Alla Valente

Principal Analyst

Forrester Bio

Author Insights

Blog

No, You Can’t Just Vibe Code Commerce — Yet

Emily Pfeiffer 1 day ago
“What coding?” Vibe coding is the cute term for using genAI systems to create, debug, or update programming code. People can use it without knowing how to write a line of code themselves. What this means: Lots of people are generating code they don’t understand. It’s not just developers using these tools to code faster; for example, it’s schoolteachers writing their […]
Blog

From Operating Rooms To iPhones: What The Stryker Attack Reveals About Third-Party Risk

Alla Valente 3 days ago
A recent cyberattack on a global medical device manufacturer shows how third-party failures can cascade from enterprise IT into patient-facing operations. This post unpacks what the incident reveals about concentration risk, vendor dependencies, and real-world impact.
Blog

The Stryker Attack: Enterprise Resiliency Plans Can’t Ignore UEM

Paddy Harrington 6 days ago
The alleged Stryker cyberattack underscores a critical blind spot in enterprise resilience strategies: the outsized risk and impact of compromised device and endpoint management platforms.
Blog

The Mandela Effect In TPRM: Why Companies Still Misremember Their Third-Party Risk Exposure

Alla Valente March 10, 2026
What do the Monopoly man’s monocle, the Fruit of the Loom cornucopia, and “Luke, I am your father” have in common? None of them actually exist the way you remember. That glitch is the Mandela effect, a collective misremembering of facts or events, and it is the same mental bug that convinces executives that their […]
Blog

Inside The Odido Breach: A Governance Thriller Unfolds

Madelein van der Hout March 9, 2026
In February 2025, Dutch telecom operator Odido disclosed a breach affecting 6.2 million current and former customers (roughly a third of the country’s population), the largest telecom breach in Dutch history. Attackers socially engineered a call center employee into approving a fraudulent MFA request, gaining access to Odido’s Salesforce CRM environment and exfiltrating highly sensitive data […]
Blog

Anthropic Doubles Down On Agentic For The Enterprise

Brent Ellis March 3, 2026
Anthropic’s push into agentic AI highlights a core enterprise challenge: Speed alone is not enough. It's governance, trust, and accountability that determine real value.
Blog

The Real Deal: A Black Friday-Inspired RFP Template For Vetting AI SaaS Vendors

Alla Valente December 2, 2025
For those of us of a certain generation, “Black Friday” invokes memories of the Cabbage Patch Kid riots of 1983.
Blog

AWS Outage, Nexperia Seizure, And The EU’s Cloud Sovereignty Framework: The Battle For Digital Sovereignty Is On!

Dario Maisto October 28, 2025
In times of calm, but especially in times of chaos, risk management strategies and their execution must be dictated by context and control. Prioritizing key risks and crafting appropriate responses is essential to keeping the business going.
Blog

From Veto To Victory: California’s New AI Act Revives The National (And International) Conversation On AI Regulations

Alla Valente October 24, 2025
At its core, California’s new AI law requires safety protocols, best practices, and key compliance policies, but it stops short of prescribing risk frameworks and imposing legal liabilities. Here’s a closer look at what’s in SB 53.
Blog

Forrester’s AEGIS Framework: The New Standard For AI Governance

Jeff Pollard October 22, 2025
AEGIS is not just another acronym — it’s now a fully cross-referenced, regulation-aware blueprint for building trust in AI systems.
Blog

The AWS US-East Outage: A Wake-Up Call For Cloud Resilience

Brent Ellis October 20, 2025
The fourth outage in five years for AWS’s US-East region was traced to DNS resolution failures that affected many core services. Find out what you should do from both the technology and the supplier risk management side to improve your cloud resilience.
Blog

How F5 And SonicWall Revealed The Fragility Of The Software Supply Chain

Carlos Rivera October 17, 2025
The recent breaches at F5 and SonicWall illustrate how attackers are targeting the very infrastructure that enterprises rely on to secure and deliver digital services.
Blog

The Netherlands Targets Chip Governance: A New Precedent For Cyber And IP Risk Intervention

Tope Olufon October 15, 2025
The Netherlands placing Chinese-owned chipmaker Nexperia under ministerial oversight is a sign that Europe has crossed from passive screening to active control to keep IP and capacity in-region. Find out what this means for CISOs and risk leaders and what steps to take next.
Blog

AI Regulations Clear Major Hurdles On Both Sides Of The Atlantic

Enza Iannopollo July 23, 2025
July has marked a defining moment for global AI regulation, as policymakers in both the US and the EU removed or abandoned some heavy roadblocks that stood in the way of laws mandating transparency and regulations enshrining risk management.
Blog

Supply Chain, AI, And Operational Resilience Risks Dominate ERM Programs In 2025

Paul McKay June 13, 2025
For risk professionals, leading through 2025’s volatility has been like living in an “Alice in Wonderland” unreality. Risk teams have never been more important as a function to guide their businesses through challenges such as geopolitical risk events, trade disruption, economic volatility, and regulatory disruption.
Blog

Data- And Agent-Centric Roadmap Inspires Coupa’s Vision For Autonomous Spend Management

Alla Valente May 22, 2025
Coupa Inspire 2025 unveiled an elevated brand and a new leadership team. Here's the five key insights that came out of the event.
Blog

The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond

Cody Scott May 14, 2025
RSAC is the largest cybersecurity conference in the world. Leaders and practitioners across all sectors come together to tackle challenges, all under the maxim of “managing risk.” But what does “risk” actually mean at a security conference? Is it a mythical pursuit? Marketing buzzword? Or generic substitute for “the thing we need to detect/prevent/remediate”? RSAC […]
Blog

RSAC Conference 2025: Innovation Sandbox Turns 20

Sandy Carielli May 7, 2025
RSAC Conference 2025 featured the 20th annual Innovation Sandbox competition. Learn more about the entrants and results in this review of the event.
Blog

RSAC Conference 2025: Welcome To The Petting Zoo

Sandy Carielli May 6, 2025
From live goats and puppies to robot dogs and animal costumes, the RSAC Conference 2025 delivered some unexpected surprises. But it also delivered the usual insight into various trends in the security market today. Find out more in this RSAC review.
Blog

Global Tariffs: Dynamic Risk Management Meets Its Moment

Paul McKay April 23, 2025
The recent introduction of US-imposed tariffs has shaken global trade. While economists and financial analysts debate whether this on-again/off-again trade war fits into their model for geopolitical, economic, or supply chain risks, the result is the same: uncertainty and chaos sure to shake up business strategy for the foreseeable future. This new era of volatility […]
More posts