Ep 112 ·
The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Topic
Governance, risk and compliance that enables the business — maturity models, third-party risk management and making audits a by-product.
62 episodes · 12 questions answered
How much effort can AI save in a third-party risk assessment?
Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.
Matthew Moog · EY
What is Project Glasswing and why should security leaders care?
Project Glasswing gives a select group, largely large banks, access to Anthropic's Mythos model; consulting firms like EY see it only through client projects and working groups. Moog says what makes Mythos different is that it stacks vulnerabilities, combining ones that are insignificant on their own into a much bigger one. He warns that organizations rushing to adopt agents need controls and an understanding of these new risks, which takes people who are deeply technical and understand the business context.
Matthew Moog · EY
Why is AI ethics a board-level issue?
Moog sees the ethical questions inside third-party risk as small next to the broader board discussion of AI ethics. Agents are given judgment and access that mirror an employee, and they have tunneled outside firewalls and interacted in ways no one expected, so the real dilemma is where to say no. He also treats workforce impact as an ethical choice, raising options such as working 20% less for 20% less pay instead of cutting 20% of staff.
Matthew Moog · EY
Will AI replace third-party risk questionnaires and assessments?
Not entirely. Moog compares it to a modern car full of sensors that still gets a 160-point inspection before resale: an assessment remains the best way to understand a new third party's controls and is still worth doing every year for critical ones. Because mature assessments rarely change year to year, he expects more time to go to continuous signals and to running third-party risk almost like a mini SOC.
Matthew Moog · EY
How does AI change security in the software development lifecycle?
Moog says AI coding models are very good at checking their own code for vulnerabilities, so scanning will be built in by default whether code is written by humans or agents, although the models still struggle with user personas, access and non-linear workflows. He expects constant scanning of code bases and external perimeters, and says patching what is found will have to be automated in many cases because that would be very difficult with a human-based labor force.
Matthew Moog · EY
Will AI reduce the size of security teams?
Moog does not expect a fully autonomous security organization in the next 10 years outside some very small startups, because agents cannot yet think critically through chaos the way a SOC analyst does when deciding whether to cut off an anomaly. He sees demand for more security professionals, especially those with a deep technical understanding of their architecture, their tools and where AI fits in, including through third parties.
Matthew Moog · EY
Should security and compliance be treated as separate priorities?
Andy says security and effective compliance shouldn't be at odds. He defines compliance broadly, covering external requirements such as regulations and contracts and internal obligations such as policies and controls, and argues that good compliance mandates describe what must be done, not how. Clear, traceable compliance requirements then become inputs to the security roadmap and can be prioritized like any other requirements.
Winthrop (Andy) Welch
What is the biggest hurdle to aligning security strategy with the business?
According to Andy, it is gaining persistent, regular access to the right people on the business side, so you understand their motivators and where the business is headed. Security has to offer those stakeholders value and keep the dialogue open and refreshed, and he thinks many organizations don't spend enough time keeping that alignment steady.
Winthrop (Andy) Welch
How mature is GRC in most enterprises?
Andy sees GRC maturity as pretty low in many organizations, where GRC is treated as the assessments team that arrives after development with a checklist and a list of problems. That makes it a source of noise and friction, and it quickly gets marginalized. The shift comes when GRC moves upstream, embeds in development and operations, learns their workflows and helps teams make security decisions as they are being made.
Winthrop (Andy) Welch
How should you structure a GRC team?
Andy starts with clarity: when he built out the GRC program at Yahoo, he defined its vision, scope and value proposition and tied everything back to them. Rather than splitting teams into governance, risk and compliance, he splits them by internal focus (policies, control standards, risk oversight, internal compliance) and external focus (regulatory engagement, third-party risk, M&A contracts, customer and partner assurance). He finds this aligns better with how businesses are structured and builds more natural relationships with stakeholders.
Winthrop (Andy) Welch
How do you fix security tool sprawl?
Andy sees tool sprawl as a symptom of never having a cohesive security architecture or long-term plan, with tools picked reactively for each problem, leading to overlap, integration gaps and bloated cost. The fix is strategic: step back, map out your future state architecture and build a reasonable roadmap to get there. It takes time and coordination across teams, but the payoff is a leaner, more effective and more affordable program.
Winthrop (Andy) Welch
When should security get involved in M&A deals?
Andy says security has to be part of the deal from the deal thesis through diligence to execution, not bolted on at the end. He describes a deal that collapsed because the deal team didn't engage IT or security until after close, and the acquired software's architecture proved too expensive to integrate. Once his team started adding insight to deal teams, those teams began inviting them in, which he treats as the sign of success.
Winthrop (Andy) Welch
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.
Sana Talwar on product security at scale, reducing friction for developers, and defending AI integrations in the enterprise.
Ammar Ekbote, Cloud Security Engineer at Pinterest, on eBPF, MCP server adoption, and kernel-level AI security monitoring.
James Cash on zero trust, AI-driven threats, human risk, and future-proofing organisational security programmes.
Ashish Garg on proactive security leadership, analysing business risk impact, and cross-team alignment on security roadmaps.
Ep 95 ·
Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.
Patricia Titus on the future CISO, AI and quantum security challenges, and becoming a multidisciplinary security strategist.
Stephen Kuenzli on IAM, AI-driven cloud security, and using agents and MCPs to improve security decision-making at scale.
Joseph Haske on cybersecurity risk management, stakeholder communication, and qualitative-vs-quantitative frameworks.
