
Our Cybersecurity Mission · 2026-07-22 · 22 min
In this episode, host Allie Krings sits down with Bob Welch, an auditor at KirkpatrickPrice with a background spanning large national accounting firms, banks, and risk and compliance work, to break down vendor management - and why it matters more than most organizations realize. What's the difference between vendor management, vendor due diligence, and third-party risk management? (Spoiler: not much.) Bob walks through how to categorize your vendors, what to look for when reviewing their audit reports, and why the CrowdStrike incident is a perfect example of why annual re-evaluations aren't optional. He also shares a real story of a vendor that had no documentation, no audit reports, and was storing client data overseas - and why that was an immediate deal-breaker. Whether you're just starting to think about vendor risk or looking to tighten up a program you already have, this conversation is a practical reminder that if it's your data, it's your problem. At KirkpatrickPrice, we're on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance.