---
title: "Burim Bivolaku: Financial Sector Collaboration is Key to Third-Party Risk Management"
description: Burim Bivolaku, BISO of ICE, talks about the biggest challenges in third-party risk management and how to effectively address them.
image: https://www.fsisac.com/hubfs/Podcast/Episode19-BurimBivolaku/FinCyberToday-Podcast_Website_Episode-19.png
---

![FinCyber Today_HeroBanner copy 2](https://www.fsisac.com/hubfs/FinCyber%20Today_HeroBanner%20copy%202.png)

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Burim%20Bivolaku,%20BISO%20of%20ICE,%20talks%20about%20the%20biggest%20challenges%20in%20third-party%20risk%20management%20and%20how%20to%20effectively%20address%20them.) [![Share on Email](https://static.hubspot.com/final/img/common/icons/social/email-24x24.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fwww.fsisac.com%2Finsights%2Fpodcast%2Fburim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management%3Futm_medium%3Dsocial%26utm_source%3Demail)

 

 

# Burim Bivolaku: Financial Sector Collaboration is Key to Third-Party Risk Management

Third-party providers are often crucial to financial service operations – and a serious cyber risk. For that reason, EU regulators are taking a close look at the digital supply chain. Here, BISO (Business Information Security Officer) at ICE Trading and Clearing, and Chair of FS-ISAC’s UK Strategic Subsidiary Board, Burim Bivolaku talks about the biggest challenges in third-party risk management, how to effectively address them, and why FS-ISAC’s UK Strategic Subsidiary Board helps its governance structure remain both global and local. 

Third-Party Risks and the Benefit of Collaboration 

Reliance on third-party providers varies among financial service firms and sub-sectors, and some have more critical providers than do others. But risk management considerations– especially as they pertain to cloud computing and UK and EU regulations – are gaining prominence across the sector.  

For that reason, the financial community should encourage collaboration with providers, as the sector routinely does amongst itself. Proactively sharing knowledge and capabilities complements regulatory compliance requirements. And getting to know each other builds trust in a way that due diligence doesn’t – and trust can be a vital asset during an incident.  

Define the Third-Party Interface 

Financial service firms should define their interface with and outputs from third-party suppliers – and be really specific -- from a cyber-risk perspective. Risk outcomes manifest in different ways, from outages to contagion, but the interface definition can minimize or prevent harm. This is especially important with critical service providers because they’re core to effective risk management and overall resilience, while contractual agreements can address fourth- and fifth-party risks.   

Threat Goes Beyond the Cybersecurity Department  

Cybersecurity is a multi-disciplinary, cross-organizational issue. All departments should be involved, because the implications of a cyber attack are wide.   

Why FS-ISAC’s UK Strategic Subsidiary Board is Important 

FS-ISAC has a global remit because threats are cross-national, but members navigate local and jurisdictional complexities as well. FS-ISAC has enhanced its regional governance structures over the years, and the UK Strategic Subsidiary Board is a logical continuation. The Board will help FS-ISAC advance cyber risk management, sharing, and collaboration among members and authorities in the UK, provide local and global threat intelligence, and offer a forum to share best practices, knowledge, and cybersecurity frameworks.  

DORA and Third-Party Risks 

Collaborating with regulatory bodies on third-party risks helps drive positive regulatory change. And the sector’s feedback helps actions such as the EU’s Digital Operational Resilience Act (DORA) reduce risk with appropriate proportionality. 

For example, DORA includes rules regarding third-party tracking. Some critical service providers will not be able to meet the additional cost of compliance, which increases the potential of concentration risk – and that impacts financial service firms’ resilience. The sector’s input will help regulators keep the sector safe. 

Advice for People Aspiring to Become BISOs 

The role links information security and business functions, so on-the-ground experience with both business and cyber issues will help you advise your board, management, and sector. By understanding the business, you can better serve it.   

 

### FinCyber Today

**FinCyber**** Today **is a podcast from FS-ISAC that covers the latest developments in cybersecurity, contemporary risks, financial sector resilience and threat intelligence.

Our host Elizabeth Heathfield leads wide-ranging discussions with cybersecurity leaders and experts around the world who bring practical ideas on how to confront cyber challenges in the financial sector, improve incident response protocols, and build operational resilience.

Amid the clutter and noise, FS-ISAC Insights is your go-to destination for clarity and perspectives on the future of finance, data, and cybersecurity from C-level executives worldwide.

© 2026 FS-ISAC, Inc. All rights reserved.

