Can a supplier assessment completed once a year protect an organization against risks changing at machine speed?
In this episode of The Business of Cybersecurity, I speak with Rami Habal, founder and CEO of Magnitude. We discuss why traditional third party risk management is struggling to keep pace with connected supply chains, autonomous attacks, AI adoption, and constantly changing vendor environments.
Rami explains that third party risk management developed largely as a compliance process. Companies relied on questionnaires, spreadsheets, point-in-time assessments, and annual reviews. Those methods provided documentation, but they offered limited visibility into what changed after the review or which fourth and fifth parties supported the original vendor.
The result can be a false sense of security. A supplier may change its infrastructure, ownership, software, data practices, or terms of service months before the customer performs another formal assessment. Attackers do not wait for the next compliance cycle.
Rami argues that AI has broken the traditional mathematics of third party risk. Security teams cannot manually monitor thousands of suppliers and every organization supporting them. Attackers can use advanced models to find weaknesses faster, while businesses are adding AI services and dependencies at speed.
Magnitude provides what Rami describes as an AI workforce for third party and supply chain risk management. Its agents support tasks including supplier intake, evidence gathering, security evaluation, risk analysis, onboarding, continuous assurance, and offboarding.
We discuss how this automation can address three business problems. The first is time compression, allowing security teams to process supplier reviews faster. The second is risk reduction through wider visibility, including fourth and fifth party dependencies. The third is business enablement, reducing delays that might otherwise encourage employees to use unapproved AI tools.
Rami explains how Magnitude maps supplier relationships as a connected graph. Security teams can see where dependencies overlap, identify concentration risk, and assess which parts of the business may be affected when a provider experiences an incident.
Continuous monitoring also includes unstructured information. A vendor may update a lengthy terms of service document and introduce permission to train AI systems using customer data. An employee receiving the notification may ignore it, while an automated agent can compare the document, identify the change, and explain its potential effect.
Rami uses a helpful analogy. Traditional vendor assessments resemble photographs, while continuous monitoring resembles a live video feed. Operational, financial, cybersecurity, and privacy risks continue changing after the original assessment.
Automation does not remove people from the process. Rami sees AI preparing evidence, correlating signals, and recommending action while humans handle exceptions, ask difficult questions, and judge the business consequences.
He closes by urging boards to treat third party risk as part of cyber resilience rather than leaving it within procurement or compliance. Does your organization know which suppliers create its greatest concentration risk and how far a breach could travel through the chain? Listen to the conversation and share your thoughts with me.

