Search Results
Search this site
382 results found with an empty search
- Verity Billson | Experian Ltd
Get to know Verity Billson, Experian Ltd, and a member of TPRA's Board of Directors! < Back Verity Billson Experian Ltd BOARD OF DIRECTORS Verity Billson is a senior leader in Third Party Risk Management with over 25 years of experience across financial services, retail, and manufacturing. She currently serves as Group Head of Third Party Risk Management at Experian, where she leads global oversight and strategy across UK&I, EMEA, APAC, and Brazil. Verity has a strong track record of building TPRM functions from the ground up, delivering operational resilience, and driving compliance with regulatory standards. Her career includes senior roles at Jaguar Land Rover, Boots, and Capital One, where she led supplier management strategies, contract negotiations, and risk mitigation initiatives. Verity is known for her strategic thinking, stakeholder engagement, and ability to deliver measurable results. She is also an active fundraiser for the British Heart Foundation and a recipient of the National Outsourcing Association’s Academic Achievement Award. Why are you interested in becoming a TPRA board member? I am passionate about advancing the Third Party Risk Management (TPRM) profession and contributing to the development of best practices that drive meaningful change across industries. Over the course of my career, I’ve successfully built and matured TPRM functions in large, complex organisations, often from the ground up. I understand the challenges practitioners face and the value of a strong professional community. Serving on the TPRA board would allow me to give back to the profession, collaborate with other leaders, and help shape the future of TPRM through thought leadership, advocacy, and strategic guidance. As a UK-based practitioner with a strong network across financial services, retail, and manufacturing sectors, I am well placed to support TPRA in driving increased adoption and membership within the UK. I can help raise awareness of TPRA’s value proposition, foster engagement with UK organisations, and promote the association’s resources and events to a wider audience. Next >
- Women Lead | Lisa-Mae Hill
Learn about Lisa-Mae Hill, Director for Venminder, and TPRA's WNTPRM November 2024 Leader Spotlight. < See All < Previous Next > Lisa-Mae Hill Director Venminder Biography Lisa is and dynamic and results-driven Information Security and TPRM Professional with over 15 years of experience, most currently leading a team of 12 in delivering comprehensive risk management, third-party risk management, vendor management, and cybersecurity solutions. Lisa is charged with managing complex projects, mitigating risks for her clients through comprehensive information security and regulation based assessments, and fostering strong relationships to enhance confidence. Lisa is known for her leadership skills and has a laser focus on team development and the growth of her team's professional and personal development. Lisa believes strongly (and has proven in her role) that operational excellence comes from a team that is challenged, rewarded and treated with respect and kindness. She has worked both in the private and public sector as well as across industries and has a love for helping clients feel confident about their Vendor Management program and the direction they take to assess and vet Vendors. She loves to take a complex process like integrating Information Security and technology into TPRM and make it feel attainable and manageable for any level of experience. Her passion is professional education and loves doing webinars, talks and classes for the TPRM and InfoSec community. Leadership Characteristics This was written by an employee (Travis Helton): To Lisa, Lisa, you embody the perfect blend of courage, humility, and care. Your unwavering bravery in the face of challenges inspires us all to push beyond our limits. Despite your remarkable achievements, you remain incredibly humble, always giving credit where it’s due and never seeking the spotlight for yourself. Your thoughtfulness shines through in the small, meaningful gestures that make each team member feel valued and appreciated. Whether it’s a kind word, a thoughtful note, or simply taking the time to listen, your actions consistently show how much you care. You are more than just a leader; you are a friend and mentor who feels like family. Your friendly demeanor creates a welcoming and inclusive atmosphere where everyone feels comfortable and supported. You are always approachable, ready to offer guidance and encouragement, no matter how busy you are. In times of crisis, your calm and composed nature provides a steady hand, guiding us through with confidence and grace. Your genuine kindness and unwavering support make you a pillar of strength, and your dedication to the well-being and growth of your team is truly inspiring. You don’t just lead; you uplift, nurture, and inspire everyone around you, making our workplace feel like a second home. I share this because I am not good at talking about myself and this came unexpectedly today from an employee. Leadership Challenges We have had great change in our company over the last 2 years and I am proud to say that our team worked together through every challenge and came out stronger then ever. I have found the hardest part about leadership is balancing the needs of the business and the people that the business needs. I have always erred on the side of taking care of my team and clients because I firmly believe that the stronger the confidence and loyalty in the team, the better you will always be. Key Take-a-ways TPRM is challenging because you are tasked with accountability and responsibility yet have no control over those that you need information from. It can be frustrating, but the most important thing to remember is a proactive approach with the knowledge of what you want to do and see from your Vendors is key. This helps you stay consistent and gives clear direction to your Vendors! Fun Fact I am a huge dog lover, a mom and a wife. I have a very grumpy old lady Pug, Jazzy Pants as well as an old man black Lab named Cooper. I am also a girl mom with two feral and wild minis that make me laugh everyday as well as double the grey hairs. I love to travel with my husband and I absolutely love to read.
