Rethinking Third Party Risk for Machine Speed Attacks With Magnitude
The Business of CybersecurityAugust 21, 2026
42
00:27:4325.39 MB

Rethinking Third Party Risk for Machine Speed Attacks With Magnitude

Can a supplier assessment completed once a year protect an organization against risks changing at machine speed?

In this episode of The Business of Cybersecurity, I speak with Rami Habal, founder and CEO of Magnitude. We discuss why traditional third party risk management is struggling to keep pace with connected supply chains, autonomous attacks, AI adoption, and constantly changing vendor environments.

Rami explains that third party risk management developed largely as a compliance process. Companies relied on questionnaires, spreadsheets, point-in-time assessments, and annual reviews. Those methods provided documentation, but they offered limited visibility into what changed after the review or which fourth and fifth parties supported the original vendor.

The result can be a false sense of security. A supplier may change its infrastructure, ownership, software, data practices, or terms of service months before the customer performs another formal assessment. Attackers do not wait for the next compliance cycle.

Rami argues that AI has broken the traditional mathematics of third party risk. Security teams cannot manually monitor thousands of suppliers and every organization supporting them. Attackers can use advanced models to find weaknesses faster, while businesses are adding AI services and dependencies at speed.

Magnitude provides what Rami describes as an AI workforce for third party and supply chain risk management. Its agents support tasks including supplier intake, evidence gathering, security evaluation, risk analysis, onboarding, continuous assurance, and offboarding.

We discuss how this automation can address three business problems. The first is time compression, allowing security teams to process supplier reviews faster. The second is risk reduction through wider visibility, including fourth and fifth party dependencies. The third is business enablement, reducing delays that might otherwise encourage employees to use unapproved AI tools.

Rami explains how Magnitude maps supplier relationships as a connected graph. Security teams can see where dependencies overlap, identify concentration risk, and assess which parts of the business may be affected when a provider experiences an incident.

Continuous monitoring also includes unstructured information. A vendor may update a lengthy terms of service document and introduce permission to train AI systems using customer data. An employee receiving the notification may ignore it, while an automated agent can compare the document, identify the change, and explain its potential effect.

Rami uses a helpful analogy. Traditional vendor assessments resemble photographs, while continuous monitoring resembles a live video feed. Operational, financial, cybersecurity, and privacy risks continue changing after the original assessment.

Automation does not remove people from the process. Rami sees AI preparing evidence, correlating signals, and recommending action while humans handle exceptions, ask difficult questions, and judge the business consequences.

He closes by urging boards to treat third-party risk as part of cyber resilience rather than leaving it within procurement or compliance. Does your organization know which suppliers create its greatest concentration risk and how far a breach could travel through the chain? Listen to the conversation and share your thoughts with me.

Useful Links

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.

[00:00:33] Can an annual supplier questionnaire protect a business when attackers, software updates and AI systems are operating every single minute of every day? A vendor assessment completed in January might already be obsolete by March. But despite that, yep, that spreadsheet will still remain in circulation until Christmas. So in this episode of the Business of Cybersecurity podcast,

[00:01:00] I'm joined by the founder and CEO of Magnitude. And my guest today will argue that third-party risk management was designed for an era of compliance checks, periodic reviews rather than machine speed attacks and deeply connected digital supply chains. Life used to be much simpler, didn't it? So today though, we're going to discuss how AI agents can monitor suppliers continuously

[00:01:30] and even map fourth and even fifth party dependencies, interpret security signals and identify changes that are hidden inside those lengthy documents. And we'll also talk about where automation could reduce pressure on security teams. And most importantly, where human judgment must retain authority.

[00:01:55] So if you're listening to this conversation today and your business relies on thousands of suppliers, software providers and AI services, do you understand the complete chain of dependency that is connecting them to your most sensitive operations? We're going to give you lots to think about today, but right now it's time to introduce you to my guest. So thank you for joining me on the show today.

