C
Chris Heighes
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Jun 4, 2026
Business Approaches to Risk Management
21:48
21:53
22:17
22:52
23:10
24:16

Wayne ArmstrongGUEST
And if some of those thousands are suppliers to you, then it's going to affect you as

Chris HeighesGUEST
And aligned to that as well, particularly in larger organisations where you're potentially utilising a third party to provide a range of services, it's being aware of what that almost consolidated level of risk is associated with that particular supplier.

Chris HeighesGUEST
um you could you could you could potentially look at i don't know the i.t team and then the finance team um and and their age using aws or whatever um for particular for particular activities um and they would look at that on an individual basis and talk about a level of risk that that's associated with that without necessarily taking into account the fact that that same supplier or that same service is being utilised, maybe in different ways, but across multiple areas of the business.

Chris HeighesGUEST
So that in actual fact, if that service isn't available, it's not just impacting you in IT, it's impacting the finance team, it's impacting the product team, whoever out there, possibly in slightly different ways.

Chris HeighesGUEST
But there's that concept of not just looking at at the individual services being delivered by by by a particular supplier but getting an understanding across the organization or even across the group of the level of risk associated with all of the services those particular the particular suppliers uh are delivering um and i think this is i mean i've i've i've been working in in in in it um and particularly in consultancy for quite a long time but it's clear that one of the big changes that has occurred over say the last 10 years has been a general consolidation in terms of the number of suppliers that are out there delivering particular services whereas I don't know, eight, nine years ago when you went out and talked to organisations, you would find that they were all utilising different anti-malware solutions or whatever.

Chris HeighesGUEST
Increasingly, all organisations are using a smaller and smaller set of suppliers to be delivering those types of service.
A
24:56AnnieHOST
So looking ahead now, sort of three to five years, what capability or mindset do you think information security leaders must develop now to remain effective risk advisors to the business?