Third-Party Cyber Risk Is a Security Operations Problem Now | Black Hat 2026

48% of breaches now come through a third party. Three years ago it was 9%. Third-party cyber risk has stopped being a questionnaire exercise and become a security operations problem.
In this Dark Reading News Desk interview at Black Hat 2026, Joel Molinoff, Chief Operating Officer of iCOUNTER, explains to host Jeff Gamet why fifteen years of questionnaires and continuous vulnerability monitoring have failed to actually reduce risk. Enterprises own the risk their vendors create, but they lack visibility into it and lack any ability to make their third parties act on it.
Molinoff makes the case for risk determination at the point of intelligence collection: compressing the time from threat signal to remediation, rather than routing intelligence through analysts, then the security team, then ops, then IT, while the attacker operates at machine speed.
What's covered:
- Why questionnaire-and-monitoring third-party risk programs don't reduce risk
- How AI-enabled reconnaissance made vendors the easiest way into a target
- What operationalizing threat intelligence looks like in practice
- What realistically happens in the first 24 hours when a critical vendor is under attack
- Why mean time to remediation is becoming the defining metric for third-party risk
Additional information:
Joel Molinoff is Chief Operating Officer of iCOUNTER. He previously led third-party risk products and services at BlueVoyant, served as Chief Information Risk Officer and CISO at CBS Corporation, and held roles at the National Security Agency and the White House.
Recorded at the Dark Reading News Desk at Black Hat 2026. Hosted by Jeff Gamet, Contributing Editor, Dark Reading.
.avif)