Locktivity Risk Register

How Modern Companies Are Leaving Behind the Broken Compliance Model

Locktivity

Case Study

How Monte Carlo replaced a closed, checklist GRC platform with a security-first program built on signed, verifiable evidence and AI.

Monte Carlo Case Study: Continuous Compliance | Locktivity

How Monte Carlo runs SOC 2 and ISO 27001 with no GRC hires, using signed, verifiable evidence and risk-based third-party management.

Building Security Standards at the Speed of Threats

Rachel Curran

Continuous Compliance

Frameworks overlap, move slowly, and miss new attack paths. The case for threat-informed, service-specific, community-maintained security criteria.

Threat-Informed Security Standards | Locktivity

Why security frameworks lag real threats like the Salesloft Drift breach, and how community-maintained, service-specific criteria can move faster.

The World Is Moving Faster. So Should Your Evidence.

Locktivity

Evidence Packs

Machine-readable, verifiable evidence is already here. We're releasing epack, open-source tooling to build evidence packs.

Machine-Readable Evidence and Open-Source epack | Locktivity

Continuous assurance needs machine-readable, verifiable evidence. Meet epack, the open-source tooling for building evidence packs.

Third-Party AI Risk Assessment: A Strategic Approach

Rachel Curran

AI Risk

A practical method for assessing AI-enabled vendors: classify the system, weigh the risk areas, tighten contracts, and govern continuously.

Third-Party AI Risk Assessment Guide | Locktivity

How to assess AI vendors: risk-tier the system, ask the right questions on data, security and safety, and add the contract terms AI requires.

Navigating the Privacy Maze

Rachel Curran

Privacy

Practical privacy and data protection practices that work as guardrails for the business, not roadblocks.

Privacy Practices That Support the Business | Locktivity

Data mapping, privacy policies, training, access control, minimization and incident response: privacy practices that act as business guardrails.

Managing Third Party AI Use and Privacy Risks

Rachel Curran, Stacey Shadden and Micah Carlson

AI Risk

How SaaS sprawl and AI change third-party privacy risk, and the contract terms that protect your data: minimization, flow-down, and AI restrictions.

Third-Party AI and Privacy Risk: Contract Terms | Locktivity

SaaS sprawl and AI raise third-party privacy risk. The contract provisions that protect your data: minimization, security measures, flow-downs, AI limits.

It's Our Risk, Not Third Party Risk

Rachel Curran

Third-Party Risk

Anyone can get breached. Start third-party risk with the inherent risk of the relationship, and reduce it before you assess the vendor.

Inherent Risk: Where Third-Party Risk Starts | Locktivity

Every vendor can be breached. Start third-party risk management by understanding and reducing the inherent risk of the relationship.

The Fallibility of Security Questionnaires

Rachel Curran

Security Questionnaires

Why the security questionnaire is security theater on both sides, and the three questions to start a better third-party risk program.

The Problem with Security Questionnaires | Locktivity

Security questionnaires waste time on both sides and prove little. What's broken, and how to assess third parties with less theater.

Brace for Impact

Rachel Curran

Third-Party Risk

Betting on low likelihood leaves you exposed. Practical steps to reduce the impact of third-party risks before they happen.

Third-Party Risk Impact vs. Likelihood | Locktivity

Why preparing for the impact of third-party risks beats betting on the odds, plus seven practical steps to limit the fallout when a vendor fails.

Year in Review: 10 Key Trends Shaping Third-Party Risk

Locktivity

Third-Party Risk

The ten trends shaping third-party risk management, from rising supply chain breaches and AI risk to continuous monitoring and new regulation.

Third-Party Risk Trends: 2025 Year in Review | Locktivity

Ten trends shaping third-party risk: rising vendor breaches, AI risk, waning trust in SOC 2, real-time monitoring, and DORA, NIS2 and SEC rules.

Third Party Risk Maturity Model Now Live!

Locktivity

Third-Party Risk

Assess your third-party risk program and build a roadmap with the free Third Party Risk Maturity Model and quiz.

Third-Party Risk Management Maturity Model | Locktivity

See how your third-party risk program stacks up. A free TPRM maturity model, resources, and a quick quiz to find your level and next steps.