Security Begins at Procurement with Jessie Schofer
Jul 22, 2026 · 37m
Summary
Richard Campbell interviews Jesse Schofer, co-founder of SecureList, about the critical need for security in tech procurement. They discuss how HR departments often rush AI adoption without proper vetting, leading to significant data risks. Schofer reveals that many vendors fail basic security checks, emphasizing that continuous monitoring and rigorous due diligence are essential to prevent supply chain attacks and ensure compliance.
Topics discussed
Introduction and guest Jesse Schofer background
HR's evolving role in AI and security procurement
GDPR, privacy, and the risks of vendor data exposure
Case study: Critical vulnerabilities in HR tech vendors
Marketing tracking violations and supply chain liability
The explosion of new SaaS vendors and trust signals
Curating verified vendor lists and security maturity
Sponsor break: Power Platform Community Conference
Origin of SecureList and AI-driven code risks
Leaked credentials and the cost of ignoring security
Continuous monitoring and re-evaluating vendor risk
Automated failover and proactive risk mitigation
Transparency, accountability, and concluding thoughts
Listen ad-free on Castria