Greg Rasner
Greg Rasner Speaker Biography
Gregory Rasner is a CEO, author, educator, and speaker specializing in cybersecurity, zero trust, and third-party risk. With over 25 years of experience in IT and cybersecurity, he has helped organizations across finance, biotech, telecom, and software improve their security posture and reduce risk exposure.
Gregory is the author of four books on third-party risk and zero trust: Cybersecurity and Third-Party Risk: Third-Party Threat Hunting (2021), Zero Trust and Third-Party Risk: Reduce the Blast Radius (2023), Privileged Access Management: Strategies for Zero Trust in the Enterprise (co-authored with his wife, Maria Rasner), and his newest release, AI & Third-Party Risk: Strategies for Success with your AI-enabled Vendors and Partners — the capstone to his third-party risk trilogy.
He is also the content creator behind the Third Party Risk Association’s “Third-Party Cyber Risk Assessor” certification program and its four-hour “Securing SaaS Applications” course, “Security Agent Mesh Training: Build a 4-Agent Cyber Defense” course, and he hosts the podcast Third Party Threat Hunters, where he interviews cybersecurity and risk leaders on the same issues he writes and speaks about. His website has frequent updates with blogs and course offerings directly.
Book this SpeakerFeatured Videos
Speech Topics
Third-Party Threat Hunting: Finding the Vendor Risk Hiding in Plain Sight
A vendor hands you a clean SOC 2 Type II report. The boxes look checked, everyone relaxes — then the breach happens anyway. That’s the control assurance paradox, and it’s the reason static, point-in-time vendor assessments keep failing organizations that did everything “by the book.” A polished report doesn’t mean the risk went away — it often just means no one’s asked the right follow-up questions, like whether your own side of the shared controls (access removal, internal mapping) is actually being done.
In this keynote, Greg draws on 25+ years in cybersecurity and his book Cybersecurity and Third-Party Risk: Third-Party Threat Hunting to walk audiences through how to move from reactive vendor questionnaires to active, ongoing threat hunting across the vendor ecosystem — finding the risk before it finds you.
Key Themes:
– Why a clean audit report and real operational security aren’t the same thing
– The shared-control blind spot most vendor risk programs never check (their own CUECs)
– Building a continuous, threat-hunting mindset into third-party risk programs
– Practical steps to reduce blast radius when — not if — a vendor is compromised
Best fit for: CISOs, risk and compliance leaders, procurement and vendor management teams, and boards looking to understand their real third-party exposure.
AI and Third-Party Risk: Managing the Vendors You Can’t Fully See
Most third-party risk programs ask one question about AI: does the vendor use it? That’s the wrong question. The right ones are how they use it, where they use it, and what data it touches — the difference between a vendor using AI for internal meeting notes and one letting AI make decisions or talk directly to your customers is the difference between a non-issue and a real exposure. Every AI vendor is also a data vendor, a model vendor, and increasingly a fourth-party risk multiplier — and most vendor risk programs were built for software contracts, not for systems that learn and change on their own.
Drawing on his newest book, AI & Third-Party Risk, Greg gives audiences a practical framework for extending third-party risk management to AI-enabled vendors and partners — covering what changes, what doesn’t, and where existing vendor risk programs are already falling behind.
Key Themes:
– Why “does the vendor use AI” is the wrong question — and what to ask instead
– Risk-based triage: low-stakes AI use vs. AI making decisions that touch customers or regulated data
– Data lineage, model risk, and fourth-party exposure in AI supply chains
– Where governance, procurement, and security need to move faster together
Best fit for: CISOs, AI/data governance leaders, procurement and legal teams evaluating AI vendors, and executives setting AI policy.
Zero Trust Beyond the Perimeter: Privileged Access in a Third-Party World
Zero trust usually gets talked about as an employee and device problem. It’s also a vendor problem: when an MSP, SaaS platform, or security provider plugs into your environment, they inherit your data, your uptime, and often your privileged access — and most zero trust programs stop at the edge of the org chart, never fully accounting for that inherited access.
Drawing on Zero Trust and Third-Party Risk and Privileged Access Management, co-authored with Maria Rasner, Greg shows audiences how to extend zero trust principles to vendor and third-party access — reducing the blast radius when access is misused or compromised.
Key Themes:
– Why “your vendor’s access is now your access” is the assumption most programs miss
– Applying least-privilege and continuous verification to third-party access, not just employees
– Practical steps to reduce blast radius from privileged-access failures
– Building a zero trust roadmap that includes vendors from day one
Best fit for: CISOs and security architects, identity and access management leaders, and organizations starting or maturing a zero trust program.