[00:02:22] Can you tell everyone listening a little about who you are and what you do? Great to be here. So my name is Rami Habal. I'm the founder and CEO of Magnitude. And we provide an AI workforce for third party risk management and supply chain risk for security teams. And our whole premise is that we're defending against the era of mythos scale attacks. And we can get into that some more.

[00:02:51] But we provide the full suite of services around that. Well, so much has changed in this space over the last few years, especially with the arrival of AI. And if I look back to my own IT career, third party risk was traditionally built around things like questionnaires and spreadsheets and annual reviews. But why has that approach reached its limits in today's threat environment? Yeah, it really, it's a great question.

[00:03:18] So this really has to do with the history of third party risk management. This was historically a compliance issue, a check the box issue, just designed for a different era. Point in time assessments. Since you did an assessment in January, by March it was obsolete, but it didn't really matter. And you had annual refreshes perhaps every few years.

[00:03:44] Also, there was no visibility into any of your M parties. So there was zero visibility into fourth and fifth party. There was no concept of continuous monitoring around those vendors. This was all really framed around this being a compliance issue and not really a security process.

[00:04:04] But with the threat landscape, as you know, changing daily and vendors constantly updating their software infrastructure, their capabilities, with attackers now having frontier models available to them, it's time for something new. It really is, because I think the big takeaway here is attackers are now moving at machine speed, as we record this in 2026.

[00:04:33] And many organizations, though, still assess their supplies just once or twice a year. But just to hammer home the point that we're trying to make today, what risks does that kind of disconnect create for security teams? And the number one thing, and it's no secret, it creates a false sense of security. Because you think you're okay because someone somewhere, very often an outsourced outfit, check the box.

[00:05:01] But in reality, that's not matching the needs of the organization. And just to kind of elaborate on this a little bit more, if you step back, there's machine speed attacks that are happening. We're in a hyper-connected supply chain world now, and increasingly so. And in this world of autonomous offense, we think of it as you need autonomous defense.

[00:05:27] And that's permeating throughout the entire security landscape on the defensive side. And GRC and third-party risk management are no exception, and they need to match those speeds. One way we think about this is that AI and mythos have really broken the math on third-party risk management. So there's a shift from compliance to security that we talked about.

[00:05:56] The attack surface is now the supply chain. It's a force multiplier, right? You attack someone and you attack your direct supplier or supplier-supplier. That's a much easier thing to do than, or if your supplier-supplier is attacked, then them attacking you. Imagine attacking a bank. The posture is very high, the security posture. But, you know, you go up a few chains in the supply chain, things are different. And we're seeing this, you know, all the time.

[00:06:25] There's also this idea of very timely, this shift to enablement in organizations around businesses wanting to adopt AI. The CISO, of course, is kind of straddling the enablement piece on one hand, but the accountability of defense on the other. And again, with the supply chain, this is no different in terms of, you know, their areas of concern.

[00:06:53] And then just protecting against AI-based supply chain attacks is also something that's really important. You cannot rely on a more traditional process when you have models like Kimi and others that are in the hands of anyone, really, with enough GPU horsepower to launch these attacks. So, in short, it's the TPRM side just as in scaling.

[00:07:21] And we do think of this as beyond TPRM. This is really around, you know, supply chain as a new attack surface in general. A nice way to think about this is we say that enterprises need AI to buy AI safely today. And they also need AI to protect against their AI-based attacks. And I think it's also important to highlight that many people listening, especially if they're in security teams, they're already stretched.

[00:07:49] They've well-documented burnout in the industry, alert fatigue. The list goes on and on. But what we're talking about here is not having to do it all on their own. And AI can be a great helper here, especially those repetitive, mundane tasks. And your platform has introduced AI agents into third-party risk management. So, we're not just saying, hey, you all need to go out there once or twice a year is no longer good enough.

[00:08:13] So, tell me more about what decisions organizations can confidently automate today and why they should still leave the human judgment to remain a very human part of that process. Yeah, I'll start with the first part. So, we talked to, before starting the company, over 100 CISO organizations. And this was, you know, identified as a top three issue. There were not enough resources to do the job that they're being asked to do. And, you know, you take shortcuts.

