By: Lucy Pellegrino/Director of Marketing
Earlier this week, Proviniti joined Black Kite for Beyond the Firewall: Third-Party Risk in the Age of AI, continuing a conversation we’ve been having about how frontier AI is changing cybersecurity and what that means for organizations trying to manage risk across an increasingly complex third-party ecosystem.
It was a great discussion, and one of the things that struck me was how quickly the conversation moved beyond AI itself.
Yes, AI is accelerating vulnerability discovery. It’s introducing new risks through models and agents. And it’s changing what’s possible for both attackers and defenders. But many of the biggest questions raised during the session were really about something else:
How do organizations make better decisions when the volume and speed of risk keep increasing?
That brought the conversation back to some very practical issues: visibility, prioritization, governance, collaboration, and communicating cyber risk in terms the business can actually use.
Here are five takeaways I heard that I think are worth carrying forward.
One of the most compelling data points discussed during the webinar came from Black Kite’s research.
More than 48,000 cybersecurity flaws (CVEs) were published in 2025. Black Kite ultimately identified just 58 as genuine threats requiring a supply-chain response. That’s a pretty dramatic difference and it reinforces something security teams already know: more findings don’t automatically produce better security.
As AI makes vulnerability discovery faster and more scalable, the real challenge becomes determining what actually matters.
The goal can’t simply be to find more risk. It has to be to understand which risk requires action.
Another point that caught my attention was the discussion around how organizations define critical vendors.
Traditionally vendor criticality has been used to help determine where security and risk teams should focus their attention. That still matters, but a vendor doesn’t necessarily need to run a mission-critical business process to create meaningful exposure. A smaller SaaS provider, software dependency, or mid-sized vendor may have significant connectivity or access while operating with fewer cybersecurity resources than its enterprise customers.
That suggests a slightly different question: Instead of only asking “Which vendors are critical?” we also need to ask: “Where could a third party create meaningful exposure to the business?”
That means understanding connectivity, data access, dependencies, and potential impact, not just the vendor’s classification.
This may have been one of my favorite themes from the discussion. Questionnaires aren’t going away, and they still have a place in third-party due diligence. But a lengthy questionnaire completed once a year (or even several times a year) is still just a snapshot.
Risk doesn’t operate on an assessment schedule. A new vulnerability can emerge tomorrow. A vendor can introduce a new technology. An AI capability can be added. A fourth-party relationship can change. That’s why the shift toward continuous intelligence is so important.
Another aspect of this discussion that I thought was particularly interesting was how we engage the vendor. There’s a big difference between sending another questionnaire that essentially says: “Prove to us that you’re secure,” compared to approaching a vendor with actionable intelligence: “Here’s what we’re seeing. Here’s why it matters. How do we address it together?”
That changes the relationship from interrogation to collaboration and ultimately may produce a better security outcome for everyone involved.
We hear a lot about AI governance right now. But before you can govern AI, you have to know where it exists. Doing that is getting harder every day.
Organizations aren’t only dealing with AI they build themselves. AI is increasingly embedded in third-party applications. Vendors are deploying models and agents. Employees are connecting external AI services to enterprise workflows. SaaS providers are introducing new AI capabilities. That creates a visibility problem.
The phrase that came up during our broader discussion around this topic is simple, but I think it captures the challenge well: You can’t govern what you can’t see.
AI governance and third-party risk management are becoming much more closely connected.
This was another important takeaway for me. Security teams can produce enormous amounts of data including vulnerability counts, risk ratings, severity scores and vendor assessments, but ultimately, leadership has to make decisions.
Just telling a CFO that a vendor has a “critical” vulnerability doesn’t necessarily answer the question the business needs answered:
Translating technical cyber risk into business impact gives leadership something they can actually use to prioritize investments and make decisions.
The goal isn’t more security data. It’s better decision-making.
If I had to sum up the session in one thought, it would be this: The answer to more risk isn’t simply more information. It’s better intelligence about what matters. Getting to that point requires continuous visibility, context, intelligent prioritization, clear governance, and the ability to act quickly when something meaningful changes.
AI is going to continue accelerating both sides of cybersecurity. We aren’t going to slow that down. What organizations can control is how prepared they are to respond.
Ultimately the bigger opportunity might be: not trying to eliminate every possible risk, but getting much better at seeing what matters, understanding what it means to the business, and acting before risk becomes disruption.
If you weren’t able to join us live – or if you want to revisit the conversation – Beyond the Firewall: Third-Party Risk in the Age of AI is now available on demand.
Thank you to the Black Kite team, Jeffrey Wheatman, Johnathan (JB) Bald and Proviniti’s John Heuer for a great discussion and to everyone who joined us and brought questions to the conversation.