Karen Gondoly on Vendor Privileged Access Emerges as a Growing Supply Chain Security Risk
In this interview, Leostream CEO Karen Gondoly warns that vendor privileged access management is fast becoming a critical blind spot in enterprise cybersecurity strategies. As organizations extend access to third-party suppliers and partners, attackers are increasingly exploiting excessive or poorly governed privileges to move laterally through supply chains. Gondoly argues that tightening controls and visibility around vendor access is now essential to reducing systemic risk across interconnected IT environments.
Transcript
Hey guys, thanks. The throw, we're here with Karen Oli, who's the CEO for Leo Stream, and we're having a little chat about, well, vendor privileged access management. It's a problem out there because we have so many people that we're trying to partner with, but we don't know exactly what they're doing once they get into our environments.
Karen, welcome to the show. Thank you very much, Mike. It's always a pleasure speaking with you.
Thanks for having me. This has been an issue for some time, but I feel like it's getting worse because the bad guys have kind of figured out how to attack our supply chains and they, they navigate and start to move laterally and all kinds of bad things happen. But, um, do we grant too much access to these other vendors out there and how often are we actually managing what they're doing on our networks and our systems?
Yeah, I think that's the problem is historically we have been, I don't wanna call it lax, but it is just simple to wrap vendors into the same systems that we use to manage access to our employees. So maybe that means, um, adding them into our VPN or whatever other remote access solution that we have, but the way that we manage employees but needs to be fundamentally different from how we manage vendors because these are outside people who we are giving carte blanche access to our network to, and that is just becoming, as you pointed out, more and more problematic over time. And we don't seem to know exactly what kind of defenses they have in place.
So for all we know, once we let them in our network, they've already been compromised. But how do I make some sort of assessment of what somebody's actual cybersecurity posture is, um, without just sending 'em a form and hoping that they, my scouts on are, tell me the truth. Well, that's the thing is, and, and I've gotten these as a vendor for some of the people that we work with, is they send us forms to say, what's your cybersecurity stance?
But even though we do have a good cybersecurity stance, you shouldn't trust me when I tell you that and I shouldn't trust you when you tell me that instead of relying on these forms and questionnaires, you need to put an actual plan and solution in place to essentially force them to adhere to what your cybersecurity policies are. So making sure that people ensure MFA when they're accessing your systems and enforcing that. A vendor can tell me they do that, but I need to make sure that they really are, and I do that by implementing services and solutions and my network that they have to use.
How much of this is also part of the human condition where we just get attached to other people and they work for other companies, but we kind of start to treat them like they work for us and the next thing you know, something bad happens. Yeah, there's definitely some of that. When you've worked with a vendor for a long time, it, it can become difficult to say, well, now I need you to use this different solution.
And I, I I am kind of telling you that I don't trust you. And it's not necessarily that I, I don't trust the vendor, it's just that people, people make mistakes. I may accidentally click on a phishing link and now if I have credentials for your systems and I've become compromised purely by accident, well that compromises you and you need to make sure that you're not, you're just protecting yourself from situations like that.
Mm-hmm. Of course, I would just tell people, well, I trust you, but Karen, she doesn't, so we haven't, I don't trust anybody. Not anymore.
Not these days, man. And well, to be honest though, you can't always be sure that somebody is who they say they are because there's now digital fakes and all kinds of interesting things that are going on out there. So even if somebody kind of looks and acts like somebody, you know, they might not be right.
That that is very true validation. You have to validate people's identity usually using more than one factor. It's, yeah, it's a scary world, Right?
And will it get worse with the rise of these AI agents because theoretically they are quote unquote digital employees that are now accessing things on behalf of my vendors and um, god knows what they're doing. Right. Yeah, no, that is a very interesting point.
And a good, a good thing for people to think about is, you know, we talk about managing vendors when it comes to third parties who we assume are people, but at some point in time, yes, you need to take those policies out and expand them to include these AI entities as well. So what am I supposed to do about all this? Because there are some legacy technologies out there, but I imagine they were created for a different era.
But is there another way of thinking about, you know, vendor privilege access management? There definitely is, and I think the, the key is to, again, not treat them like employees. Think of them as vendors.
You may like them, you may trust them, but you do do need to put different solutions in place that um, basically allow you to adhere to zero trust policies. So only give them access to the limited number of things that they really need instead of giving them a full VPN connection to your network. So use some sort of zero trust architecture that not only auth, authorizes them to trust the right resources, but also has a time bound policy associated with that so they can request access and you have to approve it, and that approval is for a certain period of time and when it expires, they can't come back in that way.
