Quantifying cyber risk across subsidiaries and vendors
A single weak link, whether a vendor, a supplier, or a subsidiary, can cause data breaches, regulatory penalties, and lasting reputational harm. Tools focused on the attack surface are often too slow and siloed to protect today’s extended enterprise, and many organizations monitor only a handful of critical partners while the complex middle layer, where many modern breaches originate, goes overlooked.
In this session, Resilience experts Chuck Norton and Sevan Sarkhoshian, Senior Technical Security Advisors, are joined by Jordan Bacher, Senior Product Manager, and Veda Kumarjiguda, Senior Product Marketing Manager. They show how Resilience Arc for multi-entity risk assessment and Resilience Hive for vendor risk management provide a financially quantified, unified view of cyber risk across the value chain, with a live demo.
The session covers how to define and quantify ecosystem risk, navigate subsidiary challenges like decentralized governance and M&A integration, strengthen the vendor risk lifecycle from due diligence to offboarding, and translate findings into financial terms that support enterprise risk management.
About Speakers

Charles “Chuck” D. Norton is a Senior Technical Security Advisor at Resilience. He is a seasoned enterprise technology leader with nearly two decades of expertise, specializing in implementing robust security frameworks and governance models that align risk mitigation with business objectives. Throughout his career, Norton has leveraged extensive experience in systems architecture and policy development to partner with stakeholders and build resilient security programs.
Prior to his current role at Resilience, Norton held security leadership positions at Western Michigan University and across various local government organizations. He holds an MBA from Western Governors University, a B.S. from Western Michigan University, and CISSP certification.

Sevan Sarkhoshian is a Senior Technical Security Advisor at Resilience with over 8 years of experience designing, implementing, and managing comprehensive cybersecurity and IT solutions across multifaceted environments. He excels at building robust cybersecurity programs that align with business goals, mitigate risks, and ensure regulatory compliance. Previously, Sevan spent 6 years in various roles, including Senior Security Engineer, Security and Systems Engineer, and IT Support Specialist. He holds a Bachelor’s degree in Finance from California State University, Northridge, and CISSP, CISM, CySA+, Security+, eJPT certifications.

Veda Kumarjiguda is a Senior Product Marketing Manager at Resilience with more than a decade of experience in product marketing management and client success. Prior to her current role, She held roles at Mendel.ai, Salesforce, and RebelMail. She holds a BA in English and Economics from Barnard College.
Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.
