The gap between good and great isn't budget. It's habits.
We've worked with hundreds of organisations on their third-party and supply chain security programmes. The pattern is always the same.
Some teams are still buried in spreadsheets and questionnaires, chasing suppliers for updates that arrive too late to matter. Others have found a different way to work. They're using AI in the right places, not just for volume. They're constantly refining how they respond to incidents. And critically, they've got executive leadership bought in, not just tolerating the programme but backing it.
What separates the two?
This AMA session digs into the habits, decisions and mindset shifts that define high-performing security teams, and what's holding everyone else back.
Example questions we'll explore
- What separates the most mature security teams from the rest?
- Where are organisations wasting the most time in TPRM today?
- What does a good relationship between Security and Procurement actually look like?
Who's in the room
Moderator:
Justin Kuruvilla
Panel:
Raj Kohli, Managing Partner, DCR Partners
Ben Gibbins Managing Principal, Orange Cyberdefense
What you'll get
- A straight answer on what separates high-performing security teams from the rest, based on patterns across hundreds of real programmes
- Practical detail on where TPRM time gets wasted, and where it doesn't need to be
- A working view of what a healthy Security and Procurement relationship looks like in practice
- The chance to ask your own question live, or submit it in advance



