Conference Description
Key Takeaways
- Single-day summit focused on third-party cyber risk management (TPCRM) for enterprise security and risk professionals
- Sessions cover cyber risk quantification using FAIR and FAIR-CAM frameworks, third-party AI risk, and supply chain vulnerabilities
- Speakers represent Lowe’s, JPMorgan Chase, TIAA, Capital One, McKesson, LogicGate, and Protiviti
- Addresses regulatory impacts including CCPA compliance and breach notification challenges
- Designed for CISOs, security executives, and risk managers from financial services, healthcare, retail, insurance, and technology sectors
About the Event
The TPRM Community Summit 2026 is a single-day, in-person gathering in Charlotte, NC, bringing together professionals working in third-party risk management, cybersecurity, and supply chain risk. Hosted by Black Kite, the summit combines keynotes, panel discussions, networking sessions, and a book signing to facilitate knowledge exchange among practitioners managing vendor and supplier cyber risks.
The program features speakers from major enterprises including Lowe’s, JPMorgan Chase, TIAA, Capital One, and McKesson, alongside representatives from LogicGate and Protiviti. These sessions draw on real-world experience managing third-party risk programs at scale.
Third-Party Cyber Risk and Supply Chain Vulnerabilities
The summit addresses the operational challenges of managing cyber risk across extended supply chains. Sessions examine risk concentration, where organizations face exposure when multiple vendors rely on shared infrastructure or services, creating potential cascading failures. Attendees will explore practical approaches to improving visibility into third-party security postures and reducing exposure to vendor breaches.
Emerging threats receive dedicated attention, with discussions on how threat actors exploit supply chain relationships and how organizations can adapt their risk management practices accordingly.
Cyber Risk Quantification and AI Risk
The agenda includes sessions on cyber risk quantification (CRQ), featuring the FAIR and FAIR-CAM frameworks for measuring and communicating cyber risk in financial terms. These methodologies help risk professionals translate technical vulnerabilities into business impact assessments that inform executive decision-making.
Managing third-party AI risk also features in the program, reflecting growing concerns about vendors deploying AI systems that may introduce new security and compliance considerations into enterprise environments.
Regulatory and Compliance Context
Regulatory developments shape several discussions, with specific attention to CCPA requirements and the challenges organizations face with delayed breach notifications from third parties. These sessions address how compliance obligations intersect with operational risk management practices.
Who Should Attend
The summit targets senior and executive-level professionals responsible for third-party risk, including CISOs, directors of information security, risk managers, and compliance leaders. Attendees typically work in enterprise risk, security, compliance, or procurement functions within financial services, healthcare, retail, insurance, and technology organizations.

