Alice in Supply Chains – Details, episodes & analysis
Podcast details
Technical and general information from the podcast's RSS feed.


Recent rankings
Latest chart positions across Apple Podcasts and Spotify rankings.
Apple Podcasts
🇩🇪 Germany - techNews
17/02/2026#98🇩🇪 Germany - techNews
16/02/2026#82🇩🇪 Germany - techNews
15/02/2026#69🇩🇪 Germany - techNews
14/02/2026#46🇺🇸 USA - techNews
26/04/2025#92🇺🇸 USA - techNews
25/04/2025#66
Spotify
No recent rankings available
Shared links between episodes and podcasts
Links found in episode descriptions and other podcasts that share them.
See allRSS feed quality and score
Technical evaluation of the podcast's RSS feed quality and structure.
See allScore global : 63%
Publication history
Monthly episode publishing history over the past years.
Bonus Episode - Special Guest Alex Pinto (DBIR)
Season 1 · Episode 5
mercredi 23 avril 2025 • Duration 01:02:31
Verizon’s 2025 Data Breach Investigations Report (DBIR) is out — and one of the top takeaways couldn’t be more clear: third-party risk is rapidly accelerating. This year, breaches involving third parties doubled compared to last year (from 15% to 30%), often driven by vulnerability exploitation and business disruptions. As the report puts it: when a vendor is hosting your data, the best strategy is to focus on how secure and resilient their environment truly is.
The DBIR also highlights a shift in how organizations are addressing third-party risk. While traditional risk questionnaires remain part of the equation, the report underscores a growing need for TPCRM solutions that deliver quantifiable, actionable insights — especially those that assess real-world security controls. At Tenchi, that’s exactly where we’re focused: helping organizations achieve continuous, cooperative, and comprehensive visibility into third-party cyber risk.
Tenchi CTO and Co-Founder, Alexandre Sieira, and Adrian Sanabria, Principal Researcher at the Defender's Initiative — both hosts of our Alice in Supply Chains podcast — had the great pleasure of speaking directly with Alex Pinto from Verizon Business, one of the key minds behind the DBIR, right as the report was released to the public.
Episode #4 | April, 2025
Season 1 · Episode 4
jeudi 17 avril 2025 • Duration 39:32
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter, that provides interesting discussions and expert insights on all things related to third-party cyber risk management (TPCRM).
It's hosted by two leading voices in the industry, Tenchi Security's CTO and Co-Founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
This episode is based on the content of newsletter issue #32, published on April 17, 2025. Check out the full material for more stories, links and details!
Themes discussed in this episode:
- Oracle breaches: from denial to lawsuit
- GitHub Action Hacked: Lessons Learned
Episode #3 | March, 2025
Season 1 · Episode 3
vendredi 21 mars 2025 • Duration 42:39
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's CTO & Co-founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanabria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
This episode is based on the content of newsletter issue #31, published on March 17th, 2025. Check out the full newsletter for more stories, links and details!
Here are the stories we discuss this month:
-Details on the Bybit Heist
-Surge in supply chain cyber attacks
-Ransomware trends and law enforcement success
-Exploiting abandoned resources in cloud storage
Episode #2 | February 2025
Season 1 · Episode 2
jeudi 20 février 2025 • Duration 34:20
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
This episode is based on the content of newsletter issue #30, published on February 19, 2025. Check out the full newsletter & subscribe for more stories, links and details!
Episode #1 | January 2025
Season 1 · Episode 1
mercredi 22 janvier 2025 • Duration 52:18
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
This episode is based on the content of newsletter issue #29, published on January 17, 2025. Check out the full newsletter for more stories, links and details!
Here are the six stories we discuss this month:
-Chinese hackers are deep inside America's telecoms -BeyondTrust incident hits US Treasury -Deloitte downplays breach affecting Rhode Island -US government to ban China Telecom and TP-Link -Are we overfocused on APTs? -76% of attacks in the mining industry linked to suppliers
Bonus episode with special guest Tony Martin-Vegue
Season 1 · Episode 14
mercredi 11 février 2026 • Duration 46:35
In this special interview episode, hosts Adrian Sanabria and Alexandre Sieira sit down with Tony Martin-Vegue, author of the upcoming book Heatmaps to Histadograms: A Practical Guide to Cyber Risk Quantification.
