Let’s Go Shopping: Third-Party Vendors and CyberRisk

Meghan Jacquot (Cybersecurity Engineer · Carnegie Mellon University's Software Engineering Institute), Rafael Ayala

BSides Las Vegas 2025 · Day 1

Overview

Rafael Lyala uses a grocery shopping metaphor to explain third-party risk management (TPRM) for mixed audiences: security professionals, coworkers, family, and friends. The talk explicitly warns security specialists it may feel “surface,” because the goal is transferable mental models rather than operational scoring formulas. The speaker defines TPRM simply as weighing return on investment against risk of impact, then maps grocery decisions onto criticality (impact), inherent risk (probability), and residual risk after controls.

Watch on YouTube

Visual summary for Let’s Go Shopping: Third-Party Vendors and CyberRisk by Meghan Jacquot, Rafael Ayala
Visual summary for Let’s Go Shopping: Third-Party Vendors and CyberRisk by Meghan Jacquot, Rafael Ayala

Key moments

  1. 2:00 Definition: third-party risk as ROI vs impact; need/want and duplicate-tool framing for buyers.
  2. 4:00 Heat-map prioritization: risk tolerance and regulations determine whether you assess only tail vendors or a broader set.
  3. 6:00 Deli counter exercise: cost, quality, illness risk; ambiguity of probability vs presence of store/regulatory controls.
  4. 8:00 Meat vs fruit: complexity and hidden defects change how people judge impact and likelihood.
  5. 10:00 Flowers + Valentine’s Day scenario: static risk ratings fail when context spikes impact.
  6. 12:00 2020 toilet paper lesson: supply disruption turns ‘low impact’ categories into felt crises.
  7. 16:00 Cyber pivot: HVAC as stealth criticality; Target 2014 vendor vector with $162M expenses cited.
  8. 18:00 CrowdStrike trust narrative: pre-2024 confidence vs post-2024 outage reframing of embedded third-party risk.

Let’s Go Shopping: Third-Party Vendors and CyberRisk

Speakers: Rafael Lyala (as introduced)

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=yfSGvvtmGeU

Overview

Rafael Lyala uses a grocery shopping metaphor to explain third-party risk management (TPRM) for mixed audiences: security professionals, coworkers, family, and friends. The talk explicitly warns security specialists it may feel “surface,” because the goal is transferable mental models rather than operational scoring formulas. The speaker defines TPRM simply as weighing return on investment against risk of impact, then maps grocery decisions onto criticality (impact), inherent risk (probability), and residual risk after controls.

Background

▶ Watch: Definition: third-party risk as ROI vs impact; need/want and duplicate-tool f... (2:00)

Lyala introduces himself with interdisciplinary credentials: undergraduate work in neuroscience and psychology, 15 years coaching wrestling and track, a master’s in philosophy, and prior work as a high school math teacher before entering cybersecurity—used to highlight BSides’ diverse paths.

He positions third-party risk as a resource allocation problem: organizations cannot assess every vendor equally; risk tolerance, regulatory obligations, and budgeted analyst time determine how deep assessments go. A generic heat-map graphic with 26 vendors is shown as a teaching aid (the speaker states it is not representative of any real dataset).

The grocery metaphor is doing deliberate cognitive work: most adults already perform informal risk assessment when feeding themselves or their families. Lyala’s claim is that this intuition is not irrational—it is compressed experience with controls, brands, regulation, and personal consequence. Third-party cyber risk fails in enterprises when that same intuition is never activated for software purchases, because the buyer sees a slick UI and a promise of productivity, not a dependency with availability, integrity, and data-processing implications.

Key Findings

▶ Watch: Deli counter exercise: cost, quality, illness risk; ambiguity of probability ... (6:00)

  1. Need vs want framing: Purchases (software, AI tools, groceries) should be evaluated as necessities versus desires, including whether duplicates already exist internally.
  1. Impact/probability intuition: In the deli example, impacts include cost, quality/taste, and health outcomes (foodborne illness); probability is ambiguous but mitigated by store policy and regulation, placing the example in a “moderate impact / lower probability” band in the talk’s informal matrix.
  1. Cleaning supplies / paper goods: Generally low impact if subpar; low probability of bad outcomes due to rotation and damage controls—used as a low-risk quadrant illustration.
  1. Raw meat: Higher perceived impact (food safety) and higher perceived probability due to more steps between purchase and consumption—highlighting process complexity as a risk amplifier.
  1. Fruit: Interesting split—people sometimes sample grapes in-store, interpreted as high confidence in safety; yet bagged fruit can hide one bad piece that spoils neighbors, showing how perceived impact and probability diverge by person.
  1. Flowers baseline vs Valentine’s Day: Normally low impact/low probability in-store; a holiday shortage flips impact (relationship/social consequences) and shows dynamic risk—risk is not static.
  1. Toilet paper / 2020: A reminder that supply chain disruption can transform a previously “low impact” category into a felt crisis without necessarily changing long-run probability estimates—used to argue TPRM must track context.
  1. Controls reduce residual risk: Examples include expiration dates, regulation, producer policies, store policies, and food-handler training for deli operations—framed as layered defenses analogous to organizational controls.
  1. Cyber case studies (publicly known):
  • Target (2014) breach via HVAC vendor vector; $162 million breach-related expenses cited by the speaker.
  • CrowdStrike used as a trust dynamics example: pre-2024 might look like a strong vendor in quadrant two; post-July 2024 outage reframes embeddedness and widespread impact once trust is shaken.
  1. Workplace translation questions: Ask whether a tool is needed, whether it duplicates existing capabilities, what organizational impact a failure causes, what probability looks like, and—controversially but deliberately—whether business owners are willing to own the residual risk mentally even if policy does not literally delegate it.

