Shownotes
Craig Duckworth sits down with Jowanza Joseph, CEO of Parakeet Risk, to unpack why third-party risk has become one of the most urgent challenges facing manufacturers and critical infrastructure operators.
Jowanza spent 15 years in engineering roles at Adobe, Pluralsight, and MasterCard before founding Parakeet Risk to serve an industrial sector he saw as the most underserved when it comes to technology.
Together they address why simply knowing who your vendors are is harder than it sounds, how insurers are moving past checkbox questionnaires and demanding real evidence of controls, and what happens when contracts require you to identify a new asset in your OT environment within five minutes.
They also get honest about the organizational problem few want to own: security leaders who carry responsibility for the plant floor without the authority to change anything on it. Jowanza closes with a practical, low-cost starting point for any organization and a look at where vendor attestation is headed over the next five years.
Chapters:
- (00:00:00) Why industrial companies must become cybersecurity companies
- (00:02:08) Cataloging and prioritizing your most dangerous vendors
- (00:04:37) The hidden layers of subcontractors in your supply chain
- (00:06:42) Cyber insurance moves past the checkbox era
- (00:10:47) Contracts that demand new asset identification in five minutes
- (00:12:58) AI is multiplying vulnerabilities faster than solutions
- (00:16:31) Three hallmarks of a strong third party risk program
- (00:21:14) Incident response, game days, and who falls on the sword
- (00:23:42) Responsibility without authority across the IT and OT divide
- (00:28:31) Where to start today and the future of vendor attestation
Links And Resources:
Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!