Tony shares his journey from IT and cryptography to becoming a leading voice in cyber risk quantification, including his six years building Netflix's risk quantification program from the ground up.
Tony Martin-Vegue brings over two decades of experience in IT and information security. With an economics degree that his mentor recognized as ideal for risk management, Tony has built cyber risk quantification programs at several large companies. Most recently, he spent six years at Netflix where he led approximately 3,000 FAIR-based risk assessments. He now runs his own consulting and advisory firm while promoting quantitative approaches to cyber risk.
Resources Mentioned in the Episode:
- The website for Tony’s book: https://www.heatmapstohistograms.com/
- Link to Solar Winds breach: https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach
- Link to Colonial Pipeline breach: https://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack
- The Scoville Scale: https://en.wikipedia.org/wiki/Scoville_scale
- How to use Monte Carlo simulations in Excel: https://support.microsoft.com/en-us/office/introduction-to-monte-carlo-simulation-in-excel-64c0ba99-752a-4fa8-bbd3-4450d8db16f1
- The FAIR Institute: https://www.fairinstitute.org/
- The FAIR Framework: https://www.fairinstitute.org/blog/integrating-fair-models-a-unified-framework-for-cyber-risk-management
- How to Lie with Statistics: Information Security Edition https://www.youtube.com/watch?v=p3jJnl99Lmc
- Cyentia’s IRIS Retina Report https://www.cyentia.com/services/iris-risk-retina/
- Verizon’s 2025 Data Breach Investigations Report: https://www.verizon.com/business/resources/reports/dbir
Episode #13 | January 2026
Season 1 · Episode 13
vendredi 30 janvier 2026 • Duration 57:50
Alice in Supply Chains is a monthly podcast by based on the Alice in Supply Chains newsletter - that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM).
It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanabria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
1. 2026 Outlook
- AI hits "put up or shut up" time—needs to prove enterprise value beyond demos
- Geopolitical fragmentation accelerating, impacting supply chain dependencies
- China signaling supply chain independence (banning US/Israeli security vendors, declining Nvidia H200s)
- Upcoming episode with Tony Martin-Vegue on cyber risk quantification
- RSA Conference: Tenchi hosting events at Harlan Records, Sun–Wed, during RSA week
2. Announcements
- Upcoming episode with Tony Martin-Vegue on cyber risk quantification
- RSA Conference: Tenchi hosting events at Harlan Records, Sun–Wed, during RSA week
3. Stories covered
Story 1: ENISA NIS2 Survey
Survey of 1,080 professionals across 27 EU countries on cybersecurity investments.
- Top investment driver: Regulatory compliance (70%), far ahead of proactive risk management (42%)
- Hardest to implement: Vulnerability management (#1), TPRM (#2)
- Supplier inventory: Under 10% of companies maintain one—current TPRM approaches don't scale
- Top 2026 concerns: Ransomware and supply chain attacks (~47%)
Story 1 Resources
- https://www.enisa.europa.eu/publications/nis-investments-2025
Story 2: SOC 2 Fraud Allegations
Social media discussions allege compliance platforms and auditors are rubber-stamping SOC 2 reports.
- Claims of nearly identical reports across different companies
- No AICPA enforcement—peer review doesn't verify actual control testing
- Post-breach cases (e.g., PowerSchool) reveal SOC 2s claiming controls that weren't implemented
- Takeaway: Don't over-trust SOC 2s for critical third parties; consider independent verification
Story 2 Resources
- https://www.linkedin.com/posts/troyjfine_details-have-emerged-regarding-a-widespread-activity-7415043499676483584-nI5Z
- https://www.linkedin.com/posts/sieira_details-have-emerged-regarding-a-widespread-activity-7415394996184424449-CSzO
- https://infosec.exchange/@AlexandreSieira/115865691003110478
Story 3: Japan & Korea Cybersecurity Regulations
Both countries responding to major 2025 breaches (Asahi, SK Telecom, KT, Coupang) with new rules.
