Transcript

Dark Rhiino Security:

Hello everyone. Welcome to the show. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential.

Today, we have another awesome guest joining us from halfway around the world. But before I introduce her, I want to remind you to please hit the like and subscribe button. The algorithms are fairly strict about this, and if you want us to keep bringing you great content, just hit those buttons. It really helps us out. Also, follow us on Spotify or wherever you get your podcasts.

With that, I am honored to introduce our guest this week, Sara Ricci. Sara is a cybersecurity and enterprise risk executive with deep expertise in operational resilience, IT risk, and third-party risk management, which we all know has become a hot topic recently. She advises C-suite leaders on building stronger, more resilient organizations in the ever-changing landscape of cybersecurity and operational threats. She is a frequent global speaker and mentor through the Executive Women’s Forum and the Lyft program, and is known for her cross-disciplinary approach to risk—combining cybersecurity, business continuity, privacy, and sustainability to help organizations stay resilient. Sara, thank you for joining us. Honored to have you here.

Sara Ricci:

Thank you, Manoj. Thanks for having me.

Dark Rhiino Security:

We’ve got to start with a little bit about your background. Tell us your story and how you ended up here.

Sara Ricci:

My story is fairly simple, but it has taken some interesting turns. I started in technology and have always been at the intersection of business and technology. I went through many different industries. I essentially grew up in banking, spending most of my career with institutions like UBS, Bank of America, Citi, and JPMorgan.

Then I moved into the power industry, which is also highly regulated, much like banking. That was a great experience, especially learning on the operational technology side while also contributing to IT. In the power industry, OT is king—everything revolves around SCADA systems, power generation, transmission, and so on. IT, while still important, is sometimes less of a focus compared to banking or other industries.

That experience allowed me to build resilience programs and enterprise risk frameworks. After that, I moved into technology services, where I got to see the other side as a provider rather than a client. I then transitioned into retail, which is completely different from the other sectors. There, I was responsible for cybersecurity, building out governance, risk, and compliance programs, as well as resilience programs.

When I say resilience, I don’t just mean cyber resilience—I mean enterprise resilience, including business continuity. So overall, it’s been a great journey across industries and risk disciplines, always staying close to emerging technologies, managing risks around them, and helping organizations stay ahead rather than reactive. And honestly, I’ve just enjoyed the ride.

Dark Rhiino Security:

Wow, that’s quite a journey across a number of industries, and they’re all so different. We know the financial sector is often regarded as one of the most mature sectors from a cybersecurity and resilience perspective. Power generation also takes it seriously, though perhaps not always at the same maturity level. And retail is something I’m less familiar with personally.

Across these industries, how would you characterize resilience? Is it the same formula across all of them, or are there fundamental differences?

Sara Ricci:

That’s a great question. Banking definitely has the highest level of maturity, largely because they are moving money constantly and are heavily regulated. Organizations like SIFMA have also contributed to industry-wide testing and standards.

When we talk about the energy sector being less mature, it’s really more about the IT side. The operational technology side, including SCADA systems, is actually very mature and regulated through organizations like NERC and FERC. Those systems are well protected. However, IT historically lagged because there was a belief that systems were isolated or air-gapped. Over time, that gap has narrowed significantly.

So yes, maturity varies, but best practices can be transferred. There isn’t a one-size-fits-all solution, even within the same industry. However, frameworks like ISO 22301 for business resilience provide a strong starting point. You still build similar structures—steering committees, working groups, business impact analyses, recovery objectives, and dependency mapping.

The approach is consistent, but execution must be tailored to each organization.

Dark Rhiino Security:

When you look at stakeholders across these industries, is there something that makes executive teams more open to adopting resilience strategies?

Sara Ricci:

Buy-in is critical. You need to build awareness and communicate in business terms, not technical language. Executives care about impact—financial loss, reputational damage, regulatory exposure.

A business impact analysis really helps, because it shows what happens if a critical function is lost. When leaders understand that impact, they become much more engaged. Ultimately, resilience becomes a competitive advantage rather than just a compliance requirement.

