Webinar
From Questionnaires to Consequences: Measuring Third-Party Cyber Risk That Matters
Wednesday, February 18, 2026 | 11:00am-12:00pm ET
Third-party risk programs rely on standardized tools like the SIG to evaluate cybersecurity posture, yet many organizations struggle to connect assessment responses to the real-world impact of cyber incidents. This webinar explores how incident-severity modeling and real-world ransomware intelligence can strengthen third-party risk decisions. The discussion introduces a structured approach to measuring the magnitude, duration, and operational impact of cyber incidents, alongside analysis of ransomware trends from 2023–2025 that show how attacker behavior and targeting of third parties are evolving. Together, these perspectives help risk teams better understand which control gaps lead to high-impact incidents, how to interpret SIG responses in the context of active threats, and how to communicate third-party incident severity clearly to internal stakeholders. The session is designed for organizations looking to move from static questionnaire-based assessments toward operationally meaningful third-party cyber risk insight.
Speakers:
- Munish Walther-PuriHead of Critical Digital Infrastructure, TPO GroupMunish develops and presents the Infrastructure Cyber Incident Scale, a model designed to measure the severity of operational technology cybersecurity incidents. The scale adapts concepts from natural disaster measurement tools such as the Richter Scale to quantify the magnitude, duration, and impact of OT events. His work focuses on giving OT operators, emergency response teams, public officials, and communicators a clear and intuitive way to understand and compare incident severity in real time, along with the underlying rationale and structure of the scale.View full bio
- Steve ThomasFounder & CEO, HackNoticeSteve analyzes ransomware activity from 2023 through 2025 through continuous monitoring of attacker communications, leaks, and victim disclosures. His work examines shifts in ransomware gang behavior, consolidation among top groups, evolving tactics, and the economic incentives driving attacker operations. The analysis highlights high impact trends across industries and regions and details the techniques emerging in 2025. The focus is on identifying how ransomware threats are changing and which patterns matter most for preparation and defense.View full bio
- Andrew MoyadCEO, Shared AssessmentsAndrew is the CEO of Shared Assessments, a global risk membership organization that supports hundreds of companies, risk programs, and thousands of their associated third-party, compliance, cyber, and other risk professionals. As a risk practitioner and executive with more than 25 years in risk management, Andrew promotes the creation of cultures of accountability for organizations and their third parties. Prior to joining Shared Assessments in 2022, Andrew served as Senior Vice President, Vendor Risk Management and Corporate Insurance at Blackstone for four years, where he led a team of risk professionals responsible for supporting all business teams through all phases of the vendor lifecycle. Prior to Blackstone, he worked at BlackRock from 2010-18, where he first joined and then eventually led the firm’s Vendor Risk Management team. He also worked at Citigroup nine years, finishing as a Senior Vice President and Business Information Security Officer in Global Fixed Income, leading onsite third-party risk assessments across the United States, Europe, and Asia.View full bio