- Women Lead | Morgan Binder
Learn about Morgan Binder, Third Party Risk Program Manager for Stripe, and TPRA's WNTPRM June 2023 Leader Spotlight. < See All < Previous Next > Morgan Binder Third Party Risk Program Manager Stripe Biography Morgan is a Third Party Risk Program Manager at Stripe and has spent the duration of her career in the risk and compliance space. Her belief in right-sized foundational governance based on benchmarks and best practices has enabled her to develop nimble risk programs for financial services firms. She seeks to create effective, strategic solutions to solve risk and compliance challenges facing the business and its stakeholders. Focus areas throughout her career have included enterprise, operational, and third party risk, business continuity, fraud prevention, regulatory compliance, and tooling enablement. Morgan has a M.S. of Enterprise Risk from Boston University and a B.S. of Management from Bentley University. She is based in the greater Boston area. Leadership Characteristics Morgan executes through others, partnering to guide them through problem solving steps and delegating solution building to successfully solve the problem. She is a relentless builder and is adept at balancing priorities to achieve strategic goals. Leadership Challenges Throughout her educational and career pursuits, Morgan has repeatedly found herself to be the only woman at the table. She has seen the power in finding sponsors –and being a sponsor—for leaders who need stronger representation at the table. It is incredibly important to her to give future leaders support while providing an opportunity for them to shine and demonstrate their skills in front of decision makers. Key Take-a-ways "Risk management is so often seen as a cost center, rather than a value driver. Find ways to provide opportunity through risk management! Balance should always be found with keeping the business safe and driving the business forward." Fun Fact Morgan enjoys traveling and seeks locations with outstanding scenery, food, and drink.
- AI for TPRM Professionals
TRAINING AI for TPRM Professionals Friday, November 20, 2026 Date & Time Friday, November 20, 2026 at 10:00:00 AM CST Intended Audience All TPRM Professionals Duration 4 hrs CPE Credits 4 Fee $159 Register Event Description Course Overview Instructor: Gregory C. Rasner, Third Party Threat Hunting LLC Show More SPEAKER(S) INFORMATION CPE CREDIT Gregory Rasner Gregory is a CEO, author, educator, speaker, and leader in the field of cybersecurity, zero trust, and third-party risk. With over 25 years of experience in IT and cybersecurity, he has helped numerous clients and organizations improve their security posture and reduce their risk exposure. He is the founder and CEO of Third Party Threat Hunting LLC, a cybersecurity consulting firm that specializes in a wide range of areas, including cybersecurity, cloud computing, network architecture, and more. The Third Party Risk Management (TPRM) Certificate Program , offered by TPRA in collaboration with our trusted partners, provides comprehensive training designed to enhance knowledge and expertise in TPRM best practices. This program features a diverse selection of courses covering critical topics in third party risk, cloud security, AI/LLM security, and more. Earn 4 CPE credits for attending the entirety of this training course.
