Bringing new software or SaaS into your organization is a security risk - how do you assess it? Richard chats with Jessie Schofer about her experiences in HR software acquisition, which led to the creation of secureless.ai. Jessie tells the story of evaluating various SaaS and other software products and realizing that, while the website says they are compliant with GDPR and/or SOC 2, are they really? This leads to a conversation about the product procurement process and about actually understanding the security risk you take on every time a new product is added to your organization. At what point does security block an acquisition? And after being acquired, how often do you reassess? Supply chain security hygiene starts at procurement - are you part of the evaluation?
Podden och tillhörande omslagsbild på den här sidan tillhör
Richard Campbell. Innehållet i podden är skapat av Richard Campbell och inte av,
eller tillsammans med, Poddtoppen.