06/19/2026
Brian Markham delivered a fantastic session at RVAsec 15 that every security leader managing vendor risk should watch.
CISO at EAB Global. He breaks down why most third party risk programs are overengineered, why a 500-hour vendor assessment can collect less data than a Wordle signup, and what a smarter approach to TPRM actually looks like.
๐ฅ Get the full breakdown here: https://youtu.be/AZgczztn2Lw?si=Ybf7j_y6phkSWDUt
How much time does your organization spend on third party risk assessments? ๐
Presentation: Swatting Flies With Sledgehammers: Broken TPRM Progra...