Alice in Supply Chains

← Alice in Supply Chains14 Jul · 52 min

Episode 19 | July, 2026

Episode 19 | July, 202614 Jul52 min

<p>In the July 2026 episode of Alice in Supply Chains, Adrian and Alexandre dig into Verizon&#39;s first-ever Breach Impact Study, a companion to the DBIR built on roughly 70,000 cyber insurance claims (accepted and rejected) contributed via Cyber AcuView between 2019 and late 2025. The medians-only approach (no averages allowed!) makes this one of the most honest looks at breach costs yet, and the findings vindicate a recurring theme of the show: availability, not confidentiality, drives losses. Business interruption has the highest median claim (~$90K) and grew 51% year over year, while regulatory fines turn out to be the smallest loss category — so maybe stop leaning on &quot;the regulator will fine us&quot; to justify security budgets.</p><p><br></p><p>Software supply chain incidents are just 2% of claims but punch far above their weight, with immediate impacts more than double the rest of the dataset and extreme losses topping $100 million — cases that overwhelmingly hit policy caps, meaning the true economic damage is even higher. Adrian connects this to the rise of cascading breaches (Trivy → LiteLLM → everyone downstream), and the pair discuss why this kind of concentrated, systemic risk terrifies insurers and may reshape coverage terms.</p><p><br></p><p>Story two is Gartner&#39;s new &quot;Mastering TPCRM&quot; document series, which Adrian and Alexandre praise as unusually prescriptive and genuinely useful: frameworks for roles and responsibilities across security, legal, procurement, and — critically — business owners, plus a starter TPCRM policy you can adapt. Alexandre argues the make-or-break factor for any TPCRM program is whether business owners formally own the risks they accept, rather than treating the process as a checkbox that must not slow down contracting.</p><p><br></p><p>Finally, Schrems III is nigh: with the US Supreme Court&#39;s ruling undermining the independence of agencies like the FTC — the very foundation of the EU-US Data Privacy Framework — Max Schrems is poised to strike down transatlantic data transfer agreement number three. Alexandre walks through why the EU has painted itself into a corner (idealistic legislation, total dependence on US cloud, AI, and OS providers), what the $307 billion per year in EU spending on US cloud services means for both sides, and why every company with a transatlantic footprint should be talking to their legal counsel now.</p><p>Links:</p><p>Tenchi Conference 2026: Details, tickets, and CFP - <a href="https://luma.com/vvzsmej9" target="_blank" rel="noopener noreferer">https://luma.com/vvzsmej9</a></p><p>Story 1: Verizon Breach Impact Study - <a href="https://verizon.com/dbir" target="_blank" rel="noopener noreferer">https://verizon.com/dbir</a></p><p>Story 2: Gartner’s Series on Mastering TPCRM - <a href="https://www.gartner.com/en/documents/7907309" target="_blank" rel="noopener noreferer">https://www.gartner.com/en/documents/7907309</a></p><p>Story 3: Schrems III is Nigh - <a href="https://kaynemcgladrey.com/blog/when-the-load-bearing-wall-comes-down/" target="_blank" rel="noopener noreferer">https://kaynemcgladrey.com/blog/when-the-load-bearing-wall-comes-down/</a></p>