Podcast

Alice in Supply Chains - Episode 15

Episode Description:

Hosts Adrian Sanabria (The Defenders Initiative) and Alexandre Sieira (CTO, Tenchi Security) reconvene — both recovering from the notorious con crud — to dig into the biggest stories from a packed month in third-party and supply chain security.

Show Notes:

This month, we have two main stories:

  • The ongoing Delve controversy and data leaks
  • Our RSAC Conference 2026 takeaways

In addition, we’ve got links to some of the things we mentioned in the podcast!

  1. Alex’s ESW Appearance securityweekly.com/esw452
  2. The episode we did with AJ Yawn on issues with SOC 2 reports https://www.tenchisecurity.com/en/alice-in-supply-chains/episode-7-hoxz2
  3. Tony Martin-Vegue’s excellent “acting rationally, given the incentives” take on the Delve scandal https://www.linkedin.com/posts/tonymartinvegue_i-know-youre-tired-of-the-delve-discourse-activity-7441294170406891520-UtGg
  4. Adrian’s blog with his RSAC Conference 2026 takeaways https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes
  5. Alex Sieira’s RSAC talk with Alex Pinto (login required to watch the recording) https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755192044047001WRoa
  6. Adrian Sanabria and Adam Shostack’s talk on Breach Transparency from RSAC https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1756101254392001bKZA
  7. Tenchi’s ‘near miss’ report https://www.tenchisecurity.com/en/insights-news/secure-practices-trivy-supply-chain-attack

‍

Show Transcript

Watch or listen to full episodes in English.

Recent episodes

Episode 21

In this episode of the Alice in Supply Chains Podcast, Adrian Sanabria and Alexandre Sieira discuss four stories shaping third-party cyber risk management - from a BGP hijacking that compromised software updates to emerging AI risks, the rise of inside-out scanning in financial institutions, and proposed UK restrictions on risky technology suppliers.

Episode 20 | Recorded Live at Black Hat in Las Vegas!

On episode 20, Adrian and Alexandre discuss four recent stories shaping third-party and AI risk: SOC 2 commitments deferred by vendors, the lessons from Brazil’s PSTI security requirements, AI agents and security incidents involving Hugging Face, OpenAI and Anthropic, and a prompt injection case involving outside counsel in Brazil. The episode explores what these incidents mean for TPCRM, vendor assurance, regulatory compliance, AI governance, and third-party contracts.

Episode 19

Episode 19 of Alice in Supply Chains explores how cyber risk is evolving beyond traditional security concerns and why organizations need to rethink how they measure, manage, and communicate risk. Adrian Sanabria and Alexandre Sieira discuss the latest developments influencing the cybersecurity landscape, from the real financial impact of breaches and emerging software supply chain threats to practical approaches for third-party cyber risk management and the evolving regulatory environment. Whether you're responsible for security, risk, procurement, or compliance, this episode offers valuable insights into the challenges shaping cyber risk management today.