Lalit Kumar on building good and lasting cloud security, transforming AWS India Security, and advising CXOs on cloud posture.
Rowan Udell on AWS IAM best practices for production environments, least-privilege strategies, and role-based access patterns.
Anshuman Bhartiya on product security, risk-driven prioritisation, and building secure-by-default development practices.
Reanna Schultz, founder of CyberSpeak Labs, on modern threat detection, false-positive handling, and staying ahead of threats.
Perry Carpenter on the human element in security, AI-powered deepfakes, and the evolving social-engineering threat landscape.
Mauricio Duarte on building resilient security culture, behaviour-based awareness programmes, and incident-response speed vs accuracy.
Ross Young on the CISO's dilemma — balancing security, innovation, and burnout — and building cross-functional champions.
Apoorvaa Deshpande, Senior Privacy Engineer at Google Cloud, on privacy engineering, privacy by design, and GenAI data governance.
Richard Stiennon on the ultimate guide to cloud security, the evolving threat landscape, and building defence in depth.
Cloud incident response with Hilal Ahmad — monitoring MTTD and MTTR, and why out-of-the-box security tools are never enough.
Gretchen Ruck on rethinking cybersecurity frameworks, addressing inherent risk, and measuring security effectiveness.
John Giglio on demystifying IAM, the security-vs-compliance debate, and data-perimeter controls for read, write, and download.
Cassie Clark on the intersection of security and human behaviour, choice architecture, and continuous awareness programmes.
Sandeep Agarwal on trust and security as the cornerstones of organisational resilience, leadership alignment, and building durable programmes.
Jan Hertsens, Senior Security Consultant at AWS, on continuous security, the compliance debate, and incident-response segmentation.
Tom Adamski on network segmentation, risk assessment before design, and layering AWS security tools for defence in depth.
Kailash Havildar on logging, monitoring, and detective controls in cloud security — what to capture and how to act on it.
Matthew Marji on building cybersecurity teams, evaluating communication skills in hiring, and aligning security with business.
Amit Subhanje on enterprise risk management, balancing proactive and reactive strategies, and shared security responsibility.
Jesse Miller on building cybersecurity teams, creating a virtuous cycle with clients, and taking a risk-centric approach.
Htet Naing Aung on supply-chain security, container-image signing, SBOMs, and using SCA tools in CI/CD pipelines.
Jim Manico on safeguarding applications in the AI era, verifying AI-generated code, and applying OWASP best practices on top of frameworks.
Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, on third-party risk management, vendor prioritisation, and procurement decisions.
Shivani Arni, CISO at TransUnion CIBIL, on emotional intelligence in security leadership and third-party risk management.
Chad Lorenc, Security Practice Manager at AWS, on cloud IAM beyond access control, showing value to leadership, and production-account security.
Yotam Perkal on vulnerability management, supply-chain security, SBOMs, and prioritising the risks that matter most.
Kesten Broughton on asset management, Kubernetes in the cloud, and why visibility is the foundation of cloud security.
Divyanshu Shukla on practical strategies for defending Kubernetes clusters, detection techniques, and open-source defence tools.
Steve Giguere on Kubernetes security, when monoliths beat containers, and vetting open-source dependencies with SBOMs.
Dustin Lehr on application security, threat modelling, and building security-champion programmes through long-term relationships.
Chris Hodson, CSO of Cyberhaven, on threat modelling across the SDLC, communicating security value, and DevSecOps trade-offs.
Walter Haydock on vulnerability management, prioritisation strategies, and building a vulnerability programme that scales.
Karan Dwivedi on blue-team operations, partnering with red teams, and preserving forensic data accuracy.
Alyssa Ahmann on GRC setup, data privacy, and why documentation and training underpin successful security programmes.
Paul Dyer on red, blue, and purple team operations, threat-landscape awareness, and open-source security with SBOMs.
Jim Bugwadia on Kubernetes governance, workload security responsibilities, and image-signing best practices with Sigstore.
Adam Smith on data privacy governance, building personal-data inventories, and fostering a privacy-first culture.
Syed Shareef, Senior Security Engineer at AWS, on data perimeters, combining SCP and IAM policies, and use-case-driven security.
Ray Espinoza on cloud vulnerability management, leading with empathy, and transparent communication during incidents.
Garrett Smiley on measuring security debt, context-driven risk prioritisation, and using KRIs over KPIs for security teams.
Trupti Shiralkar on organisational security culture, joint backlog reviews for security debt, and supply-chain security standards.
Charles Mendoza on setting the line of defence in cloud security, layered controls, and incident-response readiness.
Aakash Yadav on security debt, risk prioritisation, and building a pragmatic approach to reducing organisational risk.
Parul Khanna on information security, risk management, and bridging the gap between incident response and business priorities.
Mel Reyes on the biggest mistakes in cybersecurity, top-down security mandates, and setting up foundations for startups.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture and overcoming organisational resistance.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture, programme design, and security planning.
Nat Shere on preparing for cloud data breaches, incident response planning, and lowering MTTD and MTTR.
Ski on building a security-centric culture, improving cross-team relationships, and aligning certifications with controls.
Gaurav Batra, founder and CEO of CyberFrat, on surprising cloud security facts and building security awareness culture.
Swati Anuj Arya, CISO Office leader at Amazon Pay, on simplifying cloud security and responding to data breaches.
Aseem Rastogi, Head of Cybersecurity and Compliance at Meesho, on building cybersecurity and compliance programmes from the ground up.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.