Send us Fan Mail

In this episode of Third Party Threat Hunters, Greg speaks with Ronan, co-founder and CEO of Shift Security, about how third-party risk management needs to evolve beyond questionnaires and static assessments. Ronan shares how years of working inside enterprise security, including at Barclays, led him to build a product focused on real operational visibility into vendors, access, and emerging AI-related exposure.

They discuss the growing risk of third-party access, the limits of traditional vendor assessments, and why inventory is the foundation of any serious third-party risk program. Ronan also explains how AI can help security teams separate true risk from alert noise, prioritize what matters, and move from reactive checklists to actionable security decisions.

Key Topics

  • Ronan’s background in offensive security, Microsoft Security, and Barclays
  • The origin story behind Shift Security
  • Why vendor questionnaires are no longer enough
  • The importance of knowing all third parties, known and unknown
  • Third-party access as a major breach vector
  • AI agents, shadow AI, and third-party exposure
  • Using AI to reduce alert fatigue and prioritize real risk
  • Building a third-party operational security program, not just a tool stack

Main Takeaways

  • Inventory is the first step to securing third parties.
  • Risk management must account for both probability and impact.
  • Vendor access is often more dangerous than vendor compliance gaps.
  • AI can help filter noise, but only when it has strong business context.
  • CISOs need a programmatic approach to third-party operational security.

Notable Quote

“We’re living in darkness until we understand what third parties exist, what access they have, and what they’re doing.”

Why It Matters

As third-party ecosystems grow more complex and AI agents become part of the security landscape, organizations can no longer rely on one-time assessments. This episode shows why visibility, continuous monitoring, and context-driven response are now essential for operational resilience.

Guest

Ronan, Co-founder and CEO of Shift Security

Host

Greg

Mentioned Themes

  • Third-party risk management
  • Vendor access governance
  • AI exposure
  • Security alert fatigue
  • Operational resilience
  • Continuous monitoring

Want me to turn this into a LinkedIn post next?


Support the show

Podden och tillhörande omslagsbild på den här sidan tillhör Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av, eller tillsammans med, Poddtoppen.