17th TPRM Roundtable Event Report
Date: 25 April 2026
Time: 4:00 PM – 6:00 PM UAE Time
Theme: Resilience Under Fire: Cyber & Third-Party Risk in Geopolitical Turbulence
Organizer: International TPRM Alliance (ITA)
Moderator: Anshuman Tripathi

Roundtable - Overview

The International TPRM Alliance (ITA) successfully hosted its 17th TPRM Roundtable of 2026, bringing together Third-Party Risk Management, Cybersecurity, Operational Resilience, Supply Chain Security, and Governance professionals from across multiple countries and industries.

Against a backdrop of escalating geopolitical conflicts, supply chain disruptions, cyber warfare, sanctions, cloud concentration risks, and increasing regulatory scrutiny, the session explored a critical question:

How can organizations build resilience when cyber threats, geopolitical uncertainty, and third-party dependencies collide?

The discussion emphasized that resilience is no longer a theoretical concept or compliance exercise—it has become a strategic business imperative.The session featured distinguished industry leaders who shared practical experiences, emerging trends, and actionable recommendations for organizations seeking to strengthen their third-party ecosystems.

Distinguished Panelists

Fatema Fardan
Digital Data Cybersecurity Lead
Leading Bahrain Bank | Bahrain

Alison Buchanan
Professor & Resiliency Leader
Niagara University | Canada

Asem Alnogaithan, 
CEO 
GlassHub | Saudi Arabia

Karthikeyan Ramdass
Lead Member of Technical Staff
Salesforce | United States

Moderated By

Anshuman Tripathi
The session was expertly moderated by Anshuman Tripathi, who guided the discussion through real-world geopolitical scenarios, cyber incidents, cloud outages, and resilience challenges facing modern organizations.


Setting the Context

The roundtable opened with reflections on the rapidly changing geopolitical environment and its growing influence on organizational risk management.

Panelists discussed how recent geopolitical developments have demonstrated that risks are no longer isolated to specific countries or sectors.

Instead, organizations now operate within highly interconnected ecosystems where disruptions can cascade across suppliers, cloud providers, technology vendors, logistics partners, and regulatory environments.

A key message emerged early: Organizations can no longer afford to wait for incidents before activating resilience strategies. Resilience must be embedded into business operations before crises occur.


Key Discussion Pointers

1. Geopolitical Risk Has Become a TPRM Priority

The panel agreed that geopolitical risk is no longer a separate risk category.

It now directly influences:
 - Vendor stability
 - Data residency requirements
 - Regulatory obligations
 - Cross-border operations
 - Supply chain continuity
 - Cybersecurity posture

Panelists highlighted how sanctions, trade restrictions, regional conflicts, and political tensions can instantly impact third parties and disrupt business operations.

Organizations must therefore incorporate geopolitical intelligence into their TPRM programs rather than relying solely on traditional risk assessments.

2. Supply Chains Have Become Prime Attack Surfaces.

One of the strongest messages from the session was that supply chains are increasingly being targeted by threat actors.

Panelists discussed how:
 - Cyber attacks frequently originate through suppliers.
 - Software dependencies create hidden risks.
 - Fourth-party and nth-party risks remain largely invisible.
 - Attackers increasingly exploit trusted third parties.

Recent incidents demonstrated that vulnerabilities within a single supplier can rapidly impact multiple organizations and sectors.

The panel encouraged organizations to expand their visibility beyond direct vendors and assess broader ecosystem dependencies.

3. Moving Beyond Compliance-Driven TPRM

A recurring theme throughout the discussion was the need to move beyond treating TPRM as a compliance activity.

Asem Alnogaithan emphasized that many organizations still view third-party risk management as a checkbox exercise rather than a strategic capability.

Key recommendations included:
- Shift from periodic reviews to continuous monitoring. 
- Focus on resilience rather than documentation.
- Understand data flows throughout the vendor ecosystem.
- Evaluate vendors as part of a broader interconnected environment.

The panel agreed that compliance alone does not create resilience.

4. Cloud Concentration and Critical Vendor Risks

Several recent cloud service disruptions were discussed, including the impact of outages on organizations across the GCC region.

Panelists highlighted how critical vendors today extend beyond traditional service providers and now include:
- Cloud platforms
- Payment processors
- Fintech providers
- Telecommunications providers
- Software service providers

Fatema Fardan noted that vendor criticality is dynamic and can change rapidly during crisis situations.

