Scalable Third-Party Risk Management with AI-Driven Automation
Nullcon Goa 2026 · Day 1
Overview
This Nullcon talk, "Scalable Third-Party Risk Management with AI-Driven Automation," delves into the increasingly complex landscape of cybersecurity risks stemming from an organization's reliance on external vendors and partners. Presented as a dynamic panel discussion featuring Kedar, Dr. Sri, and Uday, the session meticulously unpacks the challenges of managing an ever-expanding ecosystem of third, fourth, and even fifth parties in an era defined by rapid digital transformation and the pervasive integration of AI. The speakers, drawing from their extensive experience, highlight the critical shift from traditional, often manual, compliance-driven risk assessments to a more proactive, architecturally sound, and intelligently automated approach.

Key moments
- 0:00 Introduction and the car wiper analogy
- 2:15 Real-world example: Antivirus vendor compromise impact
- 4:00 Business dilemma: Accepting potentially compromised third-party code
- 5:00 Understanding the scale: 550+ vendors and ecosystem security
- 6:00 Introducing AI for automatic and intelligent third-party review
- 6:45 How AI manages the complex and interconnected vendor ecosystem
Scalable Third-Party Risk Management with AI-Driven Automation
Speakers: Kedar, Dr. Sri, Uday
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=_QMLmrQHygA
Overview
This Nullcon talk, "Scalable Third-Party Risk Management with AI-Driven Automation," delves into the increasingly complex landscape of cybersecurity risks stemming from an organization's reliance on external vendors and partners. Presented as a dynamic panel discussion featuring Kedar, Dr. Sri, and Uday, the session meticulously unpacks the challenges of managing an ever-expanding ecosystem of third, fourth, and even fifth parties in an era defined by rapid digital transformation and the pervasive integration of AI. The speakers, drawing from their extensive experience, highlight the critical shift from traditional, often manual, compliance-driven risk assessments to a more proactive, architecturally sound, and intelligently automated approach.
The central theme revolves around the inadequacy of conventional third-party risk management strategies in the face of modern threats and the sheer scale of vendor dependencies. As organizations increasingly integrate APIs, microservices, and AI agents into their operations, the attack surface expands exponentially, making comprehensive manual oversight impractical. The talk posits AI-driven automation not as a mere buzzword but as an essential tool for intelligently monitoring, assessing, and mitigating risks across a vast and interconnected digital supply chain.
Why this topic matters is underscored by real-world incidents and the evolving geopolitical landscape. From supply chain compromises that ripple through multiple layers of vendors to the impact of international sanctions on operational continuity, the discussion illuminates how third-party vulnerabilities can directly translate into significant business disruptions and security breaches. The speakers advocate for a fundamental re-evaluation of security hygiene, architectural design, and continuous monitoring, positioning AI as a critical enabler for maintaining resilience and sovereignty in a hyper-connected world.
Background
▶ Watch: Introduction and the car wiper analogy (0:00)
The foundational premise of the talk is established through a relatable analogy: purchasing a car without wipers, where the absence of a seemingly minor component, produced by a third-party, renders the entire product unusable. This illustrates the profound and often overlooked dependency on external entities that characterizes modern business operations. As Kedar articulates, "There is a heavy reliance on the third party." This reliance extends far beyond physical components to critical IT services, software development, cloud infrastructure, and even security operations.
The discussion quickly moves to a stark real-life example of how this dependency manifests as tangible risk. Kedar recounts an incident where his organization, a "regulated entity," was indirectly compromised due to a vulnerability in a fourth-party vendor. An antivirus company, not among the top five globally but widely used, suffered a breach where its patch distribution server was compromised, leading to the dissemination of malware (remote access, encryption, and other malicious payloads). Initially, Kedar's organization felt secure as they did not directly use this antivirus product. However, six days later, a critical vendor developing payment transaction code for them was found to be using the compromised antivirus. This vendor, in turn, became a conduit for potential compromise, jeopardizing Kedar's organization's payment gateway. The incident forced them to accept code from the potentially compromised vendor, leading to an urgent need for sandboxing and assurance, highlighting the severe business impact and the challenge of securing code from an untrusted source, even with traditional code review techniques. Kedar notes that typical code reviews often "will not look at the IOCs inside the code," such as a single line of Java beaconing to a C2 server. This scenario dramatically underscores the concept of Nth-party risk, where an organization's security is inextricably linked to its entire ecosystem, which can include "more than 550 vendors."
