Cybersecurity Best Practices and Risk Management Blog | HITRUST

October at HITRUST: TPRM Insights, Expert Events, and Product Innovations

Written by HITRUST | Oct 2, 2026, 2:03:20 PM

Welcome to October, and to Cybersecurity Awareness Month. At HITRUST, we’re using the month to spotlight modern third-party risk management with new research, insights and expert perspectives, and preview product updates designed to help organizations work more efficiently and confidently. Here’s a look at what’s ahead.

 

Moving From Traditional to Modern TPRM

We’re going to be focusing on third-party risk management (TPRM) over the course of the entire month. Traditional TPRM programs are failing to keep up with the growth and complexity of an organization's vendor and supply chain ecosystem. Vendor populations are expanding, critical dependencies are deepening, and the assurance evidence used to make decisions is often incomplete, inconsistent, or already out of date. We know there is a better way, but the first step in the journey to a modern TPRM program is to recognize the issues on the path and know how to react.

 

More Product Innovation Ahead

Following the recent releases of Report Center and CSF v11.9.0, we’re announcing an exciting new AI-powered capability in MyCSF designed to help HITRUST certified organizations address a persistent, time-consuming challenge. We can’t share all the details yet, but we can say this: copying and pasting will soon be a thing of the past.

 

Hear From the Experts

October will offer several opportunities to hear practical perspectives from industry practitioners and security leaders addressing assurance, cyber risk, and vendor oversight challenges.

The second installment of our Assurance Gap webinar series, SOC 2 vs. HITRUST: A Practitioner Debate on What Third-Party Risk Actually Needs, takes place on October 8. Join TPRM and GRC experts Nick Norton, Ryan Patrick, and AJ Yawn as they discuss the strengths, limitations, and real-world applications of today's most common assurance approaches.

Looking for broader industry perspectives? HITRUST experts will also be participating in several industry events where the conversation will extend beyond compliance checklists to the future of cyber resilience and vendor risk. At the CHIME State of Cybersecurity event, we’ll join a panel of industry leaders to discuss the top priorities for CISOs over the next 90 days and how organizations are navigating an increasingly complex threat landscape.

Later in the month, our team will be speaking and exhibiting at Vendor & Third Party Risk USA, in Ft. Worth, TX. If you’re going, be sure to block time to head to Ryan Patrick’s breakout session, Rethinking Vendor Due Diligence: When Cyber Threats Outpace Traditional Assurance.

HITRUST will cap off a busy few weeks with a keynote at GRF Summit on Security & Third-Party Risk, where attendees will gain insights into emerging risks, evolving assurance expectations, and practical approaches for building greater trust across the vendor ecosystem.

If you're responsible for risk management, compliance, or vendor oversight, these sessions offer a chance to hear how peers and industry experts are addressing the challenges shaping the future of assurance.

 

Don’t Miss Out

If you don’t want to miss out on our content, product news, and events, subscribe to be notified and be sure to follow HITRUST on Linkedin and X. In the meantime, check out our recent Navigating AI Security and Assurance paper and our recent blogs.