Program



Track D(Hall D)
2026.8.11 17:00 ~ 17:40
mail share facebook share twitter share linkedin share band share kakao
Supply Chain Security in the AI Era: The Evolution of External Threat Visibility and Threat-Informed Risk Management

SecurityScorecard Youngryul Pak Senior Solutions Architect


As supply-chain-focused cyberattacks rise, visibility into external assets has become the starting point of security. The rapid spread of AI agents, cloud, and SaaS has turned unknown internet-exposed assets and third-/fourth-party risk into a new attack surface. This talk examines why traditional, periodic and manual third-party risk management (TPRM) has reached its limits, and explores the shift toward a threat-informed approach that combines internet-scale scanning and fingerprinting-based External Attack Surface Management (EASM/ASM) with threat intelligence. Using public examples, it covers external exposure discovery, shadow-AI risk, and exploitability-based vulnerability prioritization, and offers practical takeaways for building continuous monitoring programs in the Korean context (e.g., ISMS-P).