not Possible. Investment Justification: Not Available.

4 min read · 20 Jul 2026

Third-party oversight

Programming Language Runtime Security

Platform: Well-Patched Application Code. Runtime: Python 3.9, EOL October 2025. Critical Runtime CVEs: 3. Future Patches: None.

4 min read · 18 Jul 2026

Third-party oversight

Software Bill of Materials Automation

847 SBOM Documents. 7 Formats. 93% Never Parsed. 41% Over 12 Months Old. Supply Chain Visibility: None.

4 min read · 15 Jul 2026

Third-party oversight

Software Bill of Materials , Beyond the Mandate

SBOM: Provided. Critical Vulnerabilities Listed: 14. SBOM Age: 6 Months. Vulnerability Status: Not Included. Regulator: Not Satisfied.

4 min read · 13 Jul 2026

Third-party oversight

Software Composition Analysis Gaps

SCA Configured: Main Branch, Python Only, CVE IDs Only. Uncovered: 7 Repositories, Go and Java Services, Non-CVE Issues.

4 min read · 10 Jul 2026

Third-party oversight

Third-Party SDK Risk

SDK Evaluated at Integration. Vendor Acquired 18 Months Later. SDK Updated: New Data Collection. Enterprise Privacy Policy: Not Reflecting New Collection.

4 min read · 8 Jul 2026

Third-party oversight

What Is SLSA and Why Your Vendors Should Care

SLSA Compliant: Confirmed. SLSA Level: 1. What Level 1 Means: Build Process is Documented. What It Doesn't Mean: Build Is Tamper-Resistant.

6 min read · 5 Jul 2026

Third-party oversight

Software Supply Chain for SaaS Products

Installed Software: SBOM, SCA, Provenance Verification. SaaS Platform: Same Supply Chain Risk. Visibility: None.

4 min read · 3 Jul 2026

Third-party oversight

Secrets in Source Code

Policy: No Hardcoded Credentials. Git History: AWS Key, Database Credentials, RSA Key , 31 Months. Status: Technically Still There.

4 min read · 30 Jun 2026

Third-party oversight

Sigstore and the Transparency Log Revolution

Signing Key: File on Build Server, 3 Years Unrotated. Sigstore: Free, Short-Lived Certificates, Public Audit Log. Vendor Awareness: None.

4 min read · 28 Jun 2026

Third-party oversight

Software Provenance Verification

Signature: Valid. Delivery: HTTPS. Download URL: Legitimate. Distribution Infrastructure: Compromised 3 Weeks Prior. Software: Attacker's.

5 min read · 25 Jun 2026

Third-party oversight

The SolarWinds Lessons Still Unlearned

SolarWinds: 2020. Assessment Checklist: Same Questions as 2019. Build Pipeline: Not Asked About.

4 min read · 23 Jun 2026

Third-party oversight

Threat Intelligence for Supply Chain Attacks

Threat Intel Report: Received. CI/CD and SDK Targeting: Described. Vendor Assessments Updated: No. Two Vendors Targeted: 6 Months Later.

4 min read · 20 Jun 2026

Third-party oversight

Transitive Dependency Risk

Direct Dependencies: Zero Critical Vulnerabilities. Transitive Dependency Depth 4: Critical Vulnerability. SCA Scope: Direct Dependencies. Depth 4: Out of Scope.

4 min read · 18 Jun 2026

Third-party oversight

Typosquatting in Package Registries

Legitimate Package: lodash. Typosquatted: lodash-utils. Downloads: 43,000. Production Deployments: 312. CVE: None. SCA Alert: None.

4 min read · 15 Jun 2026

Third-party oversight

Software Update Mechanism Security

Auto-Update: Enabled by Default. Certificate: Compromised 3 Months Prior. Updates Applied: Potentially Compromised. Enterprise Aware: No.

4 min read · 13 Jun 2026

Third-party oversight

VEX , Vulnerability Exploitability eXchange

SCA Findings: 312. Actually Exploitable: 23. VEX Available: No. Triage Time: 3 Weeks.

4 min read · 11 Jun 2026

Third-party oversight

Zero Trust for Software Supply Chains

Network: Zero Trust. Dependencies: Pulled Without Publisher Verification. Build Agents: Broad Credentials. Software Updates: Server Identity from HTTPS Certificate Only.

5 min read · 10 Jun 2026

Third-party oversight

Software Supply Chain Security

SLSA, SBOM, and the Hidden Risk in Every Line of Code You Trust

6 min read · 9 Jun 2026

Third-party oversight

Vendor Access Creep Over Time

Original Access: Read-Only Names and Emails. Three Years Later: Five Data Categories. Four Expansions: Zero TPRM Reviews.

