Innovation in Compliance with Tom Fox

Improving Third-Party Risk Management with Paul Valente

May 2, 2023
Paul Valente, CEO and co-founder of VISO Trust and former CISO at Restoration Hardware, Lending Club and ASAPP, talks about automated third-party cyber risk management. He discusses why vendor data copies increase risk. He emphasizes boards' oversight duties and the need for continuous monitoring. He explains how automation and Document Intelligence replace slow questionnaires and enable auditability.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Founding VISO Trust From CISO Frustration

  • Paul Valente founded VISO Trust after CISO roles at Restoration Hardware, Lending Club, and ASAPP due to ineffective third-party risk tools.
  • He experienced low vendor adoption, poor visibility, and excessive manual work sending questionnaires and reading documents.
INSIGHT

Data Lives More With Vendors Than With You

  • Companies often store more sensitive data on third-party infrastructure than internally, increasing overall risk exposure.
  • Paul Valente highlights cloud-native firms with many copies of data across vendors as a growing "tax" on cybersecurity risk.
ADVICE

Boards Must Demand Regular Cyber Risk Reporting

  • Boards should regularly ask for cybersecurity risk reports, program maturity metrics, and tracked residual risk.
  • Paul Valente recommends boards hold executives accountable and advocate for appropriate cybersecurity funding.
Get the Snipd Podcast app to discover more snips from this episode
Get the app