Cybersecurity Videos
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityVideosBeyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221
CybersecurityAI

Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221

•February 9, 2026
0
Paul Asadoorian
Paul Asadoorian•Feb 9, 2026

Why It Matters

Real‑time, AI‑driven GRC transforms vendor risk management, giving businesses continuous assurance of data protection and compliance, which is critical for maintaining customer trust and meeting regulatory demands.

Key Takeaways

  • •Vanta uses NIS CSF to benchmark quarterly GRC maturity.
  • •Customer‑zero approach lets internal teams shape product roadmap directly.
  • •Continuous monitoring replaces static vendor questionnaires with real‑time control checks.
  • •Public trust center displays live green checkmarks for each security control.
  • •AI integration promises automated, near‑real‑time third‑party risk assessments.

Summary

The episode centers on Vanta’s Agentic Trust platform and its role in protecting application user data through real‑time governance, risk, and compliance (GRC). Host Jessica Hoffman interviews JD Hanson, Vanta’s security and technology lead, who explains how the company uses its own product internally—acting as “customer zero”—to refine frameworks, drive product development, and demonstrate trust to external customers.

Vanta has transitioned from ISO to the NIS CSF framework, building custom maturity models that are evaluated quarterly. This systematic approach surfaces gaps, guides remediation, and has shown measurable progress over two years. A distinctive feature is the public Trust Center, where continuous monitoring automatically updates green checkmarks for each control, offering prospects a live view of Vanta’s security posture.

Hanson emphasizes that traditional vendor risk assessments are static and rubber‑stamped, advocating for continuous, transparent monitoring instead. He notes, “continuous monitoring is the most important part,” and highlights collaboration with FedRAMP 2.0 to showcase real‑time evidence. The conversation also touches on AI as a game‑changing force, enabling near‑real‑time, automated third‑party risk evaluations.

The shift toward continuous, AI‑enhanced monitoring signals a broader industry move away from point‑in‑time questionnaires toward transparent, real‑time risk visibility. Companies adopting such models can better protect user data, accelerate compliance, and build stronger trust with partners and regulators.

Original Description

CISO Jadee Hanson shares how Vanta “drinks its own champagne,” running on NIST CSF with quarterly baseline reviews and using Vanta’s GRC platform to turn every release into live UAT for privacy, governance, and compliance. We rethink third-party management—why point-in-time risk scores are fading and how AI drives continuous monitoring and outcome-based assurance. Bottom line: don’t just audit—instrument your controls and prove trust in real time.
Show Notes: https://cisostoriespodcast.com/csp-221
00:00:00 Jadee Hanson on Vanta's Mission and Her Unique CISO Role
00:03:12 Leveraging NIST CSF for GRC Maturity with Vanta's Expert Team
00:09:37 Moving Beyond Static Assessments to Continuous Vendor Monitoring
00:12:44 Achieving Outcome-Based Assurance Through Transparent Continuous Monitoring
00:16:34 How AI is Revolutionizing GRC and Vendor Risk Management Processes
00:20:04 The Power of Vanta's Customer-Centric Product Development and Feedback
00:23:51 Jadee Hanson's Life Advice: Embrace Opportunity, Not Anxiety
0

Comments

Want to join the conversation?

Loading comments...