Ayşim Nikralı, Director of Cybersecurity Consulting Services at Forcerta, spoke about the strategies that should be followed to continuously monitor supplier risks. Nikralı said:
“AI” has certainly made a significant contribution to business processes. This is because it also serves to greatly accelerate them. But on the other hand, of course, there’s the need to keep the organization’s internal data within the organization—especially since, as you know, this data is also used to train “AI.” This is to ensure the organization isn’t part of that process. For example, when you try to take advantage of these systems yourself, you might end up teaching your competitor certain data about your own company. For this reason, we see this particularly intensely in the financial sector. This is because cloud usage is restricted in regulated industries. They can set up these systems within private cloud environments using language models they’ve developed themselves. Companies that rely heavily on cloud infrastructure—and those operating in less strictly regulated sectors—can still access cloud services. Of course, one crucial point here is this: If the information you request from the “cloud” contains any critical or sensitive data, it’s possible to filter that information—without saying “no” to users or blocking them—so that they can still receive the data they want from “AI” through certain filters. Technologies related to this are well-developed. Of course, demand on the supplier side continues to grow significantly. Because as technology grows and expands, the need for organizations that provide this technology also increases. After all, expanding an organization’s internal structures is only possible up to a certain point. Beyond a certain point, you find yourself having to source many things from outside. In that context, you must first prioritize a criticality classification based on numerous criteria—such as which aspects of the services you receive from suppliers pose greater risks, or even before that, whether the work you perform—depending on the service content or your specific field—involves issues related to data security or business continuity.becomes a higher priority. Because it’s not possible to address the security and risks of all suppliers at the same time. Here, too, managed services prove to be very valuable. Because you’re acquiring the technology—for example, in this context—and you’re also using specific products to assess your suppliers from an external perspective, evaluating how they appear to outsiders and measuring their maturity. However, we’re also observing a shift toward managed services when it comes to ensuring continuous monitoring—whether to assess the effectiveness of those products, conduct periodic reviews, or implement improvements.