Securing Your Ecosystem with Resilience Arc and Resilience Hive

A single weak link can cause major damage. Learn how to map, quantify, and manage risk across your value chain

3 Min Read

Quantifying cyber risk across subsidiaries and vendors

A single weak link, whether a vendor, a supplier, or a subsidiary, can cause data breaches, regulatory penalties, and lasting reputational harm. Tools focused on the attack surface are often too slow and siloed to protect today’s extended enterprise, and many organizations monitor only a handful of critical partners while the complex middle layer, where many modern breaches originate, goes overlooked.

In this session, Resilience experts Chuck Norton and Sevan Sarkhoshian, Senior Technical Security Advisors, are joined by Jordan Bacher, Senior Product Manager, and Veda Kumarjiguda, Senior Product Marketing Manager. They show how Resilience Arc for multi-entity risk assessment and Resilience Hive for vendor risk management provide a financially quantified, unified view of cyber risk across the value chain, with a live demo.

The session covers how to define and quantify ecosystem risk, navigate subsidiary challenges like decentralized governance and M&A integration, strengthen the vendor risk lifecycle from due diligence to offboarding, and translate findings into financial terms that support enterprise risk management.

About Speakers

Charles “Chuck” D. Norton is a Senior Technical Security Advisor at Resilience. He is a seasoned enterprise technology leader with nearly two decades of expertise, specializing in implementing robust security frameworks and governance models that align risk mitigation with business objectives. Throughout his career, Norton has leveraged extensive experience in systems architecture and policy development to partner with stakeholders and build resilient security programs.

Prior to his current role at Resilience, Norton held security leadership positions at Western Michigan University and across various local government organizations. He holds an MBA from Western Governors University, a B.S. from Western Michigan University, and CISSP certification.

Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.