Explore every episode of the podcast Alice in Supply Chains
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Bonus Episode - Special Guest Alex Pinto (DBIR) | 23 Apr 2025 | 01:02:31 | |
Verizon’s 2025 Data Breach Investigations Report (DBIR) is out — and one of the top takeaways couldn’t be more clear: third-party risk is rapidly accelerating. This year, breaches involving third parties doubled compared to last year (from 15% to 30%), often driven by vulnerability exploitation and business disruptions. As the report puts it: when a vendor is hosting your data, the best strategy is to focus on how secure and resilient their environment truly is. The DBIR also highlights a shift in how organizations are addressing third-party risk. While traditional risk questionnaires remain part of the equation, the report underscores a growing need for TPCRM solutions that deliver quantifiable, actionable insights — especially those that assess real-world security controls. At Tenchi, that’s exactly where we’re focused: helping organizations achieve continuous, cooperative, and comprehensive visibility into third-party cyber risk. Tenchi CTO and Co-Founder, Alexandre Sieira, and Adrian Sanabria, Principal Researcher at the Defender's Initiative — both hosts of our Alice in Supply Chains podcast — had the great pleasure of speaking directly with Alex Pinto from Verizon Business, one of the key minds behind the DBIR, right as the report was released to the public. | |||
| Episode #4 | April, 2025 | 17 Apr 2025 | 00:39:32 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter, that provides interesting discussions and expert insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's CTO and Co-Founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of newsletter issue #32, published on April 17, 2025. Check out the full material for more stories, links and details! Themes discussed in this episode: - Oracle breaches: from denial to lawsuit - GitHub Action Hacked: Lessons Learned | |||
| Episode #3 | March, 2025 | 21 Mar 2025 | 00:42:39 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's CTO & Co-founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanabria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of newsletter issue #31, published on March 17th, 2025. Check out the full newsletter for more stories, links and details! Here are the stories we discuss this month: -Details on the Bybit Heist -Surge in supply chain cyber attacks -Ransomware trends and law enforcement success -Exploiting abandoned resources in cloud storage | |||
| Episode #2 | February 2025 | 20 Feb 2025 | 00:34:20 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.
| |||
| Episode #1 | January 2025 | 22 Jan 2025 | 00:52:18 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of newsletter issue #29, published on January 17, 2025. Check out the full newsletter for more stories, links and details! Here are the six stories we discuss this month: -Chinese hackers are deep inside America's telecoms -BeyondTrust incident hits US Treasury -Deloitte downplays breach affecting Rhode Island -US government to ban China Telecom and TP-Link -Are we overfocused on APTs? -76% of attacks in the mining industry linked to suppliers | |||
| Bonus episode with special guest Tony Martin-Vegue | 11 Feb 2026 | 00:46:35 | |
In this special interview episode, hosts Adrian Sanabria and Alexandre Sieira sit down with Tony Martin-Vegue, author of the upcoming book Heatmaps to Histadograms: A Practical Guide to Cyber Risk Quantification. Tony shares his journey from IT and cryptography to becoming a leading voice in cyber risk quantification, including his six years building Netflix's risk quantification program from the ground up.