4 min read · 8 Jun 2026

Third-party oversight

TPRM Programme Automation and Its Limits

Automation Deployed. Efficiency: Doubled. Assessment Quality: Same as the Unvalidated Questionnaire Responses It Automated.

4 min read · 7 Jun 2026

Third-party oversight

TPRM Board and Executive Reporting

Board Report: Assessments, Tiers, Findings, Heat Map. Board Question: Biggest Unmanaged Risk Right Now? Answer: Not in the Report.

4 min read · 6 Jun 2026

Third-party oversight

TPRM as a Business Enabler

Procurement: 2-Week Deadline. Standard Assessment: 4-6 Weeks. Risk-Tiered Assessment: 8 Days. Finding: Identified and Remediated Before Go-Live.

5 min read · 5 Jun 2026

Third-party oversight

Cloud Provider Shared Responsibility in TPRM

AWS: SOC 2, ISO 27001, FedRAMP. Enterprise Cloud Configuration: Public Buckets, Excessive Permissions, Logging Disabled.

4 min read · 4 Jun 2026

Third-party oversight

Continuous Monitoring vs Point-in-Time Assessment

January Assessment: Accurate. March: Cloud Migration. June: Ransomware. September: CISO Departed. November: Still January's Data.

4 min read · 3 Jun 2026

Third-party oversight

Contract Security Requirements Enforcement

Security Addendum: Comprehensive. Enforcement: Three Years, Never Exercised. Encryption at Rest: Not Implemented.

4 min read · 2 Jun 2026

Third-party oversight

Vendor Data Handling Agreement Gaps

Data Sharing Agreement: Specifies Categories, Retention, Purpose. Model Training Use: Not Prohibited. Vendor Policy Change: Discovered Through Alert Service.

4 min read · 1 Jun 2026

Third-party oversight

Due Diligence Depth vs Vendor Tier

SOC 2: Confirmed Exists. Fourteen Controls Tested by Policy Review Only. Due Diligence: Checked the Box.

4 min read · 31 May 2026

Third-party oversight

Critical Vendor Exit Strategy Planning

Acquisition Notice: 6 Months to Support End. Exit Strategy: None. Integration Inventory: None. Evaluated Alternatives: None. Timeline: 7 Years of Integration to Unwind.

4 min read · 30 May 2026

Third-party oversight

Vendor Financial Health as TPRM Signal

Revenue Shock: 38% Customer Loss. Security Team: -40%. SOC 2: Deferred. Pentest: Cancelled. Last Assessment: 8 Months Ago, Low Risk.

4 min read · 29 May 2026

Third-party oversight

Fourth-Party Risk Blindness

ERP Vendor: Thoroughly Assessed. AWS, Auth Provider, AI Vendor, Hosting Provider: Not Assessed by Anyone.

4 min read · 28 May 2026

Third-party oversight

The Future of TPRM , From Assurance to Intelligence

847 Vendors Assessed. 2,341 Questionnaires. 1,847 Findings. Predictive Model: Not Built. Intelligence Waiting to Be Used.

5 min read · 27 May 2026

Third-party oversight

Geopolitical Risk in Vendor Selection

Data: EU-Hosted. Engineering Team: Jurisdiction with Government Access Law. Data Location: Protected. Data Access Personnel: Not.

4 min read · 26 May 2026

Third-party oversight

Vendor Incident Notification Failures

Breach: Tuesday. Discovered: Wednesday. Contract: 72 Hours. Notified: Monday. News Article: Friday. Enterprise Found Out: Friday.

4 min read · 25 May 2026

Third-party oversight

Inherent Risk Tiering

200-Question Questionnaire. Law Firm: Same as Cloud Platform. 180 Not-Applicables. 40 Missing Architecture Questions.

6 min read · 24 May 2026

Third-party oversight

TPRM for Mergers and Acquisitions

Acquisition Closed. Integration: Day One. TPRM Assessment of Acquired Vendor Portfolio: 18 Months Later. 12 Unassessed Critical Vendors Connected to Enterprise Network.

4 min read · 23 May 2026

Third-party oversight

Managed Service Provider TPRM Complexity

MSP: Thoroughly Assessed. MSP Subprocessors: 23. Subprocessors with Production System Access: 6. Assessed by Enterprise: 0.

4 min read · 22 May 2026

Third-party oversight

TPRM Programme Maturity Models

Self-Assessment: Level 3. Regulator: Level 3 for Tiering and Documentation. Level 1 for Monitoring, Fourth-Party, and Exit Planning.

4 min read · 21 May 2026

Third-party oversight

Open Source as a Third-Party Risk

Commercial Vendors: 847 Assessed. Open-Source Libraries: 847 Unassessed. Critical Vulnerability: 14 Applications Affected. Inventory: None.

