Why TPRM Demands a Structured Approach

▶ Watch (01:25)

Regulations now require vendors to meet the same security baseline as the companies that hire them. SolarWinds, NotPetya, and MOVEit showed what happens when they don’t. Ad-hoc oversight breaks under that pressure. Companies with hundreds of suppliers cannot staff enough analysts to assess every one with equal depth, so without a tiered framework, assessments pile up or get skipped.

The fix is prioritization before assessment. Map each vendor to the business process it supports. If that process is outsourced and critical to continuity or revenue, it earns a high-risk assessment. Everything else fits a lighter tier. That classification decision drives every tool choice and resource allocation downstream.

People, Process, and Technology as the Continuous Monitoring Foundation

▶ Watch (02:46)

Every TPRM program rests on the same three pillars: people, process, and technology. Without a strategy tying them together, they work against each other. People get checked through training and awareness programs. Processes and technology require automated checks, log management, vulnerability scanning, and contract-linked controls. A gap in any pillar can cost a company its reputation or its compliance standing.

Mastercard maps each vendor to the macro business processes it supports, then assigns a risk tier. Larger vendor pools make that triage unavoidable. “Risk prioritization is key in this situation,” Miracca said. A core process outsourced to a single supplier earns a high-risk assessment. A peripheral service goes through a lighter, tool-driven pass. That tiering is what keeps the program from becoming a manual burden at scale.

Assessing Low- and Medium-Risk Vendors with Automated Tooling

▶ Watch (08:56)

For low-risk vendors, RiskRecon scans internet-exposed systems across nine domains, patching, encryption, network filtering, past breaches, and more, cross-checks against Shodan, and returns a 0-to-10 score without touching the vendor’s network.

Medium-risk vendors get two more tools. CyberQuant maps questionnaire answers against a Mastercard-customized FAIR ontology and converts them into a euro loss figure for specific crisis scenarios. That number lets the team talk to top management. CyberFront then runs hundreds to thousands of attacks from a library of over 1,000 techniques against the vendor’s environment and compares results against the questionnaire.

“people have bias on their own companies.” — Alessandro Miracca

High-Risk Assessment: Integrating Cyber, Financial, and Geopolitical Risk

▶ Watch (17:04)

For critical suppliers, cyber risk alone is not enough. Mastercard’s Systemic Risk Assessment (SRA) platform pulls threat intelligence from the clear web, dark web, and deep web, then layers in Bloomberg financial data, weather forecasts, and geopolitical news feeds. A data center sitting in an earthquake zone affects the catastrophic risk score. Active conflicts or pending legislation in a supplier’s home country affect the geopolitical score.

“Having an holistic approach in evaluating third party is something key” — Alessandro Miracca

The result is a single view that covers cyber, financial, and catastrophic exposure together. Mastercard applies this to vendors ranging from Fortune 500 firms down to small and medium businesses.

Operationalizing the Framework and the Road Ahead

▶ Watch (22:29)

Procurement, legal, and security all sit at the same table. Advisory connects them. When a vendor falls short on a security clause, the advisory team flags it before contract renewal and legal adds an appendix. RiskRecon gives procurement a benchmark module to screen RFP candidates before invitations go out, so human effort stays on the decisions that matter.

The roadmap points toward contract-linked scoring through Stik, a generative AI platform Mastercard trained on its own templates. The idea: feed vendor contracts directly to the engine, extract financial clauses automatically, and track risk through the full lifecycle. Client authorization on sensitive contract data has blocked the release so far. Until then, those checks stay manual.

Q&A

How do you integrate the cyber TPRM piece into the overall TPRM process, given that organizations often treat the cyber part as a separate silo? Mastercard breaks the silo by giving procurement teams direct access to RiskRecon (including its benchmark modules for RFP shortlisting), while a dedicated cyber advisory team connects tool outputs to legal, procurement, and executive stakeholders so that contract renewals, security-clause updates, and remediation decisions move through one coordinated process. ▶ 21:33

When you do vendor testing, is it in UAT environments or do you get consent to target real production systems? Neither RiskRecon nor CyberFront runs real penetration tests: RiskRecon does passive outside-in reconnaissance (port scanning, exposed-service enumeration), while CyberFront is a breach-and-attack simulation platform that places an agent-equipped VM inside the vendor’s own network and fires simulated kill-chain traffic over HTTP, HTTPS, FTP, and email to measure whether the vendor’s firewall, EDR, SIEM, and sandboxing controls catch the payloads. ▶ 25:01

Is there a way to automatically track a vendor’s risk score throughout the full contract lifecycle rather than only at renewal? Continuous contract-linked risk scoring is the acknowledged next step, targeted for delivery by end of 2026, with Mastercard working to use its generative-AI partnership with Yстick to parse non-standard contract clauses at scale and feed incident outcomes back into the cyber risk score, but the capability does not exist yet. ▶ 38:02

Notable Quotes

risk prioritization is key in this situation. Alessandro Miracca · ▶ 7:10

people have bias on their own companies. Alessandro Miracca · ▶ 15:20

Having an holistic approach in evaluating third party is something key Alessandro Miracca · ▶ 19:43

Key Takeaways

  • Classify every supplier by business-criticality before assessment — risk prioritization is the prerequisite to efficient TPRM.
  • Cross-validate self-reported questionnaires with outside-in scanning and breach-and-attack simulation to expose the gap between claimed and actual posture.
  • For critical vendors, cyber risk alone is insufficient — fold in financial, geopolitical, and catastrophic signals to assess true resilience.

About the Speaker

Alessandro Miracca

Alessandro has worked continuously in strategic consulting, dealing with many Cyber Security-related topics such as risk quantification and risk management, response to malicious events, compliance with regulatory requirements imposed by Italian and international regulatory bodies and the definition of key processes in the field of IT and Cyber Security from 2014 to 2024. During this period, his professional experience led him to tackle complex projects in Italy, Europe and some countries in North Africa and the Middle East. Although most of the clients he supported were from the Financial Services industry, Alessandro is able to assist organizations from other sectors thanks to his successful work with pharmaceutical companies, energy companies, and government institutions. In September 2024, he took on the role of Director of Cybersecurity & Risk at Mastercard, with responsibility for the provisioning of cyber security services to Mastercard clients across Europe. Alessandro holds an ISO/IEC 27001 Foundation qualification, as well as professional certifications as a Certified Ethical Hacker (CEH) and Certificate of Cloud Security Knowledge (CCSK). He took his Master’s degrees in Engineering of Computing Systems at Politecnico di Milano. He is also a licensed engineer, with professional certification issued by Italian authorities.