3rd Party Risk Management
,
Governance & Risk Management
,
Video
Australian Payments Plus’ Cody Kieltyka on Using Approaches Beyond Questionnaires
Cody Kieltyka, CIO, Australian Payments Plus
Supply chain risk management processes that rely solely on vendor questionnaires are failing to deliver meaningful security benefits despite their widespread use, according to Cody Kieltyka, CISO at Australian Payments Plus.
See Also: Why Zero Trust requires uncompromising network visibility
Understanding vendor interdependencies requires more advanced detection and prevention methods that extend beyond traditional approaches because the task to too complex for humans to manage without technological help.
“One of the things we’re doing is dark web monitoring of our vendors. If we’re suspecting them in a breach, we can force a conversation with them instead of waiting for them to notify us,” Kieltyka said. “For our most critical vendors, we’re also talking to them about our incident response plan. In the case of an incident, how would we work together? What would be the bridges that we’d be on? What information would we be sharing?”
In this video interview with Information Security Media Group, Kieltyka also discussed:
- The need for machine learning to identify concentration risks and weak points;
- How regulatory frameworks such as CPS 234 and CPS 230 drive risk management practices;
- Why security vendors themselves have become significant attack vectors.
Kieltyka is a cybersecurity expert with nearly 15 years of experience, specializing in defining strategies, implementing security capabilities and enhancing operations across industries. He adopts a consequence-driven, threat-informed approach to cyber risk management, focusing on cost-effective solutions.