Resources

DCR Partners Joins Risk Ledger's Expert Panel: Three Key Takeaways

Written by Marketing Team | Aug 4, 2026, 12:13:40 PM

 Last week, our Managing Director, Raj Kohli, joined Risk Ledger's 'Ask Me Anything: What the Best Security Teams Are Doing Differently' webinar as an expert panellist.

The audience-led discussion explored everything from third-party risk management and supplier assurance to operational resilience and the habits that distinguish high-performing security teams. 

 Here are three of Raj's key takeaways: 

 

1. Understand the business before managing the risk

Raj emphasised that effective security starts with understanding the organisation itself.

Before introducing tools or assessment processes, organisations need a clear understanding of the business outcomes they're trying to achieve, which services are most critical, and how suppliers support those objectives.

By taking a business-first view of risk, organisations can make better decisions, prioritise their efforts and ensure third-party risk management enables the business rather than becoming an administrative exercise.

 

2. The best security teams understand, adapt and stay curious

When asked what consistently separates high-performing security teams from everyone else, Raj highlighted three defining characteristics.

  • Understand the business and how it delivers value.
  • Manage change effectively, recognising that change is constant.
  • Stay curious, continually learning and adapting because they know they don't have all the answers.

These qualities enable security teams to move beyond compliance and become trusted partners to the wider business.

 

3. Build a proportionate approach to third-party risk

When asked how organisations should approach assurance for smaller suppliers, Raj challenged the assumption that supplier size should determine the level of attention it receives.

Instead, he encouraged organisations to first identify which suppliers are genuinely critical to delivering their most important business services. As he explained, "Small doesn't mean insignificant."

Once critical suppliers have been identified, organisations can apply the appropriate level of assurance based on the risk they present. Or, as Raj put it, "Make sure that the levels of assurance that you provide over them is proportionate."

By taking this approach, organisations can focus their time and resources where risk is greatest, rather than applying the same level of scrutiny to every supplier.

 

As the discussion reinforced, building resilience isn't about doing more - it's about focusing on what matters most. By understanding the business, taking a proportionate approach to risk and fostering a culture of continuous learning, organisations can strengthen security while better supporting their strategic objectives.

If you'd like to hear the discussion in full, you can now watch the webinar on demand.

If your organisation is looking to strengthen its approach to third-party risk management, build a more proportionate assurance model or improve operational resilience, we'd be happy to help. Get in touch with the team to discuss how we can support your organisation.