
← Alice in Supply Chains30 Jan · 58 min
Episode #13 | January 2026
<p>Alice in Supply Chains is a monthly podcast by based on the Alice in Supply Chains newsletter - that provides interesting discussions and insights on all things related to third-party cyber risk management (TPCRM). </p><p>It's hosted by two leading voices in the industry, Tenchi Security's Co-founder and CTO <a href="https://www.linkedin.com/in/sieira/" target="_blank" rel="ugc noopener noreferrer">Alexandre Sieira</a> & The Defender's Initiative Principal Researcher, <a href="https://www.linkedin.com/in/adrian-sanabria/" target="_blank" rel="ugc noopener noreferrer">Adrian Sanabria</a>, and it promises expert opinions and takeaways to help audiences navigate the complex cybersecurity landscape.</p><p><br></p><p>1. 2026 Outlook</p><ul><li>AI hits "put up or shut up" time—needs to prove enterprise value beyond demos</li><li>Geopolitical fragmentation accelerating, impacting supply chain dependencies</li><li>China signaling supply chain independence (banning US/Israeli security vendors, declining Nvidia H200s)</li></ul><ul><li><strong>Upcoming episode</strong> with Tony Martin-Vegue on cyber risk quantification</li><li><strong>RSA Conference</strong>: Tenchi hosting events at Harlan Records, Sun–Wed, during RSA week</li></ul><p>2. Announcements</p><ul><li><strong>Upcoming episode</strong> with Tony Martin-Vegue on cyber risk quantification</li></ul><ul><li><strong>RSA Conference</strong>: Tenchi hosting events at Harlan Records, Sun–Wed, during RSA week</li></ul><p>3. Stories covered</p><p><u><strong>Story 1: ENISA NIS2 Survey</strong></u><br>Survey of 1,080 professionals across 27 EU countries on cybersecurity investments.</p><ul><li><strong>Top investment driver</strong>: Regulatory compliance (70%), far ahead of proactive risk management (42%)</li><li><strong>Hardest to implement</strong>: Vulnerability management (#1), TPRM (#2)</li><li><strong>Supplier inventory</strong>: Under 10% of companies maintain one—current TPRM approaches don't scale</li><li><strong>Top 2026 concerns</strong>: Ransomware and supply chain attacks (~47%)</li></ul><ul><li><a href="https://www.enisa.europa.eu/publications/nis-investments-2025" target="_blank" rel="noopener noreferrer">https://www.enisa.europa.eu/publications/nis-investments-2025</a></li></ul><p>Story 1 Resources</p><ul><li>https://www.enisa.europa.eu/publications/nis-investments-2025<br></li></ul><p><u><strong>Story 2: SOC 2 Fraud Allegations</strong></u><br>Social media discussions allege compliance platforms and auditors are rubber-stamping SOC 2 reports.</p><ul><li>Claims of nearly identical reports across different companies</li><li>No AICPA enforcement—peer review doesn't verify actual control testing</li><li>Post-breach cases (e.g., PowerSchool) reveal SOC 2s claiming controls that weren't implemented</li><li><strong>Takeaway</strong>: Don't over-trust SOC 2s for critical third parties; consider independent verification</li></ul><p>Story 2 Resources</p><ul><li><a href="https://www.linkedin.com/posts/troyjfine_details-have-emerged-regarding-a-widespread-activity-7415043499676483584-nI5Z" target="_blank" rel="noopener noreferrer">https://www.linkedin.com/posts/troyjfine_details-have-emerged-regarding-a-widespread-activity-7415043499676483584-nI5Z</a></li><li><a href="https://www.linkedin.com/posts/sieira_details-have-emerged-regarding-a-widespread-activity-7415394996184424449-CSzO" target="_blank" rel="noopener noreferrer">https://www.linkedin.com/posts/sieira_details-have-emerged-regarding-a-widespread-activity-7415394996184424449-CSzO</a></li><li><a href="https://infosec.exchange/@AlexandreSieira/115865691003110478" target="_blank" rel="noopener noreferrer">https://infosec.exchange/@AlexandreSieira/115865691003110478</a></li><p><br></p></ul><p><u><strong>Story 3: Japan & Korea Cybersecurity Regulations</strong></u><br>Both countries responding to major 2025 breaches (Asahi, SK Telecom, KT, Coupang) with new rules.</p><ul><li><stron