Technical Deep Dive

▶ Watch: Flowers + Valentine’s Day scenario: static risk ratings fail when context spi... (10:00)

This session is intentionally non-technical. It does not provide a scoring rubric, control frameworks, or TPRM workflow automation. Instead, it offers cognitive scaffolding:

  • Heat mapping as a prioritization lens: not every vendor warrants the same depth.
  • Dynamic risk: mergers, outages, geopolitics, and supply shocks move items across quadrants.
  • Hidden criticality: HVAC may look non-core until a third-party relationship becomes the attack path with major financial impact.

For practitioners seeking operational detail (e.g., how to weight threat vectors), the speaker directs those conversations outside the talk’s scope.

How to translate the metaphor into procurement conversations (without pretending it is a framework): When a business owner requests a new SaaS tool, ask the same triad the deli section uses: what is the worst plausible harm if the product is wrong (impact), how likely is a harmful failure mode given how the vendor touches your environment (probability), and what controls reduce the remaining risk (contracts, monitoring, backups, exit plans). The talk’s innovation is not the math; it is giving non-experts permission to think in those terms before the ticket hits IT.

Why “no single right answer” is a feature, not a bug: The fruit discussion highlights divergent personal risk tolerance—some people discard an entire bag for one bad orange; others accept the loss. Organizations exhibit the same split across business units. A security program that pretends there is one universal scoring function will keep fighting shadow IT; a program that documents explicit tolerance can route exceptions cleanly.

Demo / Proof of Concept

▶ Watch: 2020 toilet paper lesson: supply disruption turns ‘low impact’ categories int... (12:00)

The “demo” is a guided imaginary grocery trip with audience participation (deli, cleaning supplies, meat, fruit, flowers). No software or data analysis is shown.

Defensive Implications

▶ Watch: CrowdStrike trust narrative: pre-2024 confidence vs post-2024 outage reframin... (18:00)

  • Use plain-language analogies to onboard non-security stakeholders before introducing heavyweight questionnaires.
  • Teach teams to recognize process complexity and hidden dependencies as probability/impact drivers—especially for vendors touching network access or physical environments.
  • Treat vendor trust as time-varying: post-incident learning should update monitoring and contingency plans, not just contractual language.
  • When users lack experience, TPRM analysts should help translate “What data does this touch?” and “Does it reach crown jewels?” into scoping decisions (raised in Q&A).

Q&A highlights: A participant asks how to help employees who have no mental model of the tooling landscape (they heard a tool “solves it” from a friend). Lyala’s answer routes through data scope and crown jewels questions—essentially triage questions that do not require deep security literacy. Another question touches ISO 27001 / SOC 2 skepticism; Lyala responds that certifications can be a starting point but not an endpoint, deferring operational scoring detail. A third explores build vs buy as a resource question—aligned with the talk’s ROI framing.

Key Takeaways

  • Third-party risk is fundamentally resource-constrained prioritization, not “assess everything equally.”
  • Impact and probability are often ambiguous—controls exist precisely because intuition alone fails.
  • Context shifts (holidays, supply shocks, major incidents) can move “low risk” vendors into critical paths overnight.
  • Public breaches illustrate non-obvious criticality (HVAC) and concentration risk (widely deployed agents).
  • The grocery schema is a conversation starter for procurement, not a replacement for formal risk methodology.

Using the CrowdStrike example without turning it into tribal warfare: Lyala anticipates controversy. The point is not “vendor X is bad”; it is that trust and embeddedness change the shape of tail risk. A vendor can have strong engineering culture and still become a single point of failure by deployment pattern. That is a portfolio-management observation—relevant to concentration limits, rollback plans, and canary update strategies—rather than a verdict on any one company’s long-term quality.

Facilitation detail worth stealing for internal lunch-and-learns: Lyala repeatedly repeats audience answers for the recording, slows down when concepts get abstract, and invites disagreement (especially on fruit risk). If you reuse this material inside a company, copy that facilitation pattern: third-party risk discussions fail when they feel like a quiz with secret answers; they succeed when stakeholders can argue safely and then converge on what your organization will tolerate.

Regulation as a risk control, not just paperwork: The deli and meat sections emphasize food-handling training, expiration labels, and government oversight. Lyala explicitly names the tension security teams feel when business partners experience controls as slowdowns (“why are you slowing me down?”). The grocery analogy reframes those controls as the reason the baseline probability of acute harm stays low. Translating that to cyber: vendor questionnaires, SOC reviews, and contractual audit rights are unglamorous, but they exist to reduce residual risk when you cannot eliminate dependence.

Human impact beyond financial statements: Near the end, an audience member who worked at Target after the breach shares that the incident affected store employees emotionally even when their work seemed far from the technical root cause. Lyala acknowledges it. That moment matters because third-party risk discussions often flatten into dollars and downtime; the talk’s broader audience framing (family and friends) implicitly argues that organizational trauma is part of the true impact column—even if it rarely appears on a heat map.

About the Speaker(s)

Rafael Lyala presents the talk as personal views not representing his employer. Biographical details are as stated in the transcript (neuroscience/psychology undergrad, coaching experience, philosophy graduate degree, former high school math teacher). Employer name and current role details are not specified in the transcript beyond the disclaimer.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Well-intentioned accessibility talk for non-specialists, but thin for a technical BSides track. The grocery metaphor is memorable; the cyber section is mostly headline history without new analysis or defender mechanics.

Heather Calloway (CISO) — STRONG ACCEPT

This is executive education done right for a security-adjacent audience: it teaches prioritization under ambiguity and makes third-party dependence tangible without drowning newcomers in frameworks.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025