Podcast

Alice in Supply Chains - Episode 14

Descrição do episódio:

The Alice in Supply Chains Podcast is back for another episode! On it, Adrian Sanabria and Alexandre Sieira share their expert opinions on the most pressing matters in the TPCRM world - as presented on issue #42 of our newsletter of the same name, also launched today! From cyber risk at scale in private equity portfolios, to the evolution of TPCRM in the AI era, to real-world regulatory scrutiny following a major education-sector breach in Canada - this discussion connects the dots between headlines and hard accountability. The takeaway? Third-party risk is no longer an operational checkbox. It’s financial exposure. It’s regulatory pressure. It's a board-level strategy. If you’re responsible for security, risk, compliance, or investment decisions, this episode is your pulse check on where the market is moving.

Notas do episódio:

This month, we’ve got some interesting stories to discuss, but first - if you’re going to RSAC Conference 2026, drop by Harlan Records in Union Square to say hello!https://www.tenchisecurity.com/en/tenchi-rsa-lounge-2026From March 22 to March 25, 2026, Tenchi Security will host the cybersecurity community attending RSA Conference in San Francisco at Harlan Records, which was exclusively reserved for the Tenchi Lounge - a space to unwind, exchange ideas, and build meaningful connections.Here are our stories for this episode and their associated links:

  1. Cyber Risk at Scale: Safeguarding Portfolio Value in Private Equity
  2. Gartner Predicts: TPCRM Evolves for the AI Era
  3. Canadian Privacy Commissioners Investigate the PowerSchool Breach
  4. https://www.newswire.ca/news-releases/ontario-and-alberta-privacy-commissioners-release-investigation-findings-into-powerschool-breach-affecting-school-boards-and-other-educational-bodies-866592221.html
  5. https://www.ipc.on.ca/en/resources/ontarios-privacy-commissioner-releases-investigation-findings-powerschool-breach-affecting-school
  6. https://oipc.ab.ca/wp-content/uploads/2025/11/FINAL-Investigation-Report-Regarding-PowerSchool-Breach-FOIP2025-IR-02.pdf

newswire.ca

Ontario and Alberta privacy commissioners release investigation findings into PowerSchool breach affecting school boards and other educational bodies

/CNW/ - Ontario and Alberta information and privacy commissioners have released the findings of their investigations into a massive privacy breach involving...

‍

Show Transcript

Assista ou ouça os episódios completos em Inglês

Episódios Recentes

Episode 21

In this episode of the Alice in Supply Chains Podcast, Adrian Sanabria and Alexandre Sieira discuss four stories shaping third-party cyber risk management - from a BGP hijacking that compromised software updates to emerging AI risks, the rise of inside-out scanning in financial institutions, and proposed UK restrictions on risky technology suppliers.

Episode 20 | Recorded Live at Black Hat in Las Vegas!

On episode 20, Adrian and Alexandre discuss four recent stories shaping third-party and AI risk: SOC 2 commitments deferred by vendors, the lessons from Brazil’s PSTI security requirements, AI agents and security incidents involving Hugging Face, OpenAI and Anthropic, and a prompt injection case involving outside counsel in Brazil. The episode explores what these incidents mean for TPCRM, vendor assurance, regulatory compliance, AI governance, and third-party contracts.

Episode 19

Episode 19 of Alice in Supply Chains explores how cyber risk is evolving beyond traditional security concerns and why organizations need to rethink how they measure, manage, and communicate risk. Adrian Sanabria and Alexandre Sieira discuss the latest developments influencing the cybersecurity landscape, from the real financial impact of breaches and emerging software supply chain threats to practical approaches for third-party cyber risk management and the evolving regulatory environment. Whether you're responsible for security, risk, procurement, or compliance, this episode offers valuable insights into the challenges shaping cyber risk management today.