[00:08:43] And so, this was really around, you know, not enough people to do the work. So, there's a whole element of time compression on how can I do more with less. And there's also this idea that the AI capabilities act as a force multiplier. So, they can start automating a lot of their traditional, we think of them as like these jobs to be done, mundane but critical jobs to be done.

[00:09:09] So, our sets of agents are really clustered around everything from intakes. So, if I'm a business user who has an intent to purchase a project management tool or have a specific tool in mind that I want to purchase. Traditionally, that's been a one-way gate. I simply declare what I want and wait a few months until someone from security approves it. Very one-way.

[00:09:39] There's no element of risk mitigation. So, our agents start at that point and have a two-way conversation with a business user. And proxying the security team's controls, duplication, things like that.

[00:09:58] And when you're able to take that process all the way from intake through a business user co-pilot all the way to the entire evaluation process that the security team has to do through continuous monitoring, continuous assurance, onboarding, the entire offboarding. It's the entire range of tasks. And evidence gathering is really just one piece of it.

[00:10:25] There's also all the risk analysis and the reporting that needs to be done and the findings, which is extremely time-consuming. And you put all that together and that represents a significant ROI. We have customers, we have a Fortune 200 that literally declared to us that this has been a force multiplier for their team, unlocking capacity for their team to do other things.

[00:10:52] So, we've got a lot of examples like this where the time compression has resulted in the team doing other things. I think of this as just really one of three value propositions. The second one, obviously, is a risk reduction because now you're able to monitor not just your immediate supply chain or your immediate suppliers, but your supplier's suppliers. And that was simply not possible. So, that has nothing to do with time compression.

[00:11:22] That was impossible to monitor before. How do you monitor thousands of vendors? You can't. There's also this idea of just around this risk reduction of insider risk that you're preventing insider risk. And why is that?

[00:11:40] Many large organizations and, you know, we have Fortune 500 organizations that are customers all the way down to mid-market organizations in the regulated and unregulated space. And across the board, many organizations outsource some of those capabilities offshore. Sure. Now, what's introduced there is the potential for insider risk.

[00:12:05] So, when you're taking this entire process and bringing it in-house, you know, you're outsourcing to your GPU. It has a very different risk profile and it lowers the risk tremendously. That's the second value. So, time, savings, I would say the risk reduction. The third one is the one that I get most excited about. And this really has to do with enablement. You're enabling the company to move faster. Well, why is that?

[00:12:34] In the age of AI, you need AI to buy AI, as I was saying earlier. And often, the bottleneck process is the security review. What ends up happening is people sometimes go around it with shadow AI. But if you can de-bottleneck that process that is holding someone from doing their job in a more productive way, and you're able to make that process move faster, that the entire organization starts to move faster.

[00:13:03] So, this is like there's an overall enablement message when you zoom out a little bit more. And I also wanted to bring up the topic of supply chains because they've become so much more complex in recent years. We're not just talking about third parties now. We're talking about fourth and fifth party dependencies that many organizations didn't even know that they have on many occasions.

[00:13:26] So, how can businesses gain maybe more meaningful visibility without creating even more operational overhead? Yeah, I mean, this is by far one of the areas that resonates the most with our customers. One of the biggest challenges today is that organizations don't even know what their true exposure is, where it begins and ends when it comes to the supply chain. And again, the framing here is that the supply chain is the new attack surface.

[00:13:55] And so, every vendor depends on other vendors, and especially now in the AI space where there's a lot of interconnectivity at the model level, etc. It's important to make all of that visible. And it's largely invisible today. Our AI can continuously map these dependencies. You can visualize a graph of your third, fourth, and fifth parties in our platform.

[00:14:22] And you understand how they're connected, where the concentration is. You can start asking questions, very outcome-based questions, once you understand what that mapping is, understand what your exposure is. And it's not just about the visibility, but also about the remediation. Because now I know, like in the recent Vercel attack, if I don't use Vercel, I know if my fourth parties are using Vercel.