- TPCRA 4-Day November Training & Exam Bundle
TRAINING TPCRA 4-Day November Training & Exam Bundle Monday, November 16, 2026 Date & Time Monday, November 16, 2026 at 4:00:00 PM CST Intended Audience Those interested in advancing their careers by taking TPCRA training Duration 12 hrs CPE Credits 12 Fee Starting at $340 Register Event Description The TPCRA Certification is a specialized qualification that validates expertise in assessing third-party cybersecurity controls, managing cyber risk assessments, and evidencing proficiency in cybersecurity assessment techniques, as well as establishing credibility for third-party risk management professionals. SPEAKER(S) INFORMATION CPE CREDIT Your Instructor Gregory Rasner Gregory is a CEO, author, educator, speaker, and leader in the field of cybersecurity, zero trust, and third-party risk. With over 25 years of experience in IT and cybersecurity, he has helped numerous clients and organizations improve their security posture and reduce their risk exposure. He is the founder and CEO of Third Party Threat Hunting LLC, a cybersecurity consulting firm that specializes in a wide range of areas, including cybersecurity, cloud computing, network architecture, and more. TPCRA training provides you with 12 hours of in-depth discussion on the examination domains, hands-on experience designing and performing cyber assessments, as well as opportunities to perform mock interviews and run through physical validation scenarios. Training is taught by a knowledgeable subject matter expert who has achieved the TPCRA Certification designation. Earn 12 CPE credits for attending 12 hours of TPCRA Training.
- TPRA Announces Winners of 2026 Third Party Risk Management (TPRM) Service Provider Innovator Award | TPRA
FOR IMMEDIATE RELEASE TPRA Announces Winners of 2026 Third Party Risk Management (TPRM) Service Provider Innovator Award Tuesday, April 21, 2026 1/1 Interos Named 2026 TPRM Service Provider Innovator; Aravo, Interos, and HITRUST Earn Excellence Awards Across Key Categories ANKENY, IOWA – 21 APRIL 2026 – The Third Party Risk Association (TPRA) today announced the winners of its 2026 Third Party Risk Management (TPRM) Service Provider Innovator Award and Excellence Awards during its annual in-person conference on April 21, 2026. Established to recognize and promote the critical role service providers play in advancing the TPRM industry, the TPRM Service Provider Innovator Award honors organizations that deliver innovative, efficient, and effective solutions to help practitioners assess, mitigate, and manage third party risk. “TPRM service providers are the backbone of our programs,” said Julie Gaiaschi, CEO of TPRA. “These organizations continue to push the boundaries of innovation while collaborating across the ecosystem to strengthen how risk is understood and managed. We are proud to recognize this year’s winners for their leadership and impact.” 2026 Award Winners TPRM Service Provider Innovator Award Interos was selected as the 2026 overall Innovator Award winner for its transformative approach to third party and supply chain risk management. Through its AI-powered platform, Interos delivers a unified, near real-time view across six critical risk domains, enabling organizations to move beyond fragmented data toward a single, actionable intelligence framework. Its breakthrough solutions— itariffs and itracing —provide predictive insights into tariff exposure, multi-tier supplier dependencies, and product-level disruption impacts, setting a new standard for proactive, intelligence-driven risk management. Excellence Award Winners GRC/TPRM Platform: Aravo Recognized for its innovations leveraging artificial intelligence to enhance multiple uses and views in the third party risk space, Aravo stood out for delivering advanced capabilities that improve visibility, efficiency, and decision-making for practitioners. Image: Dean Alms (right), Chief Product Officer for Aravo, accepts the Excellence Award on the organization's behalf from Julie Gaiaschi, CEO of TPRA, at TPRA's 2026 Conference on April 21, 2026. Risk Rating/Risk Intelligence Tool: Interos In addition to earning the overall Innovator Award, Interos was recognized in this category for its comprehensive risk intelligence capabilities, providing near real-time insights across a broad spectrum of risk domains along with