- Mandatory breach reporting with government actively assisting incident response
- Korea: GDPR-style fines up to 3% of annual sales for repeat breaches
- Japan: Expanding cyber intelligence capabilities, reflecting reduced reliance on US protection
- TPRM angle: Public breach disclosure would enable better third-party "background checks" than self-reported questionnaires
Story 3 Resources
- https://www.centerforcybersecuritypolicy.org/insights-and-research/japans-new-active-cyber-defense-law-a-strategic-evolution-in-national-cybersecurity
- https://www.japantimes.co.jp/news/2025/12/23/japan/crime-legal/new-cybersecurity-strategy-police-sdf/
- https://www.koreatimes.co.kr/southkorea/20251212/science-minister-vows-punitive-fines-against-companies-with-repeated-security-breaches
Other Resources Mentioned
- The Alice in Supply Chains Newsletter https://www.linkedin.com/newsletters/alice-in-supply-chains-6976104448523677696/
- Episode 440 of the Enterprise Security Weekly podcast: why cybersecurity predictions are so bad https://youtu.be/qyn7F2NPCMs?si=P0bhGQtwwHXrnIhW
- Prior episode with AJ Yawn discussing how the SOC 2 sausage gets made https://www.tenchisecurity.com/en/alice-in-supply-chains/episode-7-hoxz2
- "The Security Products We Deserve" talk https://www.youtube.com/watch?v=GHuQC1qLnJ4
Stay safe and stay vigilant!
Episode #12 | December 2025
jeudi 18 décembre 2025 • Duration 01:03:12
Join Alexandre Sieira (CTO & Cofounder, Tenchi Security) and Adrian Sanabria (Principal Researcher, The Defender's Initiative) as they unpack the most relevant stories from our latest Alice in Supply Chains newsletter (issue #40) - and discuss what they mean for third-party cyber risk management.
Topics approached on the last podcast of 2025:
- Trends in Supply Chain Attacks in general, as observed through this year;
- The Risks of Ignoring Corporate Culture in Third-Party Due Diligence
- CISOs Are Losing Control of Their Security Outcomes
- Cyber Insurance
Episode #11 | November, 2025
Season 1 · Episode 11
mercredi 26 novembre 2025 • Duration 46:45
Join Alexandre Sieira (CTO & Cofounder, Tenchi Security) and Adrian Sanabria (Principal Researcher, The Defender's Initiative) as they unpack the most relevant stories from our latest Alice in Supply Chains newsletter (#39) - and discuss what they mean for third-party cyber risk management.
In this episode, the duo dive into:
Liability in the Age of AI: Who is truly accountable when AI "hallucinates" and causes reputational or financial damage?
The Fog of War in Breach Reporting: Why early breach disclosures are often highly inaccurate ?
The Cloud Availability Crisis: It’s not just AWS and Azure. We analyze the recurring, major outages impacting global infrastructure - and the critical dependencies putting your entire digital supply chain at risk.
Don't miss their expert discussion on navigating modern digital supply chain risks!
Episode #9 | September 2025
Season 1 · Episode 9
jeudi 25 septembre 2025 • Duration 01:04:03
In this episode, Alexandre Sieira (CTO & Cofounder of Tenchi Security) and Adrian Sanabria (Principal Researcher at The Defender's Initiative) celebrate the 3rd anniversary of the Alice in Supply Chains newsletter - the very starting point for this podcast. Together, they revisit key highlights from issue #37, unpacking the stories shaping today’s supply chain security landscape:
-The Salesloft “Perfect One Attack, Use Many” case-Vendors charging customers to complete security questionnaires-New CISA tools for supply chain security-The Sinqia compromise and the HSBC BRL theftStay tuned, every month, for in-depth insights, expert analysis, and key discussions on TPCRM challenges.