[00:14:51] So there's this idea of understanding the interdependencies. Then I can understand what the blast radius is. I can take appropriate action. And this isn't really just about creating more dashboards and more manual work. Our whole idea is, this type of automation really reduces the operational overhead in understanding all of this. And giving the security team much richer context from which to operate.

[00:15:18] And I'll just spend another 10 seconds on context. In the age of AI, we hear this term a lot, you know, context windows and context. When we map out the supply chain, we're taking all of this really information-rich, dense data, these rich data sets, and we bring them into a single context that enable our customers to ask really important questions.

[00:15:46] And now they're able to do that. They're able to tap into that and make decisions based on that. And as we've mentioned a few times today, yes, AI is helping defenders, but it's also helping the attackers. So how do you ensure organizations can safely use autonomous AI for cyber defense without accidentally introducing new governance or even new security? Yeah, absolutely.

[00:16:13] I mean, first of all, every AI system needs governance, whether that's a shadow AI system operating or whether, you know, a sanctioned contractual relationship that's based on AI. Our AI agents, they absolutely operate within each organization's policies. We produce explainable evidence-based recommendations that improve over time.

[00:16:38] And really, our core tenet here is that organizations don't have to choose between speed and capability versus trust. They need both. So you see emerging standards as well, which we conform to. You know, we're very transparent, obviously. We're in the business of trust, and we expect our customers to hold us to an equally high bar around this.

[00:17:06] So this is something that I think is still an evolving story in general in the industry, but we absolutely place the governance high when it comes to ourselves.

[00:17:17] And in general, when I talk to customers, the conversation often goes back to having a set of layers around governance for every unit of AI in your supply chain is really, really important.

[00:17:39] Understanding what that is, what that risk is, that ultimately leads to a supply chain breach prevention and response capability. So, again, a long way of saying that this is what we tell our customers to do with their own supply chain and AI, and we expect the reciprocation back on us as well. And this is a conversation that comes up all the time.

[00:18:04] And on a podcast talking about continuous monitoring, it will sound incredibly attractive, aspirational or an aspirational goal for every organization to achieve. But I'm curious, from someone that's working in the heart of this space and talking with so many different customers and businesses, what does it actually look like in practice? And how is it changing the day-to-day role of a third-party risk team? What are you seeing here?

[00:18:29] Yeah, this was core premise of the company and the founding of the company was really around when it came to third-party risk management and looking at all the jobs to be done in this arena. It was really around, can you have a swarm of agents that 24-7 monitors every single supplier in your whole chain?

[00:18:53] And that's just an image that transcends time of how we think about it. This needs 24-7 vigilance. Continuous monitoring is, you can't treat vendor risk like a snapshot, like a photograph. It has to be like a live video feed. There's a lot of dynamics going on, operational, financial, cyber, privacy.

[00:19:22] And our agents extract different signals, both permissionless as well as permissioned, plugged in directly into our customers' environments. And we're able to consolidate all of that and correlate it and establish a risk posture around every single supplier that's out there. And then that's step one.

[00:19:45] And then step two is to have an automated remediation step because the last thing we want to do is create more work for our customers. So once there's visibility, once you have exceeded certain thresholds of risk when it comes to a supplier based on all these different signals, there's automated actions that kick in.

[00:20:07] And it's important also to point out that the big unlock for the AI era is not just correlating different signals, but the nature of these signals. Historically, you had to only look at IOCs, indicators of compromise, very statics or very structured elements. Well, now we look at unstructured data too.

[00:20:34] So I'll give you a good example of this from a continuous monitoring. Let's say I sign up a vendor and then let's say that vendor over time changes their terms of service. And they might send a notification out to the business user who receives an email in their inbox. But most people ignore that stuff. But someone somewhere cares on whether or not any of those terms of service changed.

[00:21:01] It could be as drastic as that they now training on customer data. And that's really, really important for the security team to know that. Now, the nature of this information might be buried in a document, a 50-page document.

[00:21:18] And again, going into where agents are really powerful is they can scrub through all that unstructured data and transform it into a way that can lead to a positive outcome for the security team. And say, look, this vendor basically went from green to red or green to yellow for this reason. In terms of service change, here's how it impacts you.