actionable mitigation guidance. Image: Marty Clough (right), VP of Sales for Interos.ai, accepts Excellence Award on behalf of the organization from Julie Gaiaschi (left) during TPRA 2026 Conference on April 21, 2026. TPRM Services: HITRUST HITRUST was recognized for its standardization work that shifts the market from fragmented questionnaires toward a shared, defensible, and standardized assurance model that can be reused across vendor relationships. Image: Ryan Patrick (right), EVP, Customer Solution for HITRUST, accepts the Excellence Award on behalf of the organization from Julie Gaiaschi (left), CEO of TPRA, during the TPRA's 2026 Conference on April 21, 2026. Selection Process Nearly 40 TPRM service providers submitted applications across three categories: GRC/TPRM Platforms, Risk Rating/Risk Intelligence Tools, and TPRM Services. A panel of TPRA Officers, Board Members, and Practitioner Members representing diverse industries evaluated submissions based on innovation, collaboration, social responsibility, and overall impact on advancing the TPRM industry. Finalists underwent a multi-stage review process, including detailed scoring and live interviews, where judges assessed product capabilities, real-world applications, and contributions to the broader risk management community. ### The Third Party Risk Association (TPRA) is dedicated to advancing the practice of third party risk management by fostering collaboration, education, and innovation across the global TPRM community. Through its programs, events, and initiatives, TPRA supports practitioners and service providers in strengthening risk management practices and driving industry progress. MEDIA CONTACT Meghan Schrader Marketing & Communications Manager meghan.schrader@tprassociation.org www.tprassociation.org FOR MORE INFORMATION https://www.tprassociation.org/innovator-award Previous Next
- Women Lead | Franchesca Williams
Learn about Franchesca Williams, SVP, Director of Third Party Risk Management for Ameris Bank, and TPRA's WNTPRM July 2023 Leader Spotlight. < See All < Previous Next > Franchesca Williams SVP, Director of Third Party Risk Management Ameris Bank Biography Franchesca Williams is the SVP, Director of Third Party Risk Management at Ameris Bank and has 13+ years in the third party risk management field in financial services. Prior to her role at Ameris, Franchesca served as the Vice President of Third Party Risk Management at VyStar Credit Union in Jacksonville, FL. Franchesca is a detail oriented, analytical, and organized professional with an ability to adapt to change quickly, learn new concepts at a fast pace, and an ability to create solutions and overcome challenges presented. She currently holds the Certified Regulatory Vendor Program Manager IV (CRVPM IV) certification, Certified Third Party Risk Professional (CTPRP) certification, and a CCM Advanced Practitioner (CCMAP) certification. Leadership Characteristics Franchesca is always up for a challenge and completing work with accuracy. She focuses on taking the time to coach and mentor her team and colleagues in risk to help them be successful in managing identified risk within the organization. Leadership Challenges Franchesca has learned to be more flexible in her career as risk is about being in the gray at times and making a judgment call. She was not always flexible on her decisions or path in the past, but was blessed to have some great leaders and mentors that helped her see this as a strength and to open her mind to growing in this area. She has since grown to see the possibilities and paths forward as a result. This has led to her growth as a leader and helped her to succeed to further career growth. Key Take-a-ways Franchesca truly enjoys third party risk management because each day brings a new challenge to find a solution and to help identify ways to reduce or mitigate the risk that has been identified. “If one way does not work, forge forward and be open to creating a new way of doing things to accomplish your goals.” Fun Fact Franchesca enjoys spending time with her husband, 7-year-old son, and two Boston terriers in her free time. Some of her hobbies include crafting, gardening, cooking, and interior decorating/organizing. She is an advocate for Asian communities and culture in Jacksonville, FL where she serves on the Mayor's Asian American Advisory Board.