| |||
| Episode #13 | January 2026 | 30 Jan 2026 | 00:57:50 | |
Alice in Supply Chains is a monthly podcast by based on the Alice in Supply Chains newsletter - that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanabria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. 1. 2026 Outlook
2. Announcements
3. Stories covered Story 1: ENISA NIS2 Survey
Story 1 Resources
Story 2: SOC 2 Fraud Allegations
Story 2 Resources
Story 3: Japan & Korea Cybersecurity Regulations
Story 3 Resources
Other Resources Mentioned
Stay safe and stay vigilant! | |||
| Episode #12 | December 2025 | 18 Dec 2025 | 01:03:12 | |
Join Alexandre Sieira (CTO & Cofounder, Tenchi Security) and Adrian Sanabria (Principal Researcher, The Defender's Initiative) as they unpack the most relevant stories from our latest Alice in Supply Chains newsletter (issue #40) - and discuss what they mean for third-party cyber risk management. Topics approached on the last podcast of 2025: - Trends in Supply Chain Attacks in general, as observed through this year; - The Risks of Ignoring Corporate Culture in Third-Party Due Diligence - CISOs Are Losing Control of Their Security Outcomes - Cyber Insurance | |||
| Episode #11 | November, 2025 | 26 Nov 2025 | 00:46:45 | |
Join Alexandre Sieira (CTO & Cofounder, Tenchi Security) and Adrian Sanabria (Principal Researcher, The Defender's Initiative) as they unpack the most relevant stories from our latest Alice in Supply Chains newsletter (#39) - and discuss what they mean for third-party cyber risk management. In this episode, the duo dive into:
Don't miss their expert discussion on navigating modern digital supply chain risks! | |||
| Episode #9 | September 2025 | 25 Sep 2025 | 01:04:03 | |
In this episode, Alexandre Sieira (CTO & Cofounder of Tenchi Security) and Adrian Sanabria (Principal Researcher at The Defender's Initiative) celebrate the 3rd anniversary of the Alice in Supply Chains newsletter - the very starting point for this podcast. Together, they revisit key highlights from issue #37, unpacking the stories shaping today’s supply chain security landscape: -The Salesloft “Perfect One Attack, Use Many” case-Vendors charging customers to complete security questionnaires-New CISA tools for supply chain security-The Sinqia compromise and the HSBC BRL theftStay tuned, every month, for in-depth insights, expert analysis, and key discussions on TPCRM challenges. | |||
| Episode #8 | August, 2025 | 29 Aug 2025 | 00:58:47 | |
Alice in Supply Chains is a monthly podcast inspired by the Alice in Supply Chains newsletter, delivering sharp discussions and insights on all things related to third-party cyber risk management (TPCRM). Hosted by two of the industry’s leading voices - Alexandre Sieira, Co-founder & CTO of Tenchi Security, and Adrian Sanabria, Principal Researcher at The Defender’s Initiative - the show offers expert analysis and practical takeaways to help you navigate today’s complex cybersecurity landscape. In this episode, they dive into three standout stories from issue #36 of the newsletter of the same name, Alice in Supply Chains:
| |||
| Episode #7 | July, 2025 | 28 Jul 2025 | 00:51:39 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter that provides interesting discussions and expert insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Alexandre Sieira, Tenchi Security's CTO and Co-Founder & The Defender's Initiative Principal Researcher, Adrian Sanabria - and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of issue #35 of the newsletter and covers: - Prolific cybercriminal group now targeting aviation and transportation Companies - Patient's death linked to cyber attack on NHS, hospital trust says - Cyberattack on Brazil tech provider affects reserve accounts of some financial institutions; | |||
| The Limitations of SOC 2 with AJ Yawn (bonus episode) | 14 Jul 2025 | 00:51:13 | |
We’re thrilled to announce a special bonus episode of the Alice in Supply Chains podcast featuring an insightful conversation you won’t want to miss. In this episode, Alexandre Sieira, CTO and Co-founder of Tenchi Security, and Adrian Sanabria, Principal Researcher at the Defender's Initiative, sit down with AJ Yawn - Director of GRC Engineering at Aquia, author of GRC Engineering for AWS, and host of CyberTakes. Together, they take a deep dive into SOC 2 and its fate - exploring challenges, limitations, why it’s become so popular - and what the future holds. It’s a timely and important discussion for anyone interested in cyber risk management. | |||
| Episode #6 | June, 2025 | 16 Jun 2025 | 00:49:35 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter, that provides interesting discussions and expert insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's CTO and Co-Founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of issue #34 of the newsletter of the same name, and covers: - Cyber attack on Rhode Island's benefit system - Retail attacks in the UK and the US - How to incentivize security by design | |||
| Episode #5 | May, 2025 | 16 May 2025 | 01:01:41 | |
Alice in Supply Chains is a monthly podcast by Tenchi Security based on the Alice in Supply Chains newsletter, that provides interesting discussions and expert insights on all things related to third-party cyber risk management (TPCRM). It's hosted by two leading voices in the industry, Tenchi Security's CTO and Co-Founder Alexandre Sieira & The Defender's Initiative Principal Researcher, Adrian Sanaria, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape. This episode is based on the content of issue #33, published on May 16th, 2025, and covers the following stories: - EU businesses looking to ditch US Cloud Companies - Insights from the UK ICO Investigation into the 2022 NHS Breach - The great Hanoi rat massacre and modern risk practices - JPMorgan's CISO open letter: a call to action | |||