Send us Fan Mail

In this episode, Rachel Curran, co-founder of Loctivity, shares insights on how AI is transforming third-party risk management, the importance of governance at speed, and practical steps to strengthen security postures. Discover how to balance automation with human oversight and keep your organization resilient in a rapidly evolving threat landscape.

Key Topics

  • Rachel’s background in GRC and her passion for security and compliance
  • The role of AI in accelerating vendor assessments and risk management
  • The importance of human-in-the-loop for effective governance at speed
  • Bridging the governance gap by focusing on actual enforcement over paperwork
  • How AI influences remote vendor onboarding and real-time data exchange
  • Critical security risks introduced by AI agents, especially access control
  • The shift from static to dynamic, self-optimizing AI-driven vendor risk profiles
  • The evolving threat landscape and the dangers of AI-enabled malicious actors
  • Practical strategies for organizations: going back to fundamentals and prioritization
  • The significance of frameworks and continuous updating of security programs
  • How to leverage evidence packs and automation for ongoing compliance verification

Timestamps
00:00 - Introduction to Rachel Curran and her expertise in GRC

01:17 - Rachel’s career journey and motivation in cybersecurity

02:37 - Personal interests: favorite travel destinations and favorite fruit

03:41 - Fun questions: funniest vendor excuses and entrepreneurship drive

06:27 - The challenge of governance at speed in the AI era

07:00 - Human oversight’s critical role in AI-driven risk management

08:47 - Managing governance gaps through prioritization and verifiable data

10:11 - The biggest governance gaps organizations face today

11:37 - Using automation to improve vendor visibility and risk assessments

12:35 - Why compliance alone isn’t sufficient and how cybersecurity underpins it

14:02 - The fallacy of paper policies versus actual practice in governance

15:40 - Data dependence and the importance of real-time controls and backups

16:07 - The impact of AI on third party risk landscape over the next 12-18 months

16:42 - Risks from AI-enabled access control and recent AI breach incidents

18:12 - Managing AI agents’ permissions and preventing privilege creep

20:30 - The threat of AI agents executing malicious or unintended actions

22:08 - The necessity of quality data, transparency, and human oversight

24:06 - Moving away from point-in-time assessments toward continuous, evidence-backed evaluations

25:00 - The potential to improve vendor transparency with real-time info sharing

26:12 - How AI can support dynamic security assessments and ongoing compliance

27:21 - The importance of foundational security controls and a risk-focused mindset

28:13 - Tactical action: back to basics—understand your vendors and their risk posture

29:12 - Wrap-up: the future of third-party risk management with AI and continuous monitoring
Final Takeaways
Focus on fundamental security controls and verifiable data to reduce risks
Prioritize vendors based on actual risk to manage resources effectively
Use automation and frameworks for continuous compliance and rapid response
Recognize AI as a tool to augment, not replace, human judgment and oversight
Thank you for joining us. Stay tuned for more insights into cybersecurity and risk management.
Want me to turn this into a LinkedIn post next?

Support the show

Podden och tillhörande omslagsbild på den här sidan tillhör Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av, eller tillsammans med, Poddtoppen.