SecurityScorecard Youngryul Pak Senior Solutions Architect
As supply-chain-focused cyberattacks rise, visibility into external assets has become the starting point of security. The rapid spread of AI agents, cloud, and SaaS has turned unknown internet-exposed assets and third-/fourth-party risk into a new attack surface. This talk examines why traditional, periodic and manual third-party risk management (TPRM) has reached its limits, and explores the shift toward a threat-informed approach that combines internet-scale scanning and fingerprinting-based External Attack Surface Management (EASM/ASM) with threat intelligence. Using public examples, it covers external exposure discovery, shadow-AI risk, and exploitability-based vulnerability prioritization, and offers practical takeaways for building continuous monitoring programs in the Korean context (e.g., ISMS-P).
Korean
English
Chinese
Japanese


