Someone Else's Breach
Vendor incident response as its own discipline — distinct from TPRM and from internal IR. The DC-TPIR framework: conditional exposure analysis, calibrated estimation, defensible decisions, institutional memory. Based on the practitioner's guide of the same name.
- 2of 5
Are We Affected? The Sixty-Minute Triage for Vendor Incidents
The Slack alert lands at 3:47pm. By 4:00 the CISO needs a recommendation. Three questions, five artifacts, sized for a small security team. The framework that makes the next vendor incident go differently.
Read - 3of 5
Conditional Exposure Analysis: Why Your Risk Isn't What the Vendor Reported
FAIR estimates whether a loss event will occur. Vendor incidents: the loss event already occurred. P(InScope) × P(Affected | InScope) × P(Exploitable | Affected) — the decomposition that makes vendor risk quantifiable.
Read - 4of 5
Stay, Exit, or Mitigate: The Vendor Incident Decision Framework
Exposure analysis says 18%. The CISO asks what to do. Four options, one decision criterion, five anti-patterns to avoid. The framework that converts judgment into defensible recommendation.
Read - 5of 5
Mitigation Debt: The Silent Risk That Accumulates Between Vendor Incidents
Eighteen months ago you committed to controls after a vendor incident. Today the same vendor has another one. The mitigations were partly delivered, partly not. The math + memory system that surfaces what TPRM misses.
Read
Ready to put this into practice?
See how vCISO Lite operationalizes the methodology behind this series.