

You're invited to join us in Nashville this November!
After continued demand and past successes, CeFPro is returning with the second edition of Third Party & Supply Chain Risk: Cross Sector in Nashville this November.
Third party and supply chain risks should be top of mind across industries, sectors, and types of organizations. However, different industries have different approaches to tackling and mitigating such risks; what can you learn from your peers and approaches across industries?
This Congress will bring Senior Risk Executives across all industries together to address the critical aspects of managing third-party relationships and leverage technology to stay ahead, as they learn best practices to create a blueprint of success for their organization.


Key highlights:
- GEOPOLITICAL RISK:
Managing supply chains across jurisdictions and continued uncertainties of external factors
- ECONOMIC VOLATILITY:
Monitoring global economic volatility and reliance of global economies on supply chains
- CYBER SECURITY:
Prioritizing cyber security defenses across third parties and supply chain
- PRIVACY:
Incorporating privacy as part of a security framework to protect confidential data
- NEARSHORING:
Managing global trends of onshoring and deglobalization post pandemic
- CONTRACTS:
Reviewing third party controls to mitigate risks and key features to include within a contract
- 4TH PARTIES:
Fourth parties/subcontracting: Gaining a holistic view of subcontractors to understand full risk landscape
- AI:
Leveraging advanced technology to gain insight across the supply chain whilst understanding potential new risks
Hear from subject matter experts and industry front-runners

Free to attend, plus VIP upgrade option
This year we welcome all practitioners and end users to join the Congress for FREE. Enhance your experience and upgrade your registration to our VIP pass and join us for our post-event drinks reception. Visit the registration tab for more information.

7+ hours of networking opportunities
After sessions are over, continue conversations within our networking breaks and complimentary cocktail hour. Network with colleagues, peers and event partners for a well-rounded view of key industry opportunities.

Explore the city center of Nashville
In addition to attending the conference, Nashville is a lively city offering a range of attractions. Make the most of Music City with our conveniently located venue situated within walking distance from Broadway!

Hear from senior risk experts representing a diverse range of industries:

FBI

Walmart

GSK

Meta

TikTok

HCA Healthcare

Pelco Products

HBC

American Industrial Partners

United States Steel
*All views and opinions expressed are those of the individual and not of the associated organization.
Session previews and related insights
Get an insight of what to expect from the Congress with our past and present speaker session previews.
Best practices for a world class third party cyber risk program
Best practices for a world class third party cyber risk program Vanessa Jankowski, Senior Vice President & General Manager, TPRM & CNI, Bitsight was a speaker at our recent Vendor & Third Party Risk USA Congress. {{ vc_btn: title=Find+out+more+about+Vendor+%26amp%3B+Third+Party+Risk+USA&style=outline-custom&outline_custom_color=%23d51224&outline_custom_hover_background=%23d51224&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-usa%252F }} The views and opinions expressed in this article are those of the thought leader as an individual, and
Reviewing regulatory expectations and driving resilient supply chains
Reviewing regulatory expectations and driving resilient supply chains Wayne Scott, Regulatory Compliance Lead, NCC Group Below is an insight into what can be expected from Wayne's session at Vendor & Third Party Risk Europe 2023. {{ vc_btn: title=Find+out+more+about+Vendor+%26amp%3B+Third+Party+Risk+Europe&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and opinions expressed in this article are those of the thought leader as an individual,
Managing increased risk of data breaches through third parties with increased data sharing
Managing increased risk of data breaches through third parties with increased data sharing Anders Norremo, VP, Product Management for TPRM, Bitsight Below is an insight into what can be expected from Anders' session at Vendor & Third Party Risk Europe 2023. {{ vc_btn: title=Find+out+more+about+Vendor+%26amp%3B+Third+Party+Risk+Europe&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and opinions expressed in this article are those of
The impact of geopolitical risk on vendors and supply chain
The impact of geopolitical risk on vendors and supply chain Merlin Linehan, Risk Manager, EBRD Below is an insight into what can be expected from Merlin's session at Vendor & Third Party Risk Europe 2023. {{ vc_btn: title=Find+out+more+about+Vendor+%26amp%3B+Third+Party+Risk+Europe&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and opinions expressed in this article are those of the thought leader as an individual,