Dark Rhiino Security:

Let’s clarify something for our audience. What’s the difference between cybersecurity and resilience?

Sara Ricci:

Cybersecurity is about protection—primarily focused on confidentiality, integrity, and availability, the CIA triad. Resilience is broader. It’s about ensuring the business continues to operate even when something goes wrong.

Cybersecurity is one component of resilience. Resilience includes business continuity, disaster recovery, crisis management, third-party risk, and cyber resilience. The key difference is protection versus impact. Cybersecurity protects systems, while resilience ensures the business survives disruptions.

Dark Rhiino Security:

What about things like business email compromise or social engineering attacks that don’t show up in a SOC?

Sara Ricci:

That’s where people and culture come in. Not everything can be detected by tools. Employees need to be trained to recognize threats and report anomalies.

Security is everyone’s responsibility, not just the CISO’s. Awareness programs, continuous training, and a strong reporting culture are essential. Leadership behavior also matters—culture starts at the top.

Dark Rhiino Security:

Let’s talk about third-party risk. What’s your approach there?

Sara Ricci:

Third-party risk is significant. First, you need visibility—you have to know who your vendors are. Then you tier them based on risk, considering factors like data sensitivity, access, and criticality.

You focus more on high-risk vendors and assess them regularly. Tools like SOC 2 reports, penetration testing, and security questionnaires help. You also need to think about fourth-party risk, because your vendors rely on other vendors.

And it’s important to treat vendors as partners, not just suppliers. That helps with transparency and cooperation.

Dark Rhiino Security:

As I listen to you, I’m thinking about aviation. There’s a concept there—what’s the minimum required to keep the plane in the air? Everything else is secondary. Does that apply here?

Sara Ricci:

Absolutely. You need to identify your critical functions—the minimum required to keep the business running. Everything else is secondary.

Resilience is about ensuring those critical functions continue, even during disruption.

Dark Rhiino Security:

We’re just about at time here. Sara, is there anything you’d like to share or plug for our audience?

Sara Ricci:

Yes, I would say keep an eye on developments in AI governance. Look at frameworks like ISO 42001 and the NIST AI Risk Management Framework.

Focus on proactive risk management, not just compliance. Ask what could go wrong, what controls exist, and whether they are effective. Think holistically—cyber, risk, and technology are all interconnected.

I’ll also be speaking at the Risk Americas conference on operational and enterprise risk. And most importantly, keep learning. This field evolves constantly.

Dark Rhiino Security:

Fantastic. Sara, it’s been a pleasure having you here. We didn’t have enough time to get into everything, but we really appreciate your insights. You’re always welcome back.

Sara Ricci:

Thank you very much, Manoj. I really appreciate the opportunity. It was great speaking with you.

Dark Rhiino Security:

Thank you so much.

Chapter Titles:

00:00 Intro
02:29 Our Guest
06:12 Resilience across industry
15:30 Data exists in many forms
21:20 Is you see something, say something
26:20 The attack surface changing with AI
38:30 4th party risk
42:15 Connecting with Sara

About Sara Ricci

Sara Ricci is a cybersecurity and enterprise risk executive with deep expertise in operational resilience, IT risk, and third-party risk management.

As Founder and Head of the Risk & Resilience Practice at Transcend Advisory & Consulting, she advises C-suite leaders on building stronger, more resilient organizations in the face of evolving cyber and operational threats. Sara previously held senior leadership roles at organizations including HCL Technologies, the New York Power Authority, JPMorgan Chase, Citi, Bank of America, and UBS. She has helped shape several influential industry frameworks, including the FSTC Resilience Maturity Model, the C2M2 Cybersecurity Model for the energy sector, and the Govern domain of the NIST Cybersecurity Framework 2.0.

A frequent global speaker and mentor through the Executive Women’s Forum Lift program, Sara is known for her cross-disciplinary approach to risk, combining cybersecurity, business continuity, privacy, and sustainability to help organizations stay resilient.