Events
Lema AI sponsors NAC-ISSA November lunch
Join us on Tuesday, November 10, for our chapter lunch sponsored by Lema AI. For years, Third-Party Risk Management (TPRM) has been built around a simple assumption: the greatest risk

November 10 @ 11:30 am – 12:30 pm
Join us on Tuesday, November 10, for our chapter lunch sponsored by Lema AI.
For years, Third-Party Risk Management (TPRM) has been built around a simple assumption: the greatest risk occurs when a new vendor is introduced into the organization. Security teams perform due diligence, approve the vendor, and revisit the relationship months or even years later. Artificial intelligence has fundamentally changed that model. Today’s greatest governance challenge is no longer evaluating new vendors. It is understanding how trusted vendors continuously evolve after they have already been approved. AI copilots, autonomous agents, new data-sharing practices, MCP integrations, and rapidly changing vendor capabilities are transforming enterprise software faster than traditional review cycles can keep pace. This session explores why AI is reshaping the software supply chain, how traditional TPRM programs are falling behind, and what security leaders can do to evolve from periodic assessments to continuous vendor intelligence. Attendees will leave with a practical framework for identifying meaningful vendor changes, prioritizing risk, and building security programs that are designed for the pace of AI innovation.
Our presenter, Craig Riddell, is the Chief Information Security Officer (CISO) at Lema AI, where he leads security strategy, governance, customer trust, and executive engagement. He partners with enterprise security leaders to help organizations modernize Third-Party Risk Management through continuous risk intelligence, evidence-based decision making, and AI-driven security insights. Craig specializes in the intersection of cybersecurity, AI governance, and third-party risk. As both a practicing CISO and executive advisor, he focuses on helping organizations adapt their security programs to a world where vendors, technologies, and AI capabilities evolve continuously. His work challenges traditional approaches to vendor risk by emphasizing continuous visibility over periodic assessments and helping security teams move from reactive compliance to continuous confidence.