In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape.
Key Topics
Rachel’s background in GRC and her passion for security and compliance
The role of AI in accelerating vendor assessments and risk management
The importance of human-in-the-loop for effective governance at speed
Bridging the governance gap by focusing on actual enforcement over paperwork
How AI influences remote vendor onboarding and real-time data exchange
Critical security risks introduced by AI agents, especially access control
The shift from static to dynamic, self-optimizing AI-driven vendor risk profiles
The evolving threat landscape and the dangers of AI-enabled malicious actors
Practical strategies for organizations: going back to fundamentals and prioritization
The significance of frameworks and continuous updating of security programs
How to leverage evidence packs and automation for ongoing compliance verification
Timestamps 00:00 - Introduction to Rachel Curran and her expertise in GRC
01:17 - Rachel’s career journey and motivation in cybersecurity
02:37 - Personal interests: favorite travel destinations and favorite fruit
03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive
06:27 - The challenge of governance at speed in the AI era
07:00 - Human oversight’s critical role in AI-driven risk management
08:47 - Managing governance gaps through prioritization and verifiable data
10:11 - The biggest governance gaps organizations face today
11:37 - Using automation to improve vendor visibility and risk assessments
12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it
14:02 - The fallacy of paper policies versus actual practice in governance
15:40 - Data dependence and the importance of real-time controls and backups
16:07 - The impact of AI on third party risk landscape over the next 12-18 months
16:42 - Risks from AI-enabled access control and recent AI breach incidents
18:12 - Managing AI agents’ permissions and preventing privilege creep
20:30 - The threat of AI agents executing malicious or unintended actions
22:08 - The necessity of quality data, transparency, and human oversight
25:00 - The potential to improve vendor transparency with real-time info sharing
26:12 - How AI can support dynamic security assessments and ongoing compliance
27:21 - The importance of foundational security controls and a risk-focused mindset
28:13 - Tactical action: back to basics—understand your vendors and their risk posture
29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring Final Takeaways Focus on fundamental security controls and verifiable data to reduce risks Prioritize vendors based on actual risk to manage resources effectively Use automation and frameworks for continuous compliance and rapid response Recognize AI as a tool to augment, not replace, human judgment and oversight Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management. Want me to turn this into a LinkedIn post next?
Podden och tillhörande omslagsbild på den här sidan tillhör
Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av,
eller tillsammans med, Poddtoppen.