Cyber · Third-Party Risk · Supply Chain

Gabriel
Hasik

Security practitioner and risk thinker with 8+ years in cybersecurity and IT risk management. Writing about security, compliance, and the risks hidden in today’s interconnected business ecosystems.

Cybersecurity Third-Party Risk Supply Chain Security Personal Projects
Scroll
01 — About

I work at the intersection of cybersecurity, third-party risk, and supply chain resilience, helping organizations understand, assess, and manage the risks that come with relying on vendors, partners, and complex ecosystems. Whether it’s a gap analysis against NIS2, a compliance assessment under DORA, or building a practical Identity and Access Management (IAM) framework, my focus is always the same: making security work in the real world, not just on paper.

This site is where I think out loud. You’ll find writing on risk management, third-party security, compliance, and the tools and ideas that help turn complex requirements into practical programs.

When I’m not focused on security and risk, I’m probably tending the garden, training for my next Ironman, or spending quality time with my family.

02 — Writing

Selected Articles

Supply Chain March 2025

Why Your Vendor Risk Program Misses the Point

Most TPRM programs are built to pass audits, not to manage actual risk. Here's what changes when you treat it as an intelligence function instead.

Cyber Jan 2025

The Quiet Failure Mode: Inherited Trust in Software Supply Chains

Open-source dependencies, build pipelines, and the uncomfortable truth about software you didn't write but fully own.

View all articles --
03 — Projects

Where I've Made an Impact

01

Energy Sector

Led a NIS2 gap analysis, mapping regulatory requirements alongside ISO 27001, ISAE3402, and SOC2 to the organization's internal control environment — a critical step in understanding supply chain exposure.

NIS2 ISO 27001 SOC2
02

Crypto & Digital Finance

Assessed DORA compliance for a cryptocurrency and digital finance company, focusing on operational resilience in a space where third-party dependencies are evolving faster than regulations.

DORA Operational Resilience Third-Party Risk
03

Utilities

Performed a combined NIS2 and NIST gap analysis, advising on practical strategies to close compliance gaps across vendor-dependent infrastructure.

NIS2 NIST Gap Analysis
04

Banking & Financial Services

Oversaw the IT components of external financial statement audits, digging into access management, incident response, and change management processes — all areas where third-party risk often hides in plain sight.

IT Audit IAM Incident Response
05

Export Banking

Conducted IT and SWIFT audits, revising internal policies that directly impact how third-party transactions and communications are secured.

SWIFT IT Audit Policy Review
06

Retail

Developed and formalized IAM policies, strengthening the security posture across a supply chain that depends heavily on external partners and systems.

IAM Policy Design Supply Chain Security
07

Professional Services

Guided the implementation and certification of ISO 27001:2022, building a security management system designed to scale with third-party growth.

ISO 27001:2022 ISMS Certification
04 — Contact

Working on something in the risk space?
Let's talk.