Third Party Risk Management: How One Vendor Breach Exposed 119,000 Users
Aug 03, 2026When analytics vendor Anodot was compromised, attackers used stolen authentication tokens to pull customer names, emails, and metadata from Vimeo — exposing 119,000 users without touching video content or payment data. In this episode of CISSP Cyber Training, Shon Gerber breaks down what actually went wrong and how Third-Party Risk Management (TPRM) could have caught it sooner. You'll learn the full TPRM lifecycle (scoping, due diligence, contracting, onboarding, monitoring, and offboarding), how to tier vendors by risk (Critical, Moderate, Low), the real difference between SOC 2 Type 1 and Type 2, and why vendor questionnaires alone aren't enough. Sean also covers fourth-party risk, contractual controls like breach-notification timelines and right-to-audit clauses, and the frameworks CISSP candidates need to know — NIST 800-161, ISO 27036, and NIST CSF 2.0 — plus common exam traps around vendor risk. If you manage vendor relationships or are studying for the CISSP exam, this episode shows exactly how third-party gaps turn into six-figure breaches.
CISSP Cyber Training Academy Program!
Are you anĀ ambitiousĀ Cybersecurity or IT professionalĀ who wants to take yourĀ careerĀ to a wholeĀ new levelĀ by achieving the CISSP Certification?Ā
LetĀ CISSP Cyber TrainingĀ help you pass the CISSP Test theĀ first time!