Dr. Sri then provides a historical context to the evolution of cybersecurity, tracing its journey over 27 years. He describes an arc from basic floppy disk formatting and virus detection to sophisticated signature-less detection, firewalls, Intrusion Prevention Systems (IPS), and network threat analysis. Crucially, he observes that the approach to third-party risk management has lagged behind. Five years ago, vendor onboarding was "Excel driven" and "compliance driven," often handled by finance or procurement departments with limited cybersecurity maturity. This static, annual review process is entirely inadequate for today's dynamic threat landscape.
The current paradigm, as highlighted by Dr. Sri, demands dynamic vendor onboarding via APIs, which fundamentally alters the risk assessment process. The "boundary" of an organization is no longer a static perimeter; it's a fluid, API-interconnected ecosystem. Dr. Sri champions a "secure by design" architectural mantra, emphasizing that security must be an inherent part of system creation, not an afterthought. This includes demanding evidence from third parties of their own hack attempts and vulnerability assessments, focusing on the absence of "high-end critical vulnerabilities."
Uday further expands on the macro-level influences, particularly geopolitical risks. He cites the example of a major Indian oil and gas company losing all office access for 48 hours due to US sanctions on its Russian parent company. Similar impacts have been observed in semiconductor supplies due to US-China-Taiwan tensions and the Ukraine crisis. These geopolitical shifts can abruptly sever supply chains, revoke software licenses, or cut off critical services, demonstrating that third-party risk extends beyond technical vulnerabilities to global political stability.
The increasing complexity is also driven by regulatory demands. Uday points to the DPDP (Data Protection and Privacy) Act, which mandates stringent obligations for protecting personal data. If third parties act as data processors, organizations must ensure their compliance and infrastructure protection, passing on liability. This necessitates continuous monitoring of third and fourth parties for internet exposures, breaches, and adherence to contractual obligations like Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). The collective sentiment is clear: the sheer "quantum of the dependency on a third party" and the limitations of human-driven, static processes necessitate a new, intelligent approach.
Key Findings
▶ Watch: Business dilemma: Accepting potentially compromised third-party code (4:00)
The panel discussion reveals several critical findings regarding the contemporary state of third-party risk management and the imperative for its evolution:
- Pervasive Nth-Party Risk: The most striking finding is the depth and breadth of indirect risk. Organizations are not just dependent on their immediate third parties but also on their vendors' vendors (fourth parties) and beyond. Kedar's antivirus incident vividly illustrates how a compromise far down the supply chain can directly impact an organization, even without a direct contractual relationship. This multi-layered dependency renders traditional perimeter-focused security and direct vendor-to-client assessments insufficient.
- Inadequacy of Traditional Risk Management: Manual, Excel-driven, and compliance-focused third-party risk assessments are obsolete. Dr. Sri emphasizes that this static approach, common even five years ago, cannot keep pace with the dynamic, API-driven nature of modern IT ecosystems. It fails to provide continuous, real-time insights into evolving threats and vendor security postures.
- AI as an Essential Enabler for Scalability: The "mammoth of outcome" generated by continuous monitoring and reporting from hundreds of vendors overwhelms human analysts. The core finding is that AI-driven automation is not a luxury but a necessity for intelligently processing this vast data, identifying anomalies, and automating responses, thereby enabling scalable and effective risk management.
- "Secure by Design" is Paramount: Dr. Sri's mantra of "architecture, secure by design" is presented as a fundamental principle. This means building security into the very fabric of systems and vendor relationships from inception, rather than attempting to bolt it on later. This includes rigorous pre-onboarding security assessments, demanding proof of hack attempts, and ensuring robust internal segmentation.
- Continuous Monitoring is Non-Negotiable: Given dynamic environments and evolving threats, one-time or annual assessments are insufficient. Uday stresses the importance of continuous monitoring of third-party internet exposures, breach notifications, disaster recovery capabilities, and compliance with data protection regulations (like DPDP). This provides real-time visibility and enables rapid response to emerging risks.
- Emergence of New Attack Vectors through AI Integration: The example of the DRM solution with an AI agent bypassing file protection highlights how the integration of AI, while offering benefits, can inadvertently create novel attack vectors. Internal API communications between applications and AI bots can exploit previously unconsidered data flows, making traditional monitoring ineffective and pushing security towards behavioral analysis.
- Geopolitical Events as Major Risk Multipliers: Uday's examples demonstrate that geopolitical tensions and sanctions are not abstract concepts but direct, significant drivers of third-party risk, capable of causing immediate and widespread operational disruptions by severing critical supply chain links or service access.
- Fundamental Hygiene Remains Critical: Despite advanced threats and AI, Dr. Sri reiterates that basic security hygiene—knowing "who is coming," ensuring proper authentication and authorization for all internal and external entities, and maintaining perimeter control—remains the bedrock of a strong security posture.
Technical Deep Dive
▶ Watch: Understanding the scale: 550+ vendors and ecosystem security (5:00)
The technical aspects of the talk underscore the increasing complexity of modern IT ecosystems and the limitations of traditional security controls. Kedar’s initial anecdote provides a critical technical illustration: a compromised antivirus vendor’s patch server pushing malicious updates. This highlights a sophisticated supply chain attack vector, where trusted software updates become a conduit for malware. The malicious payload included remote access, encryption, and other malware, indicating a multi-faceted compromise. The subsequent impact on Kedar's organization, through a fourth-party vendor developing critical payment transaction code, demonstrates how deep an attacker can penetrate an ecosystem. The challenge wasn't just detection, but remediation: accepting potentially compromised code and relying on sandboxing for behavior analysis, as traditional code review techniques were deemed insufficient to detect a "one line written in the Java where it's a beaconing and giving the message to the C2." This implies a need for runtime analysis and behavioral detection over static code analysis for such subtle threats.
The speakers then delve into the role of AI. Kedar states that with "a so huge ecosystem of vendor," manual review of digital landscape monitoring reports from third-party assurance providers is unsustainable. AI is presented as the solution to "intelligently review those things," processing the "mammoth of outcome" to identify risks and potentially automate communication with vendors. This suggests AI's application in threat intelligence correlation, risk scoring, and automated remediation workflow initiation.
Dr. Sri introduces "secure by design" architecture as the fundamental defense. This means building security into the system's core, especially for dynamically onboarded vendors via APIs. Instead of just compliance checklists, organizations should demand penetration testing reports from vendors, specifically looking for the absence of "critical and high vulnerabilities."
The discussion on Agentic SOCs (Security Operations Centers) further highlights new technical challenges. Kedar poses a dilemma: if an external company deploys its AI agents to manage SOC functions and significantly reduce manpower, how is this new type of third-party risk assessed? These agents, while internal to the SOC function, are external entities operating within the organization’s environment, potentially communicating sensitive data. This scenario demands a re-evaluation of trust boundaries and monitoring capabilities for inter-agent communication and data exfiltration.
A particularly insightful technical example is given by Kedar regarding a DRM (Digital Rights Management) solution that integrated an AI agent. This bot, designed to summarize files, implicitly copied the file's content. While traditional DRM would prevent copying to a notepad, the AI agent's internal API communication allowed the content to be copied from the bot's prompt, effectively bypassing the DRM protection. This demonstrates a novel side-channel attack or unintended data leakage vector introduced by AI functionality, exploiting the internal processing of data by the AI rather than direct user interaction with the protected file. This scenario underscores the need for internal guardrails and API security within applications that integrate AI, as traditional security controls may not cover these new data flows.
