Shared Assessments
  • Search
  • Demo
  • Book a Meeting
  • Membership
    • Why Shared Assessments?
    • Members and Subscribers
    • Licensees
    • Assessment Firms
    • Success Story
    • Committees
  • Products
    • SIG
    • SCA
    • VRMMM
    • Data Governance
    • ESG SIG
    • TPSIRR
    • Demo
    • Support
  • Education
    • TPRM Fundamentals
    • SIG Fundamentals
    • CTPRP Certification
    • CTPRA Certification
    • Success Stories
  • Events
    • Upcoming
    • On-Demand
    • Summit
  • Learn
    • Blog
    • Papers
    • Studies
    • Regulatory Hub
    • Framework
    • Glossary
  • Login
  • My Account
    • Portal
    • Logout
Select Page

CTPRP: Revenge of the TPRM Nerd

CTPRP: Revenge of the TPRM Nerd

LucMay2019 1200 close

Three years ago Luc Levensohn reached a career inflection point where he decided to transition from IT management to pursue information security compliance full-time. He quickly earned three certifications, including the Certified Third Party Risk Professional (CTPRP) designation, created a one-person information security consulting business and, he explains, broadcast a straightforward sales pitch: “I’m a third party risk management nerd looking for an opportunity in a large organization where I can focus on third party risk 100 percent of the time.” It did not take Staples long to hire him as its senior consultant for security compliance. Levensohn discusses the challenges of execution and the importance of marketing third party risk management (TPRM) best practices throughout the company.

What is your TPRM role at Staples?
Luc Levensohn:  I interface with legal, procurement, security operations, IT operations,  privacy and customers. I serve Staples customers directly, which is not something that many security roles get to do. At Staples, the importance of serving our customers is continually reinforced, and that really resonates with me. Service to our customers is our highest priority. It’s an awesome responsibility!

How has your CTPRP training and exposure helped you fulfill your job responsibilities?
Luc Levensohn: Once you’ve taken the test and earned the certification, it’s really up to you to execute. Although you know what your program should look like, getting to that state can be challenging because you rarely have governance over all, or even most, aspects of the program. I’ve learned a lot by executing. I’ve learned how important it is for me to market third party risk management best practices throughout the organization. Education and communications are a huge part of what we do as third party risk management professionals.

What value do you derive from retaining your CTPRP certification?
Luc Levensohn: The book and the certification are really facets of the Shared Assessments overall body of knowledge, which I continually refer to. This year was my seventh time attending the annual summit, and I always learn from all that content [at the summits and accompanying workshops] and from gaining exposure to other CTPRP’s programs – including some who are our customers. That exposure has been invaluable. It has especially helped us respond to requests from our highly regulated customers – which is a major component of the value I bring to our organization. Through Shared Assessments, I’ve met a handful of people who I can go to with a question or a problem that I’m not 100 percent sure how to address. That issue could relate to documenting a policy for responding to customer assessments or adjusting the framework for contract reviews. I know people who are specialists in those areas from the relationships we’ve developed while working on Shared Assessments committees together. Being able to reach out to them is priceless.

How does the company benefit from your CTPRP certification and TPRM expertise?
Luc Levensohn: First, organizing all of our content – including content from our affiliate companies – based on the SIG framework gives us a powerful tool to manage our evidence and to tell a compelling story. Second, having that broad but well-mapped organizational framework for all of our evidence enables us to be far more nimble and effective when we respond to unique or tailored customer requests. We can be sensitive to those information requests without launching into an all-out fire drill, which is something you always try to avoid. Third – and this more of a Shared Assessments principle than a specific CTPRP component – using risk scoring and risk tiers has helped us manage or own vendors more effectively. We’re continually able to prioritize the areas of highest risk, which strengthens our due diligence in an efficient manner. That’s why I have the people on my team take CTPRP test as soon as they are ready.

Connect with Luc.



SPEAK AT OUR EVENTS

Are you interested in being a speaker at one of our events?

Sign up for our Newsletter

Learn about upcoming events, special offers from our partners and more.

Blog

  • Inflation Risk: High Interest Rates, Possible Stagflation – Is Your Risk Plan Ready?Inflation Risk: High Interest Rates, Possible Stagflation – Is Your Risk Plan Ready?
  • Third Party Business Continuity and Disaster Recovery ProgramsThird Party Business Continuity and Disaster Recovery Programs
  • Future Supply Chains: More Diversity, Sharper DiligenceFuture Supply Chains: More Diversity, Sharper Diligence
  • Scenario Planning For Emerging UncertaintiesScenario Planning For Emerging Uncertainties

Papers

  • Guide: Geopolitical Risk – Spotlight on Russia/Ukraine Conflict – March 2022
  • Complex Supply Chains – Gaining Visibility into Nth Party GovernanceComplex Supply Chains - Gaining Visibility into Nth Party Governance
  • C-Suite Call to Action – Risk Management Through A Different LensC-Suite Call to Action - Risk Management Through A Different Lens
  • Adaptive Risk Management for Complex Supply ChainsAdaptive Risk Management for Complex Supply Chains

Studies

  • A New Roadmap for Third Party IoT Risk ManagementA New Roadmap for Third Party IoT Risk Management
  • The 2020 Third-Party Risk Management Study: The 3rd Rail of Security & ComplianceThe 2020 Third-Party Risk Management Study: The 3rd Rail of Security & Compliance
  • The Internet of Things (IoT): A New Era of Third-Party RiskThe Internet of Things (IoT): A New Era of Third-Party Risk
  • 2016 Shared Assessments Benchmark Study2016 Shared Assessments Benchmark Study

Shared Assessments

login contact request demo book a meeting

  • Twitter

About Us

  • Our Mission
  • Leadership Team
  • Advisory Board
  • Steering Committee
  • News
  • Awards

OUR POLICIES

  • Terms
  • Privacy
  • Cookies Settings
  • Event Terms & Conditions
  • Diversity, Equity & Inclusion
  • Neutrality Statement

join our newsletter

Learn more about upcoming events, special offers from our partners and more.

© 2023 Shared Assessments LLC

×

Terms of Use

I have read and agree to the Terms of Use

Agree Cancel
×

Terms of Use

I have read and agree to the Terms of Use

Agree Cancel
×

Oh No!

It looks like you don't have access to this tool. You can gain access by becoming a member or a subscriber.

Become a Member Subscribe


Support