Synopsis:
Most vendor risk programs are built to answer the wrong question. They score financial stability, contract terms, and reputational exposure, and stop there. They rarely ask the question that actually determines whether your organization can recover: who has the authority to change, disrupt, or fail the systems you depend on, and did you ever explicitly evaluate that authority, or did you simply inherit it?
This session introduces a single framework, the control-ceded audit, and proves it against three real incidents that look unrelated on the surface but share the same root cause. CrowdStrike (2024) shows control ceded by accident, through an auto-update pipeline with no customer approval gate. Kronos/UKG (2021) shows control ceded invisibly, through dependence on a vendor's security posture that customers had no way to verify. Maersk/NotPetya (2017) shows control ceded and then weaponized, when a routine software update became the delivery mechanism for a state-sponsored attack. Three different attackers, three different timelines, one identical exposure: the organization had already given up operational control before the incident ever occurred.
Stuart Murray draws on 25+ years of Fortune 100 BC/DR leadership, including building Jabil's global program to ISO 22301 certification across 34 countries, to give practitioners a concrete audit framework for finding these exposures before a vendor finds them for you.
Attendees will leave this session able to:
About our Speaker:
Stuart Murray, CBCP, MBCI, Managing Director, Meridian Resilience, is an enterprise resilience executive with more than 25 years of experience building and leading business continuity, disaster recovery, and crisis management programs for Fortune 100 organizations. A Certified Business Continuity Professional (CBCP, DRII), Member Business Continuity Institute (MBCI-BCI),FEMA-Certified Exercise Evaluator, and Prosci Certified Change Manager, Stuart has a reputation for building programs that actually work — from writing the first policy to chairing executive steering committees and leading real-time crisis response as Incident Commander.
Stuart's career spans both the practitioner and advisory sides of the field. He served as Global Head of IT Resiliency and Infrastructure Governance at Jabil, where he built a global BC/DR program from scratch to ISO 22301 certification across 34 countries. He has also held senior resilience roles at Oracle Health and Molina Healthcare, and spent 14 years as a BC/DR consultant advising Fortune 500 clients in financial services, manufacturing, and telecommunications.
His areas of focus include program design and governance, BIA methodology, RTO/RPO frameworks, cybersecurity resilience, and tabletop exercise design and facilitation. He tracks emerging risk categories — including AI dependency, cloud concentration risk, and third-party control exposure — and integrates them into practical program strategy.
Stuart has presented at more than 50 industry conferences, including the Disaster Recovery Journal, Continuity Insights, and ServiceNow Knowledge. He is a member of the Disaster Recovery Institute International and the Association of Continuity Professionals.
1067 Cresthaven Rd.
Memphis, TN 38119
(901) 670-2738
staff@acp-international.com