Skip to main content

Chris Heighes

Jun 4, 2026

21:48
And if some of those thousands are suppliers to you, then it's going to affect you as
21:52
well.
21:53
And aligned to that as well, particularly in larger organisations where you're potentially utilising a third party to provide a range of services, it's being aware of what that almost consolidated level of risk is associated with that particular supplier.
22:17
um you could you could you could potentially look at i don't know the i.t team and then the finance team um and and their age using aws or whatever um for particular for particular activities um and they would look at that on an individual basis and talk about a level of risk that that's associated with that without necessarily taking into account the fact that that same supplier or that same service is being utilised, maybe in different ways, but across multiple areas of the business.
22:52
So that in actual fact, if that service isn't available, it's not just impacting you in IT, it's impacting the finance team, it's impacting the product team, whoever out there, possibly in slightly different ways.
23:10
But there's that concept of not just looking at at the individual services being delivered by by by a particular supplier but getting an understanding across the organization or even across the group of the level of risk associated with all of the services those particular the particular suppliers uh are delivering um and i think this is i mean i've i've i've been working in in in in it um and particularly in consultancy for quite a long time but it's clear that one of the big changes that has occurred over say the last 10 years has been a general consolidation in terms of the number of suppliers that are out there delivering particular services whereas I don't know, eight, nine years ago when you went out and talked to organisations, you would find that they were all utilising different anti-malware solutions or whatever.
24:16
Increasingly, all organisations are using a smaller and smaller set of suppliers to be delivering those types of service.
AnnieHOST
24:56
So looking ahead now, sort of three to five years, what capability or mindset do you think information security leaders must develop now to remain effective risk advisors to the business?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.