**Listen on**

[![New call-to-action](https://no-cache.hubspot.com/cta/default/5442200/0b16770e-328e-4055-a690-0fc15d9a4981.png)](https://cta-redirect.hubspot.com/cta/redirect/5442200/0b16770e-328e-4055-a690-0fc15d9a4981)

[![New call-to-action](https://no-cache.hubspot.com/cta/default/5442200/0e6e53c2-486c-48b6-83be-5d558d468e34.png)](https://cta-redirect.hubspot.com/cta/redirect/5442200/0e6e53c2-486c-48b6-83be-5d558d468e34)

[![New call-to-action](https://no-cache.hubspot.com/cta/default/5442200/7ed24d0d-b79f-412f-b330-ecfcedc005b3.png)](https://cta-redirect.hubspot.com/cta/redirect/5442200/7ed24d0d-b79f-412f-b330-ecfcedc005b3)

### Burim Bivolaku

![Burim Bivolaku](https://www.fsisac.com/hubfs/BoardOfDirectors/Headshots/BurimBivolaku-ICE%20resized.jpg)

 Burim Bivolaku has been with ICE since 2016, initially as Head of Information Security for the EMEA region, and then from April 2022 as Business Information Security Officer, Trading & Clearing with... 

[Read More **](https://www.fsisac.com/insights/podcast/burim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management#)

 global remit in managing the Cybersecurity programme across all ICE derivatives regulated markets, including exchanges, CCPs, trade repositories and benchmarks. He’s an active participant in industry sharing/collaboration initiatives, and currently serves as Chair of FSISAC UK Strategic Board, and represents ICE in multiple strategic groups, such as: FSISAC iCHEF, FIA Cyber-Risk Task Force, WFE GLEX Cyber Working Group, CCP Global Cyber Working Group, BoE CMORG Cyber Group, FCA Trading Venues & Benchmarks Cyber Coordination Group, US Analysis & Resilience Centre and Netherland’s TCO Advisory Group Cyber. Previously he served as Deputy-Chair of FSISAC ETIC and founding member of UK FSCCC Steering Committee. Burim is also involved in collaboration work with academia and is a member of Imperial College Industry Advisory Board and King’s College Industry Advisory Board. Prior to joining ICE, Burim served in various InfoSec leadership / CISO roles (Noble Group, BGC Partners, Bloomberg) and has a strong background in network security. Burim holds a BSc in Electrical Engineering from University of Prishtina and an MSc in Information Systems Engineering from Southbank University in London.

### Hosted by Elizabeth Heathfield

![Elizabeth Heathfield](https://www.fsisac.com/hubfs/Elizabeth%20Heathfield.jfif)

 Elizabeth is a storyteller at the intersection of technology and money. Layer in geopolitics and the criminal underworld and you get today's issues in cybersecurity for the global financial system. Crypto. Web... 

[Read More **](https://www.fsisac.com/insights/podcast/burim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management#)

 3.0. Quantum. AI. Ransomware. Privacy. Regulation. Zero-days. Supply chain attacks. Developing new and diverse talent. How to protect the future of money. These are the topics Elizabeth asks top executives and experts in the field about on FinCyber Today.