Would your organization like to partner with us on this event?
To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact sales@cefpro.com or call us on +1 888 677 7007 for more information.
Sponsors
Co-sponsors
Associate sponsors
Content and media partners
Agenda
8:00 – 8:50
Registration and breakfast
8:50 – 9:00
Chair’s opening remarks
![]() |
Dov Goldman, VP Risk Strategy, Panorays |
9:00 – 9:40
REGULATION
Global supply chain: A law enforcement perspective
View Session Details
- Reviewing national security
- Assessing community outreach
- Ensuring public safety
![]() |
Senior Executive, FBI |
9:40 – 10:20
GEOPOLITICAL RISK
Managing supply chains across jurisdictions and continued uncertainties of external factors
View Session Details
- Spillover effects of disruptions to supply chains
- Impact of geopolitical factors on assessment of risks
- Making complex global interlinkages
- Managing increasingly confrontational global relations
- Spill over into trade relations and tariff disputes
- Changes to processes as a result of trade tensions
- Ripple effect of changes throughout the supply chain
- Impact to manufacturing with reliance on China and Taiwan
- Understanding level of exposure
- Managing short and long term disruptions
- Updating contractual obligations in line with geopolitical changes
![]() |
Lacrecia Billings, Interim Vice President, Supply Chain Acceleration, Walmart |
10:20-10:50
Morning refreshment break and networking
10:50-11:30
Staying vigilant: 7 practical tips for ongoing third-party risk monitoring
View Session Details
- The importance of ongoing monitoring with business justification metrics
- Best practices for monitoring third-party risks across risk domains
- The top risks to look out for as it relates to your third parties
- Tips for automating incident response when new risks arise
- Methods to remove human error when monitoring third-party relationships
![]() |
Matt Moog, General Manager, Third-Party Risk Management, OneTrust |
11:30 – 12:20
RESILIENCE – PANEL DISCUSSION
Gaining visibility across suppliers and subcontractors and enhancing resilience
View Session Details
- Conducting security assessments to drive resilience
- Understanding and quantifying supply chain resiliency
- Identifying challenges and vulnerabilities
- Identifying key suppliers and steps to manage relationship
- Reviewing impact of global events on supply chain resilience
- Understanding market forces that could impact supply base
- Business continuity in case of supply chain disruptions
- Understanding where reliance lies on certain products or services
- Reviewing traceability requirements across industries
![]() |
Robert Peters, Manager of Supply Chain Implementation, HealthTrust Performance Group |
![]() |
Jeffrey Wheatman, Cyber Risk Evangelist, Black Kite |
|
Sara Ricci, Information Risk Governance and Resilience Executive, HBC |
12:20-1:20
Lunch break and networking
1:20 – 2:00
PROGRAM DEVELOPMENT
Introducing layers of risk management to build a true risk program
View Session Details
- Understanding how financial services conduct supply chain oversight
- Introducing cyber and IT security controls
- Reviewing interagency guidance to set as cross industry standard
- Developing infrastructure to manage third party risk
- Building out unified platforms and common approaches
- Calculating inherent risk for all third parties
- Quantifying risk beyond tiering high, medium, low
- Focusing on risk beyond just assessments
![]() |
Eric Elbel, Senior Manager, Supply Chain Logistics, AVROBIO |
2:00- 2:40
INDEPENDENT ASSESSMENTS
Identifying which third parties to undertake deep dive independent assessments
View Session Details
- Determining frequency of assessments
- Understanding IT, cyber and physical security risks
- Differentiating different types of third parties and services
- Identifying high risk third parties
- Demonstrating value to secure budget
- Identifying criticality via inherent risk questionnaires
- Inclusion of likelihood factors
- Identifying the likelihood of risks manifesting themselves
- Developing risk data: Driving a cultural change towards risk management
![]() |
Michael Rivas, Head of Third Party, DTCC |
![]() |
Tausif Khan, Associate Director, Third Party Risk, DTCC |
2:40- 3:20
RANSOMWARE
Preparing for increased frequency of ransomware attacks as third parties are increasingly used as an entry point
View Session Details
- Increased attacks on smaller third parties
- Ransomware as a Service
- AI as a risk providing access to less skilled criminals
- Role of cyber insurance in paying ransom
- Developing data backup plans
- Increased vulnerabilities with increased M&A activities
- Managing impact on brand reputation
![]() |
Alexander Heid, Fellow, VP of Threat Intelligence, SecurityScorecard |
3:20-3:50
Afternoon refreshment break and networking
3:50- 4:30
CYBER SECURITY
Prioritizing cyber security defenses across third parties and supply chain
View Session Details
- Third party security risk, a rising concern
- Risk conversations with TECH
- Aligning on enterprise meaning of ‘Risk‘
- Security basics – Cyber security controls in plain english
- A third party security risk management (TPSRM) framework
- Obtaining 3rd party security assurance
- TPSRM challenges – frameworks don’t always look like real life
![]() |
Cindy Chadwick, Supplier Cyber Security Risk & Assurance Principal Architect, GSK |
4:30- 5:20
PRIVACY – PANEL DISCUSSION
Incorporating privacy as part of a security framework to protect confidential data
View Session Details
- Managing access controls to data
- Aligning privacy controls with security controls
- Protecting confidentiality of data
- Technical access controls to implement privacy rules
- Distinguishing between privacy and security
- Managing interconnected nature whilst understanding differences
- Inclusion of privacy officer in event of a security incident
- Managing regulations across states and jurisdictions
- Privacy risks with increased use of AI and large language models
![]() |
Phani Dasari, former Head of Business Security Officer, TikTok |
![]() |
Eric Elbel, Senior Manager, Supply Chain Logistics, AVROBIO |
![]() |
Cindy Chadwick, Supplier Cyber Security Risk & Assurance Principle Architect, GSK |
5:20-5:30
Chair’s closing remarks
5:30
End of day one and networking drinks reception
8:00- 8:50
Registration and breakfast
8:50- 9:00
Chair’s opening remarks
9:00- 9:40
RECOVERY
Post pandemic recovery: Long-term repercussions of global disruptions
View Session Details
- Managing long lead times and impact downstream
- Impact to industries reliant on semiconductors still facing delays
- Managing and navigating delays
- Lessons learnt across industries
- Global labor and manufacturing shortages
- National infrastructure to manage changes
![]() |
Callie Kennedy, Associate Director of Supply Chain, HCA Healthcare |
9:40- 10:30
NEARSHORING – PANEL DISCUSSION
Managing global trends of onshoring and deglobalization post pandemic
View Session Details
- US move to buying onshore with limited build capability
- Developing infrastructure to move manufacturing operations
- Time consuming and cost prohibitive nature of onshoring
- Transition to green economy
- Scaling up green technologies domestically
- Mitigating concentration risks with over reliance in certain jurisdictions
- Capitalizing on the move and developing long term capabilities
- US regulations on sourcing in certain jurisdictions
![]() |
Elizabeth Anderson, Senior Director, Supply Chain Lead, JLL |
![]() |
Gonzalo Lopez-Polin, Operations/Supply Chain, American Industrial Partners |
10:30-11:00
Morning refreshment break and networking
11:00- 11:40
CONTRACTS
Reviewing third party controls to mitigate risks and key features to include within a contract
View Session Details
- Filling unknown gaps
- Including unknown variables within contract clauses
- Controls to monitor during onboarding
- Including clauses for cyber insurance
- Ensuring indemnification in the event of a breach or business continuity impact
- Balancing business priorities and risk management
- Including SLA requirements as part of contract
![]() |
Patrick Carr, Supply Chain Director, Pelco Products |
11:40- 12:20
SIOP
Risk and compliance in Sales Inventory & Operations Planning (SIOP)
View Session Details
- Aligning SIOP with strategy
- Align processes, teams, and market offering with the business strategy
- Consider risks and compliance during the alignment process
- Proactive supply chain planning
- Shift from reactive to proactive supply chain planning in SIOP
- Mitigate risks through proactive planning and compliance integration
- Metrics-driven effectiveness
- Evaluate SIOP effectiveness with metrics and data-driven approaches
- Use metrics to identify risks and improve compliance efforts
- Holistic decision-making
- Adopt a balanced, risk-aware decision-making process in SIOP
- Incorporate risk assessments for better compliance adherence
![]() |
Gonzalo Lopez-Polin, Operations/Supply Chain, American Industrial Partners |
12:20-1:20
Lunch break and networking
1:20- 2:00
4TH PARTIES
Fourth parties/subcontracting: Gaining a holistic view of subcontractors to understand full risk landscape
View Session Details
- Keeping track of third party vendors and identifying critical fourth parties
- Gaining control of fourth party oversight
- Monitoring capabilities beyond third parties
- Understanding full subcontracting ecosystem
- Getting sufficient information for due diligence on subcontracting
- Tracking percentage of a single project outsourced to fourth parties
- Identifying critical supply chain
![]() |
Anit Banerjee, Third Party Risk Officer – Legal Risk Management, Meta |
2:00- 2:50
ESG – PANEL DISCUSSION
Reviewing ESG aspects across supply chains to understand impacts and considerations beyond environmental
View Session Details
- Mitigating the impact of supply chains on the environment
- Ensuring sustainability of supply chains
- Understanding environmental impacts at all stages
- Balancing higher costs and sustainability
- Customer support in decarbonizing and creating a greener economy
- Progress of global organizations regulated across jurisdictions
- Monitoring supply chain for social challenges
- Tracking modern slavery and child labor
- Updating policies in line with ESG requirements
![]() |
Kim Bach Vu, Sr Manager, Supply Chain Responsibility, Applied Materials |
![]() |
Rhea Rakshit, Senior Director of Product Management, Supply Chain & Trade Compliance, Sayari |
![]() |
Ken Wolckenhauer, VP Vendor Management, Nordea |
2:50-3:20
Afternoon refreshment break
3:20- 4:00
HUMAN TRAFFICKING
Mitigating human trafficking and exploitation risk exposure
View Session Details
- Incorporating third party data provided through public private partnerships
- Overlapping datasets as a means of resolving entities
- Monitoring for social, political unrest and failed nation states to minimize intersection with exploitation
- Incorporate monitoring, tracking trends of missing persons globally to harden supply chains to exploitation
- Pig butchering “the most egregious form of Human Rights violations”
![]() |
Christopher Kemp, Senior Operations Manager, Anti-Human Trafficking Intelligence Initiative |
4:00- 4:40
AI
Leveraging advanced technology to gain insight across the supply chain whilst understanding potential new risks
View Session Details
- Uses of AI for supply chain and third party risk
- Analyzing and leveraging data and outputs
- Recruiting or retraining to effectively leverage AI tools
- Impact of Covid-19 on AI outputs with skewed historical input
- Managing retrospective tools
- Balancing AI as an enabler and a risk
- Risks with ChatGPT public information
- Building capabilities to enhance decision support and analytics intelligence
- Data privacy concerns with access to online tools
4:40-4:50
Chair’s closing remarks
4:50
End of End of event
*All views and opinions expressed are those of the individual and not of the associated organization.
Sponsors
Co-sponsors
Associate sponsors
Content and media partners
Would your organization like to partner with us on this event?
To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact sales@cefpro.com or call us on +1 888 677 7007 ext. 207 for more information.
Speakers


Elizabeth Anderson
Senior Director, Supply Chain Lead
JLL

Elizabeth Anderson
Biography Coming soon


Lacrecia Billings
Interim Vice President, Supply Chain Acceleration
Walmart

Lacrecia Billings
I began my Walmart career in 2021 as a temporary associate. Over the course of my 11 years with the company, I have worked across Shared Services, Store Operations, Human Resources, and Supply Chain. Walmart has given me the opportunity to develop a wide variety of skills and experiences. This includes product and program management, process and product automation, process engineering, and strategic transformation and execution.
Some of my accomplishments include designing an improved inventory management process and system for the fresh areas of the business (Meat and Produce merchandise), developing a shelf-guided work app for store associates to maintain shelf item compliance, and establishing documented standard operating procedures and training programs for the Supply Chain operation.
I am proud to have 4 Walmart patents and I feel honored to get the opportunity to contribute to our customer’s shopping experience on a day-to-day basis.


Anit Banerjee
Third Party Risk Officer – Legal Risk Management
Meta

Anit Banerjee
Anit has considerable amount of experience working with the European, APAC and US regulators on matters related to Data Privacy, Cross-Border Data Transfer, Anti Money Laundering & Terrorist Financing, Cyber Security (Governance), Business Continuity, Third-Party Risk Management (Program & Cybersecurity) and Regulatory Compliance. He has helped develop end-to-end Third-Party/Fourth party Risk Management Programs to help institutions get a deeper understanding of their supplier/vendor overall risk posture that could potentially impact from an enterprise-level and help mitigate risks. Anit has significant years of experience in non-financial risk management including risk quantification, onsite audits and advising on Consent Orders-MRA’s and working on third-party projects involving one thousand to fifty-five thousand suppliers/vendors with a global footprint.
From an industry perspective, Anit has worked with large-sized global Financial Institutions, Fintech giants and Semiconductor Manufacturing (Hi-Tech) across several countries. Currently, Anit oversees the Third-Party Risk Management program from more than a dozen risk pillars under Legal Risk Management (SLOD) at Meta. Anit loves to review US and Foreign regulations on matters related to Cybersecurity, Data Privacy, AML and Crypto.
Anit holds a JD from Massachusetts School of Law, Massachusetts, and plans to appear for the Massachusetts Bar Exam in July 2023.


Kim Bach Vu
Sr Manager, Supply Chain Responsibility
Applied Materials

Kim Bach Vu
Biography Coming soon


Cindy Chadwick
Supplier Cyber Security Risk & Assurance Principal Architect
GSK

Cindy Chadwick
Cindy holds a Master of Science in Information Security and has over 10 years’ experience in cyber, including security risk management. She has built two cyber GRC programs from the ground up, one in a healthcare-related state agency and one in a Fortune 500 retail and manufacturing company. She believes integrating cybersecurity into business processes and objectives is, at its essence, an ongoing conversation. In this regard, Cindy is known for her ability to present cyber risks in terms that require no technical knowledge on the part of business stakeholders for them to rapidly apprehend the company’s risks presented by technical threats and vulnerabilities.


Patrick Carr
Supply Chain Director
Pelco Products

Patrick Carr
Patrick Carr is speaking at Third Party Risk Management USA Cross Industry 2022


Phani Dasari
former Head of Business Security Officer
TikTok

Phani Dasari
Phani Dasari is the Head, Business Security Partner Office, Americas, TIKTOK.
Phani is a security executive with the strategic vision and financial discipline to secure organizations and protect their businesses, offering more than 16 plus years of diversified expertise in Governance, Risk, Compliance, Client Security Management, Third Party Risk Management, Data Privacy, Regulatory Compliance, IT auditing, Product Security and Project Management. Effective communicator, skilled at gaining client confidence and business buy into security initiatives. Skilled in all aspects of security lifecycle, including but not limited to building security programs from scratch and taking existing programs through maturity curve. Expert at identifying and clarifying information security and technology risks and coordinating remediation efforts. Creative problem solver and strategic decision maker in fast-paced fluid environments.
At TIKTOK, Phani is responsible for delivering senior-level security, risk, and privacy enforcement management to identify risks and implement processes to reduce/eliminate those risks. He is accountable for ensuring the delivery of security services, dedicated security functions according to the business needs, risk level, and plans associated with the assigned business units and products they are responsible for – assigned by the Global Security Organization. In his capacity as the Head, Security Business Partner Office, he serves as a liaison between TikTok and Global Security to ensure Business Units (BU’s) receive the security services required, Global Security gets clear and direct input into BU’s. He makes decisions about the interpretation of the Security Program and how best to apply it to the respective business unit situations to ensure TikTok is not taking on unacceptable risk or weakening the company’s security posture. He maintains a strong working relationship with other GSO groups to partner in the implementation of technical programs that deliver best in class security.
Prior to the above job Phani was responsible for the strategic direction and overall execution of the Global Third Party and M&A Risk Management program at ADP; responsibilities include leadership of diverse & geographically spread-out teams of senior leaders, assessors, consultants and oversee program activities to ensure effective risk management and mitigation throughout the third-party life cycle.
Prior to the above job, Phani was Global VP, Client Security Management Office and was responsible for creating ADP’s Trusted Client Experience in all aspects of client security lifecycle interactions and driving the client security assurance program.
Prior to joining ADP, Phani was a member of EMC Corporation; he worked as Client Security Advocate and Senior Risk Analyst. Before joining the EMC, Phani was a research assistant at The University of Findlay, OHIO and did project and content management for few years as well.
Phani holds an undergraduate degree in Statistics and Computer Science and a Master’s Degree in Computer Science from Andhra University, India. He did his MBA from The University of Findlay, OHIO. He is also a Certified Project Management Professional (PMP), a Certified Information Security Auditor (CISA), Certified Information Privacy Professional (CIPP) and an ISO Security Lead Auditor (ISO 27001 Security Lead Auditor). Risk Management for Corporate Leaders (Harvard Business School, USA) Advanced Crisis Leadership (Harvard Kennedy School of Government, USA)
In addition, Phani has been an active participant at a number of Community-based events including but not limited to the following:
– Stay Safe Online Presentations at Local Schools/Businesses
– Security/Privacy Awareness Presentations at Bring Your Child To Work, Habitat for Humanity


Elizabeth Dunsmoor
TPRM Principal
Shared Assessments

Elizabeth Dunsmoor
Elizabeth Dunsmoor recently joined Shared Assessments as a TPRM Principal after 15 years as a TPRM practitioner. She has experience designing holistic programs and delivering assessment work within the cybersecurity, financial services, manufacturing, and healthcare sectors. With a proven ability to oversee and execute long-term operational strategies and methodologies for risk programs, Elizabeth is proficient in a variety of management actions including translating strategies into measurable plans, partnering with Procurement, corporate teams, and firm leaders to develop a pipeline of cross-functional leaders within the risk management function. She now provides training and guidance to business leaders to ensure understanding of program requirements, third-party capabilities, and performance expectations.


Eric Elbel
Senior Manager, Supply Chain Logistics
AVROBIO

Eric Elbel
Over the course of a 20 year Supply Chain and Logistics career, Eric has worked as a Cold Chain and Dangerous Goods subject matter expert for a diverse range of companies. His background includes work in Medical Devices, Vaccine Manufacturing, Cell and Gene Therapies, and within the 3PL/Specialty Logistics Provider fields. His areas of expertise include packaging and monitoring device qualification and management, international supply chain management, and clinical trial supply chain management.


Dov Goldman
VP Risk Strategy
Panorays

Dov Goldman
Dov has years of experience in the third-party risk and compliance field, as well as a long history as a serial entrepreneur, software and network engineer. Dov focuses on the evolving best practices and industry standards in third-party management and regulatory compliance. Previously, Dov was VP of innovation at Opus, director of product marketing at Navigant, and founder and CEO of Cognet Corp and Dynalog Technologies. Dov has spoken at industry events around the world and has been quoted in numerous industry press articles, as well as The Wall Street Journal, about information security and privacy.


Alexander Heid
Fellow, VP of Threat Intelligence
SecurityScorecard

Alexander Heid
Alexander Heid is Chief Research & Development Officer at SecurityScorecard, and is Co-founder and President/CEO of HackMiami. HackMiami is the premier resource in South Florida for highly skilled hackers that specialize in vulnerability analysis, penetration testing, digital forensics, and all manner of information technology and security.His specialties include digital crime intelligence analysis, application security auditing, network vulnerability analysis, penetration testing, and malware reversal. Much of the research he has participated in is frequently featured at national industry conferences and within mainstream media.Previously, Heid served as Chapter Chair for South Florida OWASP, and worked within the financial industry. Heid was also a founding member of the Prolexic Technologies PLXSERT team.In 2007, Alexander Heid founded the Information Security Services, Inc. a full service information technology and information consulting firm.Heid attended Florida International University. He is a regular organizer and featured speaker at industry conferences.


Christopher Kemp
Senior Operations Manager
Anti-Human Trafficking Intelligence Initiative

Christopher Kemp
Christopher is a seasoned security professional with background and experience operating in austere overseas environments and permissive environments. Christopher brings with him knowledge and experience employing intelligence to sharpen training and operational success, team building, leadership, and management skills.


Callie Kennedy
Associate Director of Supply Chain
HCA Healthcare

Callie Kennedy
Biography coming soon


Tausif Khan
Associate Director, Third Party Risk
DTCC

Tausif Khan
Tausif leads the Third Party Risk Governance and Reporting group of DTCC. He is responsible for managing the Third Party Risk Management framework and lifecycle specifically focusing on Critical Third Parties, firmwide awareness of responsibilities, due diligence of 4th/nth parties, governance for monitoring and oversight, and regulatory responses. Tausif holds a BS in Finance from the University of South Florida and is currently pursuing his MS in Cybersecurity from Virginia Tech.


Gonzalo Lopez-Polin
Operations/Supply Chain
American Industrial Partners

Gonzalo Lopez-Polin
Gonzalo is an International Supply Chain Executive with over 15 years’ experience managing strategic projects and teams across North America, Europe, Africa and LATAM. His experience includes aligning the company’s supply chain with its value proposition, optimizing product and service offering, implementing S&OP / IBP, streamlining processes and organizations with up to $5 billion in revenue, growing strategic alliances through M&A integration, and managing 160 employees. With a successful track record of turning around low performing organizations, delivering profitable growth and being customer focused, Gonzalo is well known for creative problem solving, driving change, and strong analytical skills.



Matthew Moog
Matthew Moog serves as the General Manager, Third-Party Risk at OneTrust, the category-defining enterprise platform to operationalize trust. In his role, Matthew advises companies throughout their third-party risk management implementations to help meet requirements relating to relevant standards, frameworks, and laws. Prior to joining OneTrust, Matthew spent 18 years at EY where he led their Global Third-party Risk offering for Financial Services and their Third-party Risk Managed Service offering for the Americas. Moog is a CISA and has a BS in Management Information systems from Rensselaer Polytechnic Institute in Troy, NY.
Matthew Moog
General Manager, Third-Party Risk Management
OneTrust


Robert Peters
Manager of Supply Chain Implementation
HealthTrust Performance Group

Robert Peters
Biography coming soon

Sara Ricci
Information Risk Governance and Resilience Executive
HBC

Sara Ricci
Sara Ricci is an accomplished executive with a proven track record in global leadership roles, building new capabilities and enhancing organizational resilience. She is experienced in Risk Management and Technology Enablement in highly regulated financial and energy sectors. Sara excels at building trust and credibility with executives, clearly communicating risk concepts and strategies in non-technical terms to help drive business results.
As a Risk and Resilience leader, Sara leverages experience as Head of Information Risk Governance and Resilience at HBC, senior leadership roles at HCL Technologies, New York Power Authority, JP Morgan Chase, Citi, Bank of America and UBS, as well as collaboration in industry initiatives to provide guidance for maturing Risk and Resilience programs.
MBA (Finance and Management), CRISC CDPSE CBCP HSEEP SCR


Rhea Rakshit
Senior Director of Product Management, Supply Chain & Trade Compliance
Sayari

Rhea Rakshit
Biography coming soon.


Michael Rivas
Head of Third Party
DTCC

Michael Rivas
Biography coming soon


Jeffrey Wheatman
Cyber Risk Evangelist
Black Kite

Jeffrey Wheatman
A strategic thought leader with extensive expertise in security and cyber risk management, Jeffrey Wheatman is regarded as a foremost expert in guiding public sector clients and Fortune 500 companies in connection with their cybersecurity and risk management programs. Jeffrey’s history of working with clients to plan, grow, and transform their cyber risk management programs has been instrumental in ensuring organizations’ continued viability and health as they define short- and long-term expansion plans. Under Jeffrey’s guidance, board and C-level leaders are fortified with the best practice solutions to realize exceptional performance outcomes.
In his current capacity as SVP, Cyber Risk Evangelist at Black Kite, Jeffrey has been tasked with raising awareness of the enterprise-wide risk impacts of third party risk, both in the digital and traditional supply chain and supporting the strategic vision of the executive leadership team and investors.
Most recently, Jeffrey acted as a VP, Advisor with Gartner, the global strategic advisory firm, where he worked with clients to build and improve their security programs, assess risk, focus on reporting on program status, metrics, performance management, stakeholder engagement, executive communication, and bridging the connection between technology and security risk. Jeffrey guided leaders in selecting frameworks to run cyber programs in compliance with regulatory requirements and expectations of auditors and partners.
For four years, Jeffrey served as the Chair of the North America Security and Risk Management Summit, Gartner’s 2nd largest conference with 4000+ annual attendees. As part of this high-profile effort, he guided the creation of the conference agenda comprising more than 150 presentations, 20 case studies, external keynote speakers, and 50 vendor sessions.


Ken Wolckenhauer
VP Vendor Management
Nordea

Ken Woclkenhauer
Ken Wolckenhauer is the Head of Vendor Management at Nordea Bank’s New York branch. Leading up to this position, Ken was as a subject matter expert, trainer, solutions provider, and consultant for FIS, the world’s largest global provider dedicated to banking and payments technologies. With FIS, Ken specialized in financial industry regulatory risk and compliance, mostly in the area of anti-money laundering and watchlist compliance.
Nordea Bank leveraged Ken’s risk and compliance knowledge to build out the vendor management program for the New York branch, developing a program that would properly manage risk as well as gaining acceptance to the US regulators. The success of the US program is now being used to advise Nordea’s European branches on enhancements to its TPRM program. Ken is a graduate of Bucknell University and is a Certified Anti-Money Laundering Specialist.
*All views and opinions expressed are those of the individual and not of the associated organization.
Sponsors
Co-sponsors

Mirato
Traditional TPRM solutions automate workflow; Mirato automates the manual work.
Mirato’s TPRM Intelligence Platform is an advanced Artificial Intelligence solution created and trained specifically to complete your TPRM assessments using your unique risk model and the information you already collect. The platform validates your controls with evidence and a complete audit trail.
Mirato’s Questionnaire Killer uses the same advanced technology to automatically pre-answer your unique due diligence questionnaires for your third parties and validate the answers with evidence for you. This reduces time, cost, pain, and effort for everyone.
Mirato makes no decisions but enables better human decisions faster.

OneTrust
As society redefines risk and opportunity, OneTrust empowers tomorrow’s leaders to succeed through trust and impact with the Trust Intelligence Platform. The market-defining Trust Intelligence Platform from OneTrust connects privacy, GRC, ethics, and ESG teams, data, and processes, so all companies can collaborate seamlessly and put trust at the center of their operations and culture by unlocking their value and potential to thrive by doing what’s good for people and the planet.

Security Scorecard
SecurityScorecard is the global leader in cybersecurity ratings and the only service with millions of organizations continuously rated. Our mission is to make the world a safer place by transforming the way organizations understand, improve, and communicate cybersecurity risk to their boards, employees, and vendors.
SecurityScorecard’s patented rating technology is used by thousands of organizations for enterprise cyber risk management, third-party risk management, board reporting, cyber insurance underwriting, and regulatory oversight to meet compliance mandates; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their externally facing digital-footprint.
SecurityScorecard is the only provider of instant risk ratings that automatically map to vendor cybersecurity questionnaires and the largest ecosystem of integrations, providing a true 360-degree view of risk. But we don’t stop there. Through a customer-centric, solution-based commitment to our partners, we are transforming the digital landscape building a path toward resilience.
Associate sponsor

Back Kite
Black Kite is disrupting third-party risk management practices by providing security experts with the industry’s most accurate and comprehensive cyber intelligence, resulting in unparalleled visibility into vendor risk. The award-winning platform pushes the limits on predictive insights, delivering the highest quality intelligence to help organizations make better risk decisions.

Panorays
Panorays offers an automated, comprehensive and easy-to-use third-party security platform that manages the whole process from inherent to residual risk, remediation and ongoing monitoring. Unlike other solution providers,
Panorays combines automated, dynamic security questionnaires with external attack surface assessments and business context to provide organizations with a rapid, accurate view of supplier cyber risk. It is the only such platform that automates, accelerates and scales customers’ third-party security evaluation and management process, enabling easy collaboration and communication between companies and suppliers, resulting in efficient and effective risk remediation in alignment with a company’s security policies and risk appetite.

Sayari
Sayari provides global corporate transparency and supply chain risk identification for government and industry. Its commercial risk intelligence software harvests comprehensive corporate and trade data from more than 250 jurisdictions worldwide and surfaces previously hidden risk insights in an intuitive network analysis platform.
Since its founding in 2015, Sayari has earned the trust of top financial institutions, Fortune 100 corporations, and government agencies, securing a $40M Series C in 2021. Sayari is headquartered in Washington, D.C., and its solutions are used by thousands of frontline analysts in 35 countries.
To learn how Sayari powers safer global commerce, please visit sayari.com.
Content and media partners

CeFPro Connect
CeFPro Connect aims to connect industry experts through thought leadership content and timely news, written for the industry, by the industry. Gain unlimited access to CeFPro’s unparalleled library of resources including iNFRont Magazine, market intelligence reports, filmed presentations, insights Q&A’s, and much more. Sign up for free.

iNFRont Magazine
iNFRont Magazine is a unique publication providing regular insight on the operational and non-financial risk (NFR) sector. Featuring contributions provided by leading industry figures and experts from around the world, iNFRont Magazine touches on the most critical themes and challenges currently affecting financial professionals. Available to download for free.
Would your organization like to partner with us?
To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact sales@cefpro.com or call us on +1 888 677 7007 for more information.
Venue & FAQs
The Westin Nashville
807 Clark Place
Nashville
TN 37203
We have secured a preferential rate of $329++ per room, per night, for delegates to stay at the venue. This offer is only valid until October 19, so book on early to avoid missing out before prices increase.
With the conference taking place early in the week, this is the perfect opportunity to spend the weekend in Nashville and soak in the sights and sounds of Music City!
The Westin is located within walking distance to Broadway in the city’s downtown district, with plenty to do to keep you occupied. From music and culture, to food and shopping, must-see attractions include the Music City Center and Music Row. Alternatively, retire to the rooftop bar and pool after a busy 2-days at the conference!

Frequently Asked Questions
Can I share my thought leadership at Third Party & Supply Chain Risk USA: Cross Sector?
Will there be opportunities to network with other attendees?
- Breakfast, lunch and refreshment breaks
- Drinks reception at the end of day-1
- Q&As, panel discussions, and audience participation technology
What is included within the registration fee?
Where can I find the Congress documentation and speaker presentations?
* Please note that our speakers often have to gain permission from their relevant compliance departments to release their presentations. On rare occasions compliance may not allow presentations to be distributed.
Will breakfast, lunch and refreshment be provided?
Are there any rules on dress code?
Are CPE Credits available?
Register
You’re invited to join us at Third Party & Supply Chain Risk USA alongside 150+ industry professionals and subject matter experts as you explore current developments and challenges within the space across industries.
On top of this, we are offering delegates to upgrade their conference experience with our VIP pass which will provide you exclusive access to our post-event reception hosted by CeFPro, inclusive of drinks, dinner, and entertainment.
Need assistance with your registration? Get in touch with us via email below, or call us on +1 888 677 7007.

Secure your place today
For end-user corporations and practitioners only, subject to approval by CeFPro. Apply below to find out if you qualify.
Enhance your experience and join us for a post-event reception inclusive of drinks, dinner, and entertainment!
Build valuable business relationships as you meet and greet delegates and key decision makers.
*CeFPro have final approval over all registrations and rates charged. Once you have registered your place, a member of the CeFPro Events team will get back to you to confirm your registration, or issue an invoice with the correct payment amount. The VIP upgrade is only available to end-user delegates.
Terms and conditions apply.