Even if they're compromised later, well their session has expired, it's enforced through the services that you're using to control their access. They can't get in anymore. So who's in charge of these kinds of issues?
Because I sometimes feel like, well, the cybersecurity people are generally aware of it, but they have no idea how many vendors they are and who's in charge of what. And then there's the business folks who, um, you know, they have a handle on how many vendors they're working with, but cybersecurity is never top of mind for them. So where does this fall in the, in in terms of who's responsible?
It really is kind of interdepartmental. 'cause I know I, you know, me as the CEO, I have a vendor spreadsheet. We know who our vendors are, but now I need to make sure I'm talking with it to say, okay, now you need to put policies in place and actually implement plans based on those policies that control the access that these different vendors have.
So it really is, again, cross department and communication as it is in many cases is, is the key there to make sure vendors don't fall through the cracks and policies get put into action. Mm-hmm. Do you think that the auditors and the regulators are starting to figure all this out and starting to ask tougher questions about this stuff?
Oh, I think that's definitely true. I think there's, there's more accountability now, so you need to not only, again, it's not just good enough to have the policy, you have to have the plan that backs it up and then implement that plan. And people are looking at that now too.
It used to be you could say, look, we have this policy, but now you have to prove that you're putting the policy in place. Do you think also that maybe we're getting to the point where, you know, companies will fire vendors for the lack of security controls and governance issues and this will become something that, you know, there'll be a little teeth in these evaluations? Oh, absolutely.
I mean, we even, we have cases where we've had to invoke our incident response plan because we've had a vendor who's done something that was, uh, not, we didn't have a, a hacking type incident, but it's still, you have to hold your vendors accountable and if they aren't resolving issues that they have and proving to you that they can be better than, then yeah, they're gonna be put on notice. We talked about AI being used by the bad guys, but it occurs to me that, well, maybe I can use AI to kind of evaluate the security of my vendors and make some assessments of that, because otherwise it's kind of a hard job to do and don't really have the time and capability. So will this get easier for folks to do maybe, hopefully, You know, that's an interesting question.
We're actually just starting to adopt AI into our business workflows and look for ways that we can implement it. So maybe I'll look at that one. Uh, think about how we can leverage AI to manage our vendors a little better.
Alright, I think, so what's your best advice to folks? Because honestly, I think some of them look at this and they go, I understand the issues, but it's a daunting task and it's so overwhelming that they just don't get started. Well, I think that's the key is to look at a little problem that you can solve and then expand from there.
So when we talk about vendor access, it's really about, okay, can I find a simple solution that'll make it easy for me? If I have a vendor who's doing maintenance on a couple operating systems or just needs to maintain my database or install some patches on a server, can I take this one little use case and make it very simple to secure that better than I am right now by finding some sort of vendor privilege access management solution? And so that, that's the key is just, you know, the world is big.
Can you find a little problem and start from there? And I think the, the concept of just securing third party access to a particular server or a particular application, that's a pretty small little problem to solve. And then you can kind of expand out, Is there an aren to this?
Because inevitably someone will complain about whatever security measures you put in there because they added friction to a process. But I mean, what is the tolerance for additional friction and how far can I go before everybody starts to rebel? Uh, I think that's gonna depend on the person.
Some people are so security focused that they're okay with a little friction, but some end users don't like any kind of change in any sort of experience that they have. So some of it's gonna be case by case, and then some of it's gonna be mandated by what your organization requires that people essentially put up with. But again, the key is to find that balance.
Can I find something that's simple enough for it to implement and simple enough for end users to use that if there's some friction in the fact that, you know, they have to do MFA now they're okay with it because otherwise it's, it's simplifying other aspects of their life. So ultimately, what's your best advice to folks? Then as you kind of think this through for a minute, um, you know, should I have a big meeting and convene everybody and kind of make it a giant corporate wide initiative?
Or you know, to your earlier point, do I just kind of like go after it one at a time until eventually I get my arms around it? Again, you've got the cross departmental, so there's somebody on top that's kind of thinking of it from the overarching, oh my God, here's everything we need to do standpoint. But when it comes to actually implementing the solution, yeah, narrow it down.
Find some simple use cases that you can tackle and then expand out from there. Because if you try, as they say, if you try to boil the ocean, you're not gonna get there. All right, well folks, you're heard in here, zero trust.
Even if you know them, it's a good idea because well, vendors change, people change. You don't know who's on the other side of that contract anyway, but eventually something probably is gonna go wrong. So better to be forewarned and forearmed then to suffer the consequences.
Karen, thanks for being on the show. Thank you very much. Thanks for having me.
All right. And back to you guys in the studio.