3 min read · 20 May 2026

Third-party oversight

Outsourcing Risk vs Outsourcing Responsibility

Activity Outsourced. Liability Limitation: $240K Contract Value. Regulatory Fine: $1.8M. Accountability: Not Outsourceable.

4 min read · 19 May 2026

Third-party oversight

TPRM Ownership and Accountability Gaps

Critical Finding: Open 6 Months. TPRM Team: Business Owner's Responsibility. Business Owner: No Technical Authority. Vendor: No Formal Request Received.

4 min read · 18 May 2026

Third-party oversight

TPRM Programme Metrics & KPIs

Assessments: 847. Questionnaires: 2,341. Completion Rate: 94%. Risk Reduction: Not Measured.

4 min read · 17 May 2026

Third-party oversight

TPRM Questionnaire Design Failures

187 Questions. 14 Days to Complete. 6 Hours to Review. 40 Questions Genuinely Informative. 147: Noise.

4 min read · 16 May 2026

Third-party oversight

Vendor Security Questionnaire Fatigue

14 Questionnaires in Q4. 340 Hours. 3-Person Security Team. 3 Weeks Displaced. Same Facts: 14 Formats.

4 min read · 15 May 2026

Third-party oversight

Tiered Reassessment Frequency

Marketing Agency: Annual Reassessment. Cloud Data Platform: Also Annual Reassessment. Risk: Not Equivalent. Cadence: Identical.

4 min read · 14 May 2026

Third-party oversight

Regulatory Mapping in TPRM

TPRM Programme: SOC 2 and NIST CSF Aligned. DORA Gap Analysis: 40% Not Covered. Regulation: Changed. Programme: Same.

4 min read · 13 May 2026

Third-party oversight

Inherent vs Residual Risk Confusion

Inherent Risk: High. Controls: Strong. Residual Risk: 2/10. Breach: In System Not Covered by the Controls Assessed.

4 min read · 12 May 2026

Third-party oversight

Vendor Resilience Testing and Tabletop Exercises

Vendor SLA: 99.9%. Manual Fallback: Documented. Tabletop Result: 4 Processes With No Fallback. Estimated Recovery: 11 Days.

4 min read · 11 May 2026

Third-party oversight

Right-to-Audit Clauses in Practice

Right-to-Audit: Negotiated into Every Critical Contract. Exercised: Once in Four Years. Audit Quality: 'Unlikely to Withstand Regulatory Scrutiny.'

4 min read · 10 May 2026

Third-party oversight

Risk Acceptance Governance

Critical Finding: Escalated. Business Owner: Signed Acceptance. Finding: Closed. Risk: Unmanaged for Two Years. Outage: 36 Hours.

4 min read · 9 May 2026

Third-party oversight

Vendor Risk Appetite Alignment

Finding: No MFA on Admin Accounts. Cost to Fix: $47K. Business Owner: Accepted Risk. Risk Framework: Prohibits This Acceptance.

4 min read · 8 May 2026

Third-party oversight

Vendor Risk Register Accuracy

Risk Register: 312 Entries. Last Full Review: 8 Months Ago. Offboarded Vendors Still Listed. New Vendors Missing. Three Breaches Unupdated.

4 min read · 7 May 2026

Third-party oversight

SaaS Security Posture vs Traditional Vendor Assessment

SOC 2: Confirmed. SSPM Scan: 312 Inactive Accounts, 23 Over-Privileged, 14 Unrotated API Tokens. Same Vendor. Different Picture.

3 min read · 6 May 2026

Third-party oversight

Subprocessor Visibility

DPA Subprocessors: 12. Production Subprocessors: 18. The Six Gap: Background Check API, Fraud Detection, Cloud Logging.

4 min read · 5 May 2026

Third-party oversight

Vendor Business Continuity & Resilience

Uptime SLA: 99.9%. BCP Tested: Never Asked. Backup: Same Region. Recovery Time: 11 Days. SLA: 4 Hours.

4 min read · 4 May 2026

Third-party oversight

Vendor Concentration Risk

43% Revenue through One Vendor. 67% Infrastructure: One Provider. 81% Support: One Platform. Each Green. Together: Existential.

4 min read · 3 May 2026

Third-party oversight

Vendor Inventory Completeness

TPRM Inventory: 847 Vendors. Procurement Master: 2,341. The Gap: 1,494 Vendors Nobody Was Managing.

7 min read · 2 May 2026

Third-party oversight

Vendor Offboarding Risk

Contract: Closed. API Keys: Active. User Accounts: Two Remaining. Data Extract: Still at Vendor. IP Allowlist: Never Removed.

4 min read · 1 May 2026

Third-party oversight

Vendor Onboarding Security Gates

Contract Signed Monday. Production Data Access: Sunday. TPRM Notified: Previous Friday. Assessment: Three Weeks Later.

4 min read · 30 Apr 2026