Dr. Sri responds to this by emphasizing the need for robust security in microservices architectures. He advocates for guardrails between containers, ensuring that microservices are not allowed to "talk to other microservices" by default. The critical design mistake, he notes, is placing a firewall only at the perimeter while neglecting internal segmentation. Instead, ACLs (Access Control Lists) should be implemented for inter-service and intra-service communication, coupled with authentication and authorization for every microservice. This principle of zero-trust for internal communications is crucial for preventing lateral movement and containing breaches within a microservices environment.
The shift in threat detection is also discussed: the move away from signature-based detection (traditional antivirus) towards behavior-based EDR (Endpoint Detection and Response). Kedar suggests that with AI-generated attacks, every new threat could be a "zero-day" because AI can generate novel, unpredictable attack patterns. This necessitates systems that "will not touch the file unless it executes," focusing on malicious behavior rather than static signatures, challenging traditional regulatory demands for "clean environments." This implies a reliance on advanced machine learning models for anomaly detection and threat hunting to identify these emergent, AI-driven threats.
Demo / Proof of Concept
▶ Watch: Introducing AI for automatic and intelligent third-party review (6:00)
This talk was structured as a panel discussion, focusing on conceptual frameworks, real-world examples, and strategic insights into third-party risk management. As such, no live demonstration or proof of concept was presented during the session. The speakers conveyed their points through narratives and expert commentary rather than technical demonstrations of tools or exploits.
Defensive Implications
▶ Watch: How AI manages the complex and interconnected vendor ecosystem (6:45)
The detailed discussion on third-party risk management, especially in the context of AI and geopolitical shifts, provides several critical defensive implications for organizations:
- Achieve Comprehensive Visibility: Organizations must move beyond tracking direct third-party vendors. It is imperative to map out the entire supply chain ecosystem, including fourth-party and even fifth-party dependencies. This involves understanding what services or components each vendor provides, their sub-vendors, and the interfaces between IT systems and these external entities (18:00-19:00).
- Embrace "Secure by Design" Principles: Security must be ingrained into the architecture of all systems and vendor engagements from the outset. For microservices, this means implementing guardrails between containers, enforcing a default-deny policy for inter-service communication, and requiring authentication and authorization for every microservice (23:00-24:00). Organizations should demand proof of robust security testing, such as penetration test reports showing no critical vulnerabilities, from their vendors (11:00-12:00).
- Implement Continuous Monitoring: Static, annual assessments are insufficient. Organizations need continuous monitoring of their third and fourth parties' security posture. This includes actively scanning for internet exposures, subscribing to breach notifications, and verifying adherence to contractual obligations like RTO/RPO and data protection regulations (e.g., DPDP) (20:00-21:00). This proactive approach helps detect emerging risks in real-time.
- Leverage AI for Automation and Intelligence: Given the "mammoth of outcome" from monitoring numerous vendors, AI-driven automation is crucial. AI can intelligently process vast amounts of risk data from reports, identify patterns, prioritize risks, and automate communication with vendors for remediation (06:00, 21:00). This shifts the focus from manual review to intelligent analysis and response.
- Strengthen Internal Segmentation and API Security: The example of the DRM bot bypassing protection highlights new attack vectors introduced by AI. Organizations must apply robust security controls not just at the perimeter but also internally, especially for API communications between applications and AI agents. This includes rigorous input validation, output filtering, and access control for internal APIs to prevent unintended data leakage or manipulation (22:00-23:00).
- Adopt Behavioral-Based Threat Detection: With the rise of AI-generated "zero-days" and sophisticated, subtle code-based threats (like a single line of Java beaconing to a C2), organizations should prioritize behavioral-based EDR (Endpoint Detection and Response) solutions over purely signature-based ones. These systems can detect malicious activity at execution time, even if the initial file is unknown (31:00-32:00).
