CISO's open letter on third-party software risk is a call to action
ID: 3a906a72-2d3e-5553-ac0d-d46681fa593e
STIX ID: report--3a906a72-2d3e-5553-ac0d-d46681fa593e
Feed Name: ReversingLabs Blog
Date Published: 2025-05-29
Date Updated: 2026-04-29
Author: [email protected] (Jaikumar Vijayan)
This briefing outlines JPMorgan Chase CISO Pat Opet's warning that the ubiquity of SaaS creates concentrated, systemic risk due to overly permissive identity integrations, opaque third- and fourth-party dependencies, and rushed vendor practices; it catalogs recent supply-chain issues and misconfigurations and calls for stronger third-party software risk management (TPSRM). The piece advocates adopting SaaSBOMs (extended bills of materials) to inventory external services, improve visibility, enable risk scoring, and drive secure-by-default vendor behavior to mitigate SaaS-related exposures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
