Mastering Third-Party Risk Management : Vendor & Software Supply Chain

BlackHat USA 2026

03 August 2026

Date: August 3 & August 4, 2026 | 1 Day Training (two rounds)
Location: Palm - A, Mandalay Bay, Las Vegas
Track: Supply Chain, Risk
Format: 1 Day Training
Instructors: Anant Shrivastava | Founder, Cyfinoid Research; Sunil Yadav | Founder / Head of Security, x-biz Techventures
Skill Level: Beginner

Course Overview

This course focuses on how attackers actually use third-party, fourth-party, and software supply chain paths to compromise organizations, instead of going directly at core systems. Participants learn how to move from checklist-driven TPRM to a more practical model that combines digital verification, BOM analysis, continuous monitoring, and clear workflows for handling vendor incidents.

Modern breaches rarely start at the front door. Attackers now come through vendors, SaaS tools, open-source packages, CI/CD pipelines, and managed service providers. Incidents like SolarWinds, MOVEit, XZ backdoor, dependency confusion attacks, and large-scale SaaS provider breaches have shown how a single weak link can compromise thousands of organizations at once.

Topics Covered

Key Takeaways