- TPRA Announces Launch of New Learning Management System for Certification and Certificate Programs | TPRA
FOR IMMEDIATE RELEASE TPRA Announces Launch of New Learning Management System for Certification and Certificate Programs Monday, November 17, 2025 TPRA's new training and examination site on the Inspire360 platform. TPRA's new training and examination site on the Inspire360 platform. 1/1 TPRA's new training and examination site on the Inspire360 platform. The Third Party Risk Association (TPRA) will be moving its professional training and certification platform to Inspire360 in January of 2026 ANKENY, IOWA — NOVEMBER 17, 2025 — The Third Party Risk Association (TPRA) is pleased to announce the upcoming launch of its new educational platform and Learning Management System (LMS) in January 2026 . This transition marks an exciting step forward in TPRA’s mission to enhance the learning experience for risk management professionals around the globe. The new LMS will offer a more engaging and streamlined experience , allowing registrants to easily navigate between trainings, exams, and certifications. Registrants will also be able to upload and track their continuing professional education (CPE) credits. With improved functionality and user-friendly design, TPRA aims to provide a centralized space where all education-related activities—from registration to completion—can be accessed with ease. “Our goal is to create a modern, intuitive learning environment that supports every stage of a registrant’s certification journey,” said Julie Gaiaschi, TPRA’s CEO & Co-Founder. “This upgrade reflects our commitment to continuous improvement and to meeting the evolving needs of our professional community.” Migration from Current System TPRA will suspend TPCRA registration on its website beginning on Wednesday, November 17 th, through December 31, 2025, to allow for the transition to the new platform. Those who have previously registered through the old system but are still in the process of completing TPCRA training and/or their examination will be automatically transferred to the new system and contacted by TPRA if additional information is needed. What to Expect Launch Date for the new Learning System: January 7, 2026 New Platform: Inspire 360 User Setup: On launch day, all current learners will receive an email from support+tpra@inspire360.com with the subject line “Update Your Account.” This one-time-use link will allow users to set their password and verify their account. Welcome Experience: After verification, users will receive a Welcome Email with step-by-step guidance on navigating the new system. Continuity of Learning: Learners who are already certified will see their certification in the new system. Those currently in the process of the TPCRA will complete their training and examination requirements in the current system. Support and Assistance Technical Support: support+tpra@inspire360.com Education Support: hilary.jewhurst@tprassociation.org TPRA will send additional communications leading up to the transition to ensure a smooth and seamless experience for all registrants. “We deeply appreciate the continued support of our members and learners,” added Julie Gaiaschi. “We’re excited to unveil the new features and capabilities this platform will offer as we continue to advance education in third party risk management.” About TPRA The Third Party Risk Association (TPRA) is a non-profit organization dedicated to advancing the profession of third party risk management (TPRM) through collaboration, education, and community engagement. TPRA supports practitioners and organizations around the world with resources, training, and networking opportunities that strengthen risk management programs and professional development. MEDIA CONTACT Meghan Schrader Marketing & Communications Manager Third Party Risk Association (TPRA) meghan.schrader@tprassociation.org https://www.tprassociation.org/ FOR MORE INFORMATION https://tpra.inspire360.com/ Previous Next
- Women In TPRM Meeting
LIVE WEBINAR Women In TPRM Meeting Tuesday, November 17, 2026 Date & Time Tuesday, November 17, 2026 at 1:00:00 PM CST Intended Audience All TPRM Professionals Duration 1 hr CPE Credits 0 Fee Free Register Event Description Join us for this empowering Women In TPRM (WnTPRM) Meeting . Discover the key to success in third-party risk management and be part of an inspiring virtual gathering. Embrace this opportunity to connect with influential women in the field, share insights, and build lasting connections. Journey to TPRM: TBD Show More SPEAKER(S) INFORMATION CPE CREDIT About These Meetings Join us for our monthly Women In TPRM (WNTPRM) meeting to hear from inspiring women about their "Journey to TPRM" as well as exciting program updates! Who Should Attend All TPRM professionals are invited to these events. This group is open to ANYONE, regardless of gender identity or TPRA membership status. Cancellations In the event that this session would need to be canceled, you will be contacted and invited to register for the rescheduled event. Questions & Concerns For more information regarding administrative policies such as complaints, please contact us at info@tprassociation.org . No CPE credits are provided for this event type.