[00:21:44] And we might correlate that perhaps with an acquisition that happened or some other structured data elements that might be important in this context. So this is really all about this 24-7 vigilance.

[00:22:00] And when we talk to customers, I would say the number one thing that's on their mind is how do I bring in continuous monitoring into the agentic era, both around governance and security for all my suppliers. And when we're talking about implementing big changes in organizations, whether they be cultural or technological, of course, it's not all sunshine and rainbows. I suspect you've came across more than a few challenges, a few war stories along the way.

[00:22:29] So if you could change one thing about the way that boards and executive teams think about third-party risk today, what would it be? And why is that change becoming increasingly urgent? Yeah, I would say that I would encourage leaders in organizations to stop thinking of third-party risk as a procurement or compliance function. And start viewing it as a core element of cyber resilience.

[00:22:57] The supply chain is the new attack surface. It's the number one attack surface and will increasingly become even more important in an increasingly hyper-connected world. And in a world where you have machine speed attacks and autonomous offense, that's why you need autonomous defense. And it has to be grounded in security. Now, there's other domains for sure. There's legal, there's privacy, there's operational, financial.

[00:23:26] You have to look at the 360 view of risk when it comes to an entity. But this is very much moving towards a cyber perspective. And one thing I wanted to address, which you were mentioning earlier about the role of the human in all of this. Again, this has to do with force multiplication.

[00:23:47] So, the more we can automate as this shift is happening to security, the more we can bring in humans for judgments, for exceptions, to ask the hard questions.

[00:24:01] So, how much at a board level, how much can be prepared in advance through these systems like ours such that the right questions can be asked and made instantly where the answers are made instantly available? An example of that might be, you know, what supplier, if it goes down, is going to be, you know, the most risky for us. That's a question around concentration risk.

[00:24:31] All these signals have to emanate such that I'd get aggregated such that that question can be asked. And this is the world we're headed to. So, again, just maybe a long-winded way of saying is stop thinking of third-party risk as a procurement or compliance function and really think of it as a core part of your security practice. I think that is a powerful message to end on.

[00:24:57] And for anyone listening wanting to talk a little bit more about this, find out more information about your work and how you're helping. Where would you like me to point everyone listening? Yeah, absolutely. You can visit us at magnitude.ai, M-A-G-N-I-T-U-D-E, magnitude.ai, to learn more about our autonomous AI workforce for third-party risk management.

[00:25:20] And also on all the socials on LinkedIn and X, where we regularly share insights on AI and cybersecurity. So, on LinkedIn, magnitude-HQ, or myself, Rami Habal. And on X, it's magnitude. Awesome. Well, I'll include links to the website, the socials, your LinkedIn profile. I encourage anyone listening that have been inspired by some of the things we've talked about today that will go visit you and stay in touch.

[00:25:48] I'd love to get you back on later in the year or early next year, see how things are evolving for you and how the threat landscape is evolving. But thank you for joining me today. Thank you. Pleasure. I think my guest's argument today leaves security leaders with a practical challenge. Third-party risk cannot remain an annual compliance exercise, especially when vendors, dependencies, contracts, and attack methods all continuously change.

[00:26:17] Visibility should extend beyond direct suppliers to the companies supporting them. Continuous monitoring, yes, that can identify changes in security posture, ownership, services, privacy teams, or even data practices before the next scheduled review. And then AI. That's something that can be brought in to process the volume, correlate those signals, and recommend action.

[00:26:41] All while your people, your teams, can handle exceptions, commercial consequences, and decisions that are carrying serious business impact. So remember you can learn more about Magnitude's AI workforce for third-party risk management at magnitude.ai. Or follow my guest and Magnitude on LinkedIn. I'll give you all the links over at techtalksnetwork.com.

[00:27:06] And before I go, does your organization treat supply risk as just compliance paperwork or as an active part of cyber resilience? And if it is the former, what are you going to do about it? Keep those messages coming over to me at techtalksnetwork.com. But that's it for today. Thanks for listening. Bye for now.