logo

CISO's open letter on third-party software risk is a call to action

ID: 3a906a72-2d3e-5553-ac0d-d46681fa593e

STIX ID: report--3a906a72-2d3e-5553-ac0d-d46681fa593e

Feed Name: ReversingLabs Blog

Date Published: 2025-05-29

Date Updated: 2026-04-29

Author: [email protected] (Jaikumar Vijayan)

...
...

This briefing outlines JPMorgan Chase CISO Pat Opet's warning that the ubiquity of SaaS creates concentrated, systemic risk due to overly permissive identity integrations, opaque third- and fourth-party dependencies, and rushed vendor practices; it catalogs recent supply-chain issues and misconfigurations and calls for stronger third-party software risk management (TPSRM). The piece advocates adopting SaaSBOMs (extended bills of materials) to inventory external services, improve visibility, enable risk scoring, and drive secure-by-default vendor behavior to mitigate SaaS-related exposures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.