- Women Lead | Madiha Fatima
Learn about Madiha Fatima, Director, Head of Third Party Risk Management for Angelo Gordon, and TPRA's WNTPRM March 2023 Leader Spotlight. < See All < Previous Next > Madiha Fatima Director, Head of Third Party Risk Management Angelo Gordon Biography Madiha Fatima is a Director and Head of Third Party Risk Management at Angelo Gordon, where she leads the development of Third Party Risk Management framework while enabling businesses to achieve their strategic objectives from utilizing service providers. Angelo Gordon is a leading global investment management firm headquartered in New York. Madiha oversees the firmwide Third Party Risk Management function including vendor cyber, technology, business continuity and data security assessments and governance. Madiha is a very well-known industry expert in risk management. She has been featured as Top 50 Women Leaders of New York as well as in Wall Street Journal and published in various magazines. Prior to joining Angelo Gordon, Madiha Fatima served as Head of Third Party Risk Governance & Oversight at DTCC. Madiha is a Certified Third Party Risk Professional (CTPRP). Madiha earned a Bachelor of Science in Financial and Capital Markets from Rutgers Business School. Leadership Characteristics D&I champion, Madiha launched various programs focused on women advancement in financial industry. She has been recognized and awarded the outstanding leadership award by Financial Industry awards hosted by DTCC and FICC. Leadership Challenges Madiha worked her whole career in a challenging environment showcasing her resilience by her continuous achievements throughout her career. She is one of the Top 20 youngest executives and rising stars of wall street. Key Take-a-ways "TPRM is one function where you have to be an expert in several different areas of risk management, strategy and operations to be successful. TPRM leaders are versatile and can provide effective leadership in many different areas due to their ability of being jack of all trades whether its cyber, regulatory, BCM or info sec, we challenge and do it all." Fun Fact "TPRM is the fun part about me; however, if I have to choose one thing outside my passion for TPRM, it would be cooking. I love cooking and find it very relaxing. I love trying different cuisines and from-scratch recipes."
- Third Party Risk Association (TPRA) Announces ‘Women In Third Party Risk Management’ Program | TPRA
FOR IMMEDIATE RELEASE Third Party Risk Association (TPRA) Announces ‘Women In Third Party Risk Management’ Program Monday, May 2, 2022 1/1 TPRA Announces Launch of Their Women in TPRM (WNTPRM) Program ANKENY, IOWA — 2 May 2022 — Today, the TPRA announced the official launch of their new ‘Women In TPRM’ Program. This program is dedicated to elevating women in the TPRM industry and promoting equal opportunities within the field. “As a women-led, not-for-profit organization whose mission it is to further the profession of third-party risk, the TPRA is dedicated to creating a diverse and inclusive space for the purpose of promoting, uplifting, and supporting women in the TPRM industry,” said Julie Gaiaschi, CEO and Co-founder at TPRA. According to GRC World Forums, women only represent 15-20% of the Governance, Risk and Compliance profession. Only about 25% of every 100 security and risk management (SRM) executives are women , Gartner Inc. noted in its 2019 article. After their preliminary announcement at their 2022 TPRM Conference, “The Art of Third Party Risk,” the TPRA received an influx of interest forms for the new program, highlighting the need for industry collaboration and discussion on this important topic. The program’s first meeting is set for May 24, 2022, from 1-2 p.m. Central Time and is open to all TPRA Practitioner and Vendor Members interested in becoming active participants in industry-wide change. About Women in TPRM The mission of ‘Women In TPRM’ is to uplift women within the TPRM industry, provide access to higher-paying jobs within TPRM, facilitate mentorships for women in TPRM, create a platform for women in TPRM to be recognized, celebrated, and supported, and cultivate the next generation of women leaders. Program participants will meet quarterly to discuss activities, as well as potential barriers, related to these goals, promote the importance of women in TPRM by creating educational materials for organizations, provide access to talks, tools, and techniques for uplifting and informing women in TPRM, highlight women leaders in TPRM, and promote TPRM job listings from organizations supporting and uplifting women. The program features a Resource Sharing Library, which contains a variety of women in business-related materials such as reports over the latest trends and statistics, blogs and articles on relevant and current happenings, and TED Talks featuring inspiring women in business; educating others on how to navigate the business world and find success in their careers. In addition, members are invited to join the TPRA ‘Women in TPRM’ Slack Forum channel to facilitate discussion in real-time. The program is open to all people whose mission it is to uplift women in