Panorays’ Blog

Articles by Dov Goldman

Learn about the latest research and happenings in TPCRM
Dov Goldman - VP of Risk Strategy @ Panorays
Dov Goldman
VP of Risk Strategy @ Panorays
Dov is a serial entrepreneur who’s been involved with third-party programs of all sizes, and is the go-to person for explaining the difference between inherent and residual risk.

Expertise

Dov is a seasoned entrepreneur, navigating the world of startups with finesse. With a knack for breaking down the nuances of third-party risk management, he’s your ultimate guide in explaining inherent versus residual risk. Armed with years of expertise, Dov will untangle the intricacies of risk assessment and demystify the complexities of third-party risk.

Experience

Throughout his extensive career as a technology entrepreneur, Dov has emphasized the human dimension of implementing IT systems and the pragmatic necessity of delivering tangible business outcomes. With decades of experience spanning multiple startups, Dov has collaborated closely with cyber and risk leaders across numerous large enterprises, specializing in third-party risk management.

Cybersecurity Authoritativeness

Dov has earned recognition as a thought leader, adept at simplifying intricate problems and their resolutions into easily understandable terms. Regarded as the ‘third-party therapist’ within the industry, Dov possesses an intuitive understanding of the challenges faced by third-party risk leaders. His engaging speaking engagements and insightful written pieces captivate audiences, blending entertainment with informative content.

Dov has written and been quoted about third party cyber risk and privacy in various papers, cybersecurity news publications, websites and resources, including:

Dov has spoken at and chaired numerous industry events, including recently:

Dov has a number of patents to his name, including one for the design of a third-party cyber risk module:

Education

Dov graduated from Columbia University in New York with a degree in Computer Sciences. His time there was more than just academics—it was a transformative period where he honed his skills and immersed himself in tech competitions and workshops. Columbia equipped him not only with technical expertise but also instilled in him a relentless drive for excellence that defines his career.

Latests Posts by Dov Goldman

Anatomy of a Healthcare Data Breach

A Modern Approach to Healthcare Supply Chain Risk Management

The healthcare supply chain isn't just about pallets and purchase orders anymore. It's a dense web of…
DORA

2026 Guide to Third-Party Risk Management Under DORA

Your financial institution runs on a web of interconnected services – cloud platforms handling your infrastructure, SaaS tools powering daily operations, data processors managing sensitive information,…
Cyber Security Monitoring

How Continuous Monitoring Mitigates Supply Chain Threats

Your business runs on a sprawling web of cloud platforms and third-party tools that speed up innovation but create massive blind spots. When one supplier stumbles, the…
Vendor Due Diligence Checklist

A Comprehensive Guide to Consumer Data Privacy Laws…

Consumer data privacy laws are reshaping how you collect, use, and protect…
Third-party data breaches

Navigating HIPAA Privacy Laws: Protecting PHI from Third-Party…

Your healthcare organization's digital backbone now runs through a web of billing…
Attack Surface Monitoring

The Role of Attack Surface Management in Modern…

Your organization runs on a sprawling web of digital infrastructure – everything…
Attack Surface Management vs. Vulnerability Management

The Role of AI Vulnerability Management in Modern…

AI is everywhere now. It's in your code assistants, your workflows, and…
Vendor Due Diligence Checklist

Cyber Security Governance: Frameworks, Strategies, and Best Practices

Every year, your digital estate gets more complex. Cloud-native stacks blend with…
Vendor Due Diligence Checklist

A Complete Guide to Supply Chain Cybersecurity Strategies

Your organization doesn't operate in isolation anymore. Critical data flows through cloud…
Digital Supply Chain

A Comprehensive Guide to Supply Chain Risk Assessment

Global supply chains are more connected – and more susceptible to risk…
What is the Digital Operational Resilience Act

What is DORA?

The Digital Operational Resilience Act (DORA) will go into effect January 17,…
Third-Party Cloud Security

Cloud Security Compliance for TPRM: A Complete Guide

Cloud-first is the new normal. You're running critical workloads in public clouds…
What’s Your Risk Strategy? (And Are You Sure It’s Working?)

Supply Chain Risk Management: A Strategic Guide for…

Supply chain risk management isn't a checkbox anymore. It's a core business…
Digital Supply Chain

A Complete Guide to Cyber Supply Chain Risk…

Your attack surface isn't just bigger. It's more connected than ever. You're…
Cyber Threat Intelligence

Cyber Security Supply Chain Attacks: Navigating the 2026…

Cyber security supply chain attacks exploit trust. Instead of hammering away at…

The Fastest and Easiest Way
to Do Business Together, Securely