The discussion reinforced the need for organizations to:
- Identify concentration risks.
- Understand cloud dependencies.
- Establish alternative service arrangements.
- Strengthen vendor resilience assessments.

5. Software Supply Chain Security

Karthikeyan Ramdass provided insights into the growing importance of software supply chain security.

Key discussion points included:
- Open-source dependency risks.
- Software Composition Analysis (SCA).
- Continuous vulnerability monitoring.
- DevSecOps integration.
- Zero-day vulnerability management.

The panel discussed how organizations must move beyond one-time software reviews and adopt continuous monitoring models to address emerging software risks.

6. Building Resilient Teams, Not Just Plans

One of the most impactful messages came from Alison Buchanan. She emphasized that:
"Organizations should focus on building resilient people and teams rather than relying solely on resilience plans."

Key recommendations included:
- Conduct regular crisis exercises.
- Engage suppliers in resilience planning.
- Build trust-based relationships before crises occur. 
- Support employee well-being during disruptions.
- Create adaptive response capabilities.

The discussion highlighted that resilience is ultimately a human capability, not merely a documented process.

7. Balancing Innovation and Sovereignty

As organizations increasingly adopt cloud services, AI technologies, and digital transformation initiatives, panelists discussed the challenge of balancing innovation with regulatory obligations.

Areas of concern included:
- Data localization requirements.
- Sovereignty considerations.
- Cross-border data transfers.
- Regulatory compliance.
- Cloud dependency risks.

The panel agreed that organizations should design resilience and compliance into innovation initiatives from the outset rather than treating them as afterthoughts.

8. Governance and Board-Level Engagement

The discussion concluded with an important conversation around board oversight and governance.

Panelists emphasized that TPRM and resilience discussions must become regular boardroom topics.

Recommendations included:
- Integrating TPRM metrics into board reporting.
- Aligning risk appetite with third-party risks.
- Conducting executive-level resilience reviews.
- Providing regular updates beyond formal meetings.
- Ensuring leadership visibility into emerging geopolitical risks.

The panel noted that proactive communication is significantly more effective than reactive crisis reporting.


Key Lessons Learned

The session generated several important lessons for practitioners:

Lesson 1

Supply chains are now primary attack surfaces and require continuous visibility.

Lesson 2

Geopolitical risks must be integrated into TPRM programs.

Lesson 3

Organizations should focus on resilience by design rather than compliance by audit.

Lesson 4

Cloud concentration risks require greater attention and oversight.

Lesson 5

Continuous monitoring is replacing periodic assessments.

Lesson 6

People, relationships, and leadership are critical resilience enablers.

Lesson 7

Board engagement is essential for successful resilience programs.

Lesson 8

Organizations must prepare for disruptions that may be beyond their control.


Actionable Recommendations for Organizations

The panel collectively recommended that organizations:

✓ Vendor Resilience Planning

Require vendors to document and regularly update:
- Business continuity plans
- Disaster recovery plans
- Alternate site strategies
- Crisis communication mechanisms

✓ Continuous Monitoring

Move beyond annual assessments and implement:
- Continuous cyber monitoring
- Geopolitical risk monitoring
- Vendor performance tracking
- Supply chain visibility programs

✓ Scenario Testing

Conduct regular:
- Tabletop exercises
- Chaos engineering tests
- Vendor failure simulations
- Cloud outage drills

✓ Concentration Risk Management

Assess and mitigate:
- Cloud concentration risks
- Single vendor dependencies
- Critical technology concentrations

✓ Board Reporting

Integrate:
- TPRM metrics
- Key Risk Indicators (KRIs)
- Resilience metrics
- Geopolitical risk scenarios

into executive and board reporting frameworks.

Closing Remarks

The 17th TPRM Roundtable once again demonstrated the strength of the International TPRM Alliance's global community, bringing together professionals from diverse industries and geographies to address some of the most pressing challenges facing organizations today.

The discussion reinforced a critical reality:

In an era of geopolitical uncertainty, cyber warfare, and increasing third-party dependency, resilience is no longer optional—it is a strategic necessity.

Through thought leadership, practical experiences, and collaborative learning, the session provided attendees with valuable insights to strengthen their Third-Party Risk Management, Cybersecurity, Operational Resilience, and Supply Chain Risk Management programs.

The International TPRM Alliance extends its sincere appreciation to the moderator, panelists, and participants whose expertise and engagement made the 17th TPRM Roundtable a resounding success.

Together, we continue to connect minds, elevate standards, and advance the future of Third-Party Risk Management worldwide.