TPRM, as diversity and representation are key to industry-wide change. Gartner Inc. notes that gender- diverse and inclusive teams outperform gender-homogeneous, less-inclusive teams by an average of 50%, in their 2019 article, highlighting the importance for inclusive and collaborative discussion on this challenge. The mission of the TPRA is to further the industry of TPRM through knowledge sharing and collaboration. As such, this group is specific to third party risk management. While Women In TPRM recognizes the missions of other women-related groups, the program will not be addressing topics outside of TPRM. To learn more about this program, submit an interest form and register for upcoming meetings, visit https:// www.tprassociation.org/women-in-tprm . ### Founded in 2019, Third Party Risk Association is a leader in TPRM industry best practices. The 501(c)(6) not-for-profit organization was created out of a necessity to build a community of like-minded third party risk professionals to allow for the sharing of best practices, exchanging of ideas, and influencing of an industry. MEDIA CONTACT Meghan Schrader Meghan.schrader@tprassociation.org www.tprassociation.org FOR MORE INFORMATION https://www.tprassociation.org/women-in-tprm Previous Next
- Women Lead | Oksana Zbyranyk
Learn about Oksana Zbyranyk, Chief Compliance and Delivery Officer for Truvo Cyber, and TPRA's WNTPRM October 2025 Leader Spotlight. < See All < Previous Next > Oksana Zbyranyk Chief Compliance and Delivery Officer Truvo Cyber Biography Oksana is a highly credentialed cybersecurity professional, specializing in compliance and risk management. Her expertise spans leading frameworks such as NIST, SOC 2, ISO 27001, and other, enabling organizations to meet complex compliance requirements and build trust with prospects and customers. A leader in Vendor Risk Management, Oksana successfully developed and implemented a robust Third-Party Risk Management (TPRM) program for the Bank of Canada, ensuring vendor risks were effectively assessed and mitigated. Her in-depth understanding of vendor security frameworks and contractual safeguards has empowered organizations to secure their vendor ecosystems while maintaining regulatory compliance. With her ability to integrate best practices, streamline compliance processes, and develop actionable strategies, Oksana is a trusted advisor for organizations seeking to enhance their security posture and meet compliance objectives. Leadership Characteristics Execution-Driven Leadership (Strengths: Achiever, Responsibility, Discipline): I am highly reliable, goal-oriented, and committed to delivering results. Relationship & Trust-Building Leadership (Strengths: Relator, Trust, Connectedness): As a trusted advisor, I build strong relationships with clients and stakeholders, ensuring compliance is not just a requirement but a value-driven process that fosters trust. This is key in vendor risk management, where collaboration and clear communication are critical. Problem-Solving & Risk Mitigation Leadership (Strengths: Restorative, Responsibility, Deliberative): My focus on risk assessment and mitigation aligns with leaders who analyze risks thoroughly, make careful decisions, and take ownership of challenges. I thrive in environments where critical thinking and sound judgment are essential. Leadership Challenges Getting business buy-in when a vendor’s security posture is weak is a constant challenge because security is rarely the top priority for stakeholders. The business wants the vendor now, procurement is focused on cost, and executives don’t see an immediate risk—until something goes wrong. The pushback is: “Do we really need to delay this over a security concern?” The key is to shift the conversation from abstract risks to real business impact—breach costs, regulatory fines (GDPR), and lost deals with security-conscious customers. A vendor without basic security controls isn't just a compliance issue; it’s a liability waiting to happen. Instead of a hard “no,” I push for risk-based onboarding—tying security improvements to timelines and contracts. Legal and compliance can help enforce this, and external pressure from clients expecting strong security can be a game-changer. At the end of the day, it’s about making security a business decision, not just a checkbox. Key Take-a-ways If there’s one thing I’d tell others in the industry about Third-Party Risk Management (TPRM), it’s that vendor security isn’t just a compliance exercise—it’s a business enabler. Too often, organizations treat TPRM as a checkbox process, but the reality is that a weak vendor can take down your entire business. The best part of TPRM for me is the "negotiation and influence"—turning security from an afterthought into a non-negotiable business priority. Whether it’s getting executives to see the real risk, pushing vendors to meet higher standards, or leveraging security as a competitive edge, TPRM is where cybersecurity meets strategy. Fun Fact I was born in a place where there was only winter. I studied in a place where there was only summer. And I landed in a place with 4 beautiful seasons. Canada is home.











