
Hosted by CASME
Listed under Business
Insights and conversation about the latest issues in indirect procurement, bought to you by CASME, the global membership community for procurement professionals.
37 episodes · publishes occasionally · latest 2026-07-06 · ~34 min/episode
Rank
#1210
Substance
72.5
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#1210 of 6203
Substance
Top 19%
outscores 81% of the index
Pondering Procurement ranks #1210 on The B2B Podcast Index with a substance score of 72.5 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and insight density. Ben has legitimate credentials - 5 years of cybersecurity experience, a recent CISSP certification (master's-level equivalent), and Fortune 500 exposure across retail, manufacturing, government, and financial sectors. He has worked on multiple third-party security teams and understands the procurement-security interface from practical experience. However, his role and company are not clearly stated, and he comes across more as a mid-level practitioner/educator than a senior executive or founder who has personally led large-scale transformations. He is competent but not exceptional in terms of seniority or demonstrated business impact.
Averaged across 2 recently scored episodes, with cited evidence.
The episode delivers moderately useful information about integrating cybersecurity into procurement processes, with several concrete frameworks (supplier tiering, contractual hardening, ISO/SOC2 standards) that a procurement professional would find actionable. However, much of the content relies on general principles rather than novel insights - the core message that procurement should collaborate with security on contracts early in the cycle is straightforward. The guest repeats key points multiple times (contract importance, early involvement, communication) which reduces density.
“So one of the reasons why procurement needs to get more involved is because one of the best things that we can do is harden contracts. So we need to make sure that security language is within contracts”
“The earlier we can be involved at the start, the less hassle it is down the line. If you have it in the contract, you understand the criticality of the supplier.”
The framing of procurement as a cybersecurity control is timely but not particularly novel - the concept has been gaining traction in security circles for several years. The host and guest largely rehearse established best practices (ISO 27001 certification, SOC2 compliance, access control, incident response plans) that are documented in widely available frameworks like NIST and OWASP. The 'back door' analogy and 'would it be on the Sunday Times' heuristic are mnemonic devices rather than original thinking. No contrarian arguments or first-principles reasoning are presented.
“It's like if you were to try and get into someone's house, you may not go through the front door, you might go through the back door and it's because the back door is usually unlocked.”
“What would happen if it's on the newspaper? Um, would that be a massive impact?”
Ben has legitimate credentials - 5 years of cybersecurity experience, a recent CISSP certification (master's-level equivalent), and Fortune 500 exposure across retail, manufacturing, government, and financial sectors. He has worked on multiple third-party security teams and understands the procurement-security interface from practical experience. However, his role and company are not clearly stated, and he comes across more as a mid-level practitioner/educator than a senior executive or founder who has personally led large-scale transformations. He is competent but not exceptional in terms of seniority or demonstrated business impact.
“So my name's Ben. I've worked in cybersecurity for the last five years and I focus very much on third party security.”
“Yeah, so I've just passed my CISSP exam and that's the equivalent of a master's in cybersecurity. So you need 5 years experience to get a SISSP certification”
The episode lacks concrete data, case studies with numbers, and specific examples that would anchor recommendations. The M&S breach is mentioned briefly but not explored with detail (timeline, cost, specific controls that failed). Accreditations (ISO 27001, SOC2, Cyber Essentials) are named but not compared quantitatively. The OWASP top 10 and NIST frameworks are referenced generically. Most claims are illustrated through principles rather than evidence: no metrics on breach impact, no cost-benefit analysis of early security involvement, no actual contract language examples despite discussion of 'contractual hardening.' The AWS example (4-hour outage) lacks financial impact detail.
“So if you look at M and S, their breach was a third party supplier. They had poor security controls in place. They were then able to actually access the backend M and S website and then shut down the website.”
“there's one from IBM, there's one from Verizon and this basically tells you what is happening right now in terms of how are attackers trying to get into certain systems”
Graham is a capable host who poses logical follow-up questions (e.g., 'Can you be more specific about what's embedded in contracts?', 'Where should we start?') and demonstrates genuine listening by referencing Ben's points. However, the conversation is largely non-adversarial and interview-like rather than investigative. Graham rarely challenges claims or asks for nuance - when Ben says security is 70% communication, Graham doesn't probe what evidence supports that or whether it's sector-dependent. The tone is collaborative and appreciative rather than critical. Ben is given substantial time to talk and is rarely interrupted, which is good for depth but reduces interrogation of soft claims. The conversation lacks productive friction or counterargument.
“So let's make sure I fully understand, Ben. So when procurement is engaging with a new supplier, talk through more around the likes of those cyber risks that ah, could be introduced to the organization.”
“Can you be more specific? What are you looking to have embedded within a, uh, contract?”
2 periods tracked.
2 scored on substance · 37 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/pondering-procurement" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/pondering-procurement/badge.svg" alt="Ranked #114 on The B2B Podcast Index" width="360" height="136" />
</a>Track Pondering Procurement's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.