Third-Party Risk Management
for European Regulation.
Same team, sharper mission. We're becoming Acuna GRC — watch our 45-second briefing on what's changing, what isn't, and what it means for your TPRM program and GRC priorities.
Built the platform too.
Reading about TPRM is one thing. Running it is another. Acuna GRC is the platform our practitioners build with, vendor onboarding, continuous monitoring, evidence collection, and audit-ready reporting in one place.
The Breach Wire.
What TPRM failures cost.
Methodology: Disclosed costs only — settlements, regulatory fines, remediation outlays from SEC 8-Ks, GDPR/FCA enforcement notices, court records, and HHS OCR. Updated monthly. Never sourced from member or customer data.
Sources & full ledger →Full methodology
Sushi Talks, top episodes.
The hidden risks of AI: What businesses can learn from AI cheating in chess
Third Party Risk Management: Interview with Monika Atanasova on Industry Evolution & AI Impact
How Hackers Hijack Networks: What Businesses and Home Users Must Know
Understanding Third-Party Risk Management: Essential Insights for Businesses of All Sizes
How can financial risks in a supply chain be managed?
NIS2 Compliance: Are You at Risk of Personal Liability? | Supplier Shield
Supplier Risk Management: Best Practices to Safeguard Your Supply Chain
Streamlining TPRM: How to Boost Efficiency and Cut Costs
Why business continuity is now a legal obligation and what most leaders still don’t understand
Experts in your chair.
Cyber security and governance consultant with 20+ years advising multinationals, governments, and international organizations.
Business continuity and information security expert, certified international trainer and Lecturer at Sorbonne University Paris 1.
Strategic legal advisor in data protection and privacy law, helping organizations navigate GDPR, NIS2, DORA, and Swiss nDSG.
Hands-on IS and business continuity trainer and auditor with experience spanning finance, cloud, public sector, and NGOs.
Supports clients through vendor risk, compliance technology integration, and gap analysis from policy development to go-live.
Leads end-to-end project supervision across implementations, audits, and compliance programs for global organizations.
Risk practitioner with a story to tell? Share your expertise with our audience.
We welcome unpaid guest contributions with author attribution and profile/backlink credit.
Abilene Academy.
The reading is free. The training is structured. Abilene Academy is our practitioner school with accredited courses taught by working CISOs, GRC leads, and continuity experts.
Free for practitioners.
Cross-Border Data Transfers Between Switzerland and France: A Compliance Guide
Personal data flows freely between Switzerland and France in both directions with no SCCs required. Learn when SCCs and Transfer Impact Assessments apply, how FADP Article 9 compares to GDPR Article 28, and what financial-sector overlays apply.












