
The security questionnaire was built for a world with a few dozen vendors, one or two
frameworks, and enough time to read what came back.
Then portfolios ran past a hundred vendors, and every tool that shipped an AI feature this
year re-tiered itself into your critical list. The questionnaires got longer. The answers
still come back as a column of yes. The proof that would settle it is sitting in an audit
report nobody has the hours to open. What changes when an agent can find that evidence, read it, understand what it proves, and assess it against your own requirements?
Murat Tirmandi opens on why the questionnaire model stopped holding, how work changes by introducing agents, and how Anecdotes approached TPRM differently. Then Conor Russo (ex Cyera, Netskope, Optiv), who now runs third party risk and GRC at Anecdotes, sits down with Lior who manages compliance and risk at Palo Alto Networks and Natalie who leads GRC at Fireworks AI, on what their programs used to entail, what their teams work on now, and what a strong TPRM practice takes. Conor closes with a short live walkthrough of his own program: one vendor, assessed against his own standard, on evidence rather than answers.
What you’ll take away
If your board asked today which of your critical vendors meet your own standard, how long
would it take to answer with proof? Join us on October 28.