CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users
46 minutes Posted Aug 3, 2026 at 11:00 am.
Welcome And Why TPRM Matters
CISSP Sprint Cohort And Goals
Vimeo Anodot Breach Case Study
2026 Supply Chain Attack Pattern
Controls That Shrink Blast Radius
TPRM Lifecycle And Vendor Tiering
Proof Over Questionnaires SOC2 ISO
Frameworks Workflow And Monitoring
Exam Practice Scenarios And Wrap Up
0:00
46:08
Download MP3
Show notes
Send us Fan Mail A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputa...