← All talks

GRC & TPRM: Securing Big Banks with AI Challenges #shorts

BSides Frankfurt0:30130 viewsPublished 2025-12Watch on YouTube ↗
About this talk
Being a CISO for a vendor security firm? Big banks want you to fix *everything*. Evaluating security via GRC frameworks lacks objective truth. Compliance adds complexity; training models is tough without clear benchmarks. #GRC #TPRM #CISO #VendorSecurity #Cybersecurity
Show transcript [en]

Now, same for GSC and TPRM. I'm a Caesar for vendor security company. Guess how many big banks are asking, hey, can you fix that and this policy and and that can you just looking at the GSC framework have an objective truth if this company is well secured or not? It's hard, right? There's so many different aspects. It's compliance. So it's very hard to train the models based on this because there's no ground truth to understand what is good looking like or