- Strategically Manage Vendor Selection: A balanced approach to vendor selection is vital. For critical functions, organizations should generally opt for large, established players offering high "reasonable assurance." However, for niche innovation or R&D, engaging with smaller, specialized startups can be beneficial, provided a thorough risk assessment is conducted focusing on their security hygiene, scalability, and incident response capabilities (26:00-28:00).
- Account for Geopolitical Risks: Geopolitical events can have immediate and severe impacts on supply chains. Organizations need to assess the geopolitical exposure of their critical vendors and develop contingency plans to maintain operational continuity in the event of sanctions, conflicts, or other international disruptions (16:00-18:00).
- Reinforce Fundamental Security Hygiene: Despite the complexity of modern threats, basic security hygiene remains foundational. This includes robust identity and access management, ensuring proper authentication and authorization for all users and services (internal and external), and maintaining clear visibility over who is accessing what within the environment (24:00-25:00).
Key Takeaways
- Third-party risk is no longer limited to direct vendors but extends deeply into fourth and fifth parties, creating complex, interconnected attack surfaces that demand comprehensive visibility.
- Traditional, compliance-driven, Excel-based risk assessments are obsolete and inadequate for managing the dynamic and vast vendor ecosystems of the modern digital era.
- AI-driven automation is essential for intelligently processing the massive volume of data from third-party monitoring, enabling scalable risk management and proactive response.
- "Secure by Design" architecture is paramount, requiring security to be built into all systems, including microservices, with internal segmentation and robust authentication/authorization for every component.
- Continuous monitoring of vendor security posture, internet exposures, breach notifications, and adherence to regulatory obligations like DPDP is critical for real-time risk mitigation.
- The integration of AI can introduce novel attack vectors and bypass traditional security controls, necessitating a shift towards behavioral-based detection and enhanced internal API security.
- Geopolitical events are significant and immediate drivers of third-party risk, requiring strategic vendor selection and contingency planning to ensure operational resilience.
About the Speaker(s)
The panel featured three distinguished speakers, each contributing a unique perspective from their extensive experience in the cybersecurity domain:
- Kedar appears to be a cybersecurity practitioner, likely in a leadership role within a regulated entity. His contributions focused on real-world incident response, the challenges of managing a large vendor ecosystem (over 550 vendors), and the practical application of sandboxing for risk mitigation. He emphasized the need for intelligent automation to manage the scale of third-party dependencies and the unique challenges faced by regulated organizations.
- Dr. Sri is a veteran in cybersecurity, boasting over 27 years of experience. He shared a historical perspective on the evolution of security, from early viruses and worms to modern proactive controls, drawing on his background, including experience with a major security software company like McAfee. Dr. Sri is a strong advocate for "secure by design" architecture, emphasizing that security must be fundamental to system creation. He also humorously noted his journey from being a hacker at Nullcon to a speaker, highlighting his deep engagement with the community.
- Uday provided insights into the strategic and geopolitical dimensions of third-party risk. His contributions included real-world examples of how international sanctions and geopolitical tensions directly impact supply chains and operational continuity. He stressed the importance of complete visibility over third and fourth parties, continuous monitoring, and adherence to data protection regulations like DPDP. Uday also discussed the nuanced approach to vendor selection, balancing the reliability of large players with the innovation of niche startups based on "reasonable assurance" and risk profiles.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A panel that mistakes breadth for depth — covering supply chain risk, AI agents, geopolitics, and DPDP in 35 minutes without going deep on any of it. The anecdotes are real, but the content never advances past what a thoughtful practitioner already knows, and 'AI-driven automation' is invoked as the answer without ever showing you the AI.
Heather Calloway (CISO) — WEAK
The topic is legitimate and timely — Nth-party risk, AI-driven supply chain exposure, and regulatory pressure are real governance problems. But this panel stays at the surface, cycling through familiar frameworks and anecdotes without producing anything a security leader couldn't already recite. It identifies the problem clearly and then stops.