This paper introduces the concept of transitive trust in the context of third-party cybersecurity risk governance. It examines how a security incident involving a vendor, like the November 2025 OpenAI-Mixpanel event, can create accountability problems for the primary service provider. The research proposes the "Fortress and Gatekeeper" framework to explain cybersecurity governance based on trust and data flows, rather than just organizational ownership, and offers implications for vendor management and data handling. AI
IMPACT This research provides a framework for understanding and managing cybersecurity risks associated with AI vendors and their supply chains.
RANK_REASON The cluster contains an academic paper published on arXiv.
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →