EPISODE · Aug 6, 2026 · 34 MIN
Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of
from @BEERISAC: OT/ICS Security Podcast Playlist · host Industrial Cybersecurity Insider
Podcast: Industrial Cybersecurity InsiderEpisode: Supply Chain Risk: Your Vendors Have Vendors You've Never Heard OfPub date: 2026-08-04Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationCraig Duckworth sits down with Jowanza Joseph, CEO of Parakeet Risk, to unpack why third-party risk has become one of the most urgent challenges facing manufacturers and critical infrastructure operators. Jowanza spent 15 years in engineering roles at Adobe, Pluralsight, and MasterCard before founding Parakeet Risk to serve an industrial sector he saw as the most underserved when it comes to technology. Together they address why simply knowing who your vendors are is harder than it sounds, how insurers are moving past checkbox questionnaires and demanding real evidence of controls, and what happens when contracts require you to identify a new asset in your OT environment within five minutes. They also get honest about the organizational problem few want to own: security leaders who carry responsibility for the plant floor without the authority to change anything on it. Jowanza closes with a practical, low-cost starting point for any organization and a look at where vendor attestation is headed over the next five years.Chapters:(00:00:00) Why industrial companies must become cybersecurity companies(00:02:08) Cataloging and prioritizing your most dangerous vendors(00:04:37) The hidden layers of subcontractors in your supply chain(00:06:42) Cyber insurance moves past the checkbox era(00:10:47) Contracts that demand new asset identification in five minutes(00:12:58) AI is multiplying vulnerabilities faster than solutions(00:16:31) Three hallmarks of a strong third party risk program(00:21:14) Incident response, game days, and who falls on the sword(00:23:42) Responsibility without authority across the IT and OT divide(00:28:31) Where to start today and the future of vendor attestationLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Embed this episode
What this episode covers
Podcast: Industrial Cybersecurity Insider Episode: Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of Pub date: 2026-08-04 Details: https://www.listennotes.com/e/bc9ada47e0504d059a3843c7fa4162f5/ The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
NOW PLAYING
Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.