Episode 19 | July, 2026 episode artwork

EPISODE · Jul 14, 2026 · 51 MIN

Episode 19 | July, 2026

from Alice in Supply Chains · host Tenchi Security

In the July 2026 episode of Alice in Supply Chains, Adrian and Alexandre dig into Verizon's first-ever Breach Impact Study, a companion to the DBIR built on roughly 70,000 cyber insurance claims (accepted and rejected) contributed via Cyber AcuView between 2019 and late 2025. The medians-only approach (no averages allowed!) makes this one of the most honest looks at breach costs yet, and the findings vindicate a recurring theme of the show: availability, not confidentiality, drives losses. Business interruption has the highest median claim (~$90K) and grew 51% year over year, while regulatory fines turn out to be the smallest loss category — so maybe stop leaning on "the regulator will fine us" to justify security budgets.Software supply chain incidents are just 2% of claims but punch far above their weight, with immediate impacts more than double the rest of the dataset and extreme losses topping $100 million — cases that overwhelmingly hit policy caps, meaning the true economic damage is even higher. Adrian connects this to the rise of cascading breaches (Trivy → LiteLLM → everyone downstream), and the pair discuss why this kind of concentrated, systemic risk terrifies insurers and may reshape coverage terms.Story two is Gartner's new "Mastering TPCRM" document series, which Adrian and Alexandre praise as unusually prescriptive and genuinely useful: frameworks for roles and responsibilities across security, legal, procurement, and — critically — business owners, plus a starter TPCRM policy you can adapt. Alexandre argues the make-or-break factor for any TPCRM program is whether business owners formally own the risks they accept, rather than treating the process as a checkbox that must not slow down contracting.Finally, Schrems III is nigh: with the US Supreme Court's ruling undermining the independence of agencies like the FTC — the very foundation of the EU-US Data Privacy Framework — Max Schrems is poised to strike down transatlantic data transfer agreement number three. Alexandre walks through why the EU has painted itself into a corner (idealistic legislation, total dependence on US cloud, AI, and OS providers), what the $307 billion per year in EU spending on US cloud services means for both sides, and why every company with a transatlantic footprint should be talking to their legal counsel now.Links:Tenchi Conference 2026: Details, tickets, and CFP - https://luma.com/vvzsmej9Story 1: Verizon Breach Impact Study - https://verizon.com/dbirStory 2: Gartner’s Series on Mastering TPCRM - https://www.gartner.com/en/documents/7907309Story 3: Schrems III is Nigh - https://kaynemcgladrey.com/blog/when-the-load-bearing-wall-comes-down/

Episode metadata supplied by the publisher feed · Published Jul 14, 2026

Embed this episode

NOW PLAYING

Episode 19 | July, 2026

0:00 51:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Alice in Supply Chains?

This episode is 51 minutes long.

When was this Alice in Supply Chains episode published?

This episode was published on July 14, 2026.

Can I download this Alice in Supply Chains episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!