### Posts by Topic

- [Podcast (34)](https://www.fsisac.com/insights/tag/podcast)
- [Intelligence Sharing (23)](https://www.fsisac.com/insights/tag/intelligence-sharing)
- [Cyber Programs (19)](https://www.fsisac.com/insights/tag/cyber-programs)
- [Artificial Intelligence (14)](https://www.fsisac.com/insights/tag/artificial-intelligence)
- [Data Security (9)](https://www.fsisac.com/insights/tag/data-security)
- [CISO (8)](https://www.fsisac.com/insights/tag/ciso)
- [COVID-19 (8)](https://www.fsisac.com/insights/tag/covid-19)
- [Quantum Computing (8)](https://www.fsisac.com/insights/tag/quantum-computing)
- [Digital Banking (6)](https://www.fsisac.com/insights/tag/digital-banking)
- [Business Risk (5)](https://www.fsisac.com/insights/tag/business-risk)
- [Security (5)](https://www.fsisac.com/insights/tag/security)
- [Supply Chain (5)](https://www.fsisac.com/insights/tag/supply-chain)
- [third-party risk (5)](https://www.fsisac.com/insights/tag/third-party-risk)
- [Business Continuity (4)](https://www.fsisac.com/insights/tag/business-continuity)
- [Cyber Resilience (4)](https://www.fsisac.com/insights/tag/cyber-resilience)
- [Cyber Risk (4)](https://www.fsisac.com/insights/tag/cyber-risk)
- [Cybersecurity Risk (4)](https://www.fsisac.com/insights/tag/cybersecurity-risk)
- [Diversity (4)](https://www.fsisac.com/insights/tag/diversity)
- [Fraud (4)](https://www.fsisac.com/insights/tag/fraud)
- [Regulation (4)](https://www.fsisac.com/insights/tag/regulation)
- [Trust (4)](https://www.fsisac.com/insights/tag/trust)
- [Best Practices (3)](https://www.fsisac.com/insights/tag/best-practices)
- [Cryptography (3)](https://www.fsisac.com/insights/tag/cryptography)
- [Cybersecurity (3)](https://www.fsisac.com/insights/tag/cybersecurity)
- [Threat Intelligence (3)](https://www.fsisac.com/insights/tag/threat-intelligence)
- [Cybersecurity Framework (2)](https://www.fsisac.com/insights/tag/cybersecurity-framework)
- [Data Governance (2)](https://www.fsisac.com/insights/tag/data-governance)
- [Deepfakes (2)](https://www.fsisac.com/insights/tag/deepfakes)
- [Exercises (2)](https://www.fsisac.com/insights/tag/exercises)
- [Global (2)](https://www.fsisac.com/insights/tag/global)
- [Incident Response (2)](https://www.fsisac.com/insights/tag/incident-response)
- [Metrics (2)](https://www.fsisac.com/insights/tag/metrics)
- [Ransomware (2)](https://www.fsisac.com/insights/tag/ransomware)
- [Resilience (2)](https://www.fsisac.com/insights/tag/resilience)
- [Threat (2)](https://www.fsisac.com/insights/tag/threat)
- [Zero-Day Vulnerability (2)](https://www.fsisac.com/insights/tag/zero-day-vulnerability)
- [2FA (1)](https://www.fsisac.com/insights/tag/2fa)
- [APAC (1)](https://www.fsisac.com/insights/tag/apac)
- [API (1)](https://www.fsisac.com/insights/tag/api)
- [Attacks (1)](https://www.fsisac.com/insights/tag/attacks)
- [ChatGPT (1)](https://www.fsisac.com/insights/tag/chatgpt)
- [Cloud Security (1)](https://www.fsisac.com/insights/tag/cloud-security)
- [Community Institutions (1)](https://www.fsisac.com/insights/tag/community-institutions)
- [Critical Providers (1)](https://www.fsisac.com/insights/tag/critical-providers)
- [Cyber Hygiene (1)](https://www.fsisac.com/insights/tag/cyber-hygiene)
- [DORA (1)](https://www.fsisac.com/insights/tag/dora)
- [Data protection (1)](https://www.fsisac.com/insights/tag/data-protection)
- [EMEA (1)](https://www.fsisac.com/insights/tag/emea)
- [Framework Threat Information Sharing (1)](https://www.fsisac.com/insights/tag/framework-threat-information-sharing)
- [Incident Reporting (1)](https://www.fsisac.com/insights/tag/incident-reporting)
- [Insurance (1)](https://www.fsisac.com/insights/tag/insurance)
- [Log4j (1)](https://www.fsisac.com/insights/tag/log4j)
- [Mitigation (1)](https://www.fsisac.com/insights/tag/mitigation)
- [Red Teaming (1)](https://www.fsisac.com/insights/tag/red-teaming)
- [Research (1)](https://www.fsisac.com/insights/tag/research)
- [Retirement (1)](https://www.fsisac.com/insights/tag/retirement)
- [SWIFT (1)](https://www.fsisac.com/insights/tag/swift)
- [Talent Shortage (1)](https://www.fsisac.com/insights/tag/talent-shortage)

[see all](https://www.fsisac.com/insights/podcast/burim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management#)

### WANT TO CONTRIBUTE?

[![Get Started](https://no-cache.hubspot.com/cta/default/5442200/87cce1c8-ef9e-418f-a365-a806b5cf9c6c.png)](https://cta-redirect.hubspot.com/cta/redirect/5442200/87cce1c8-ef9e-418f-a365-a806b5cf9c6c)

### Subscribe to Insights

## FS-ISAC members around the world receive trusted and timely expert information that increases sector-wide knowledge of cybersecurity threats.

[![Learn More](https://no-cache.hubspot.com/cta/default/5442200/15f429fd-7401-4e03-9aff-57dbaed38283.png)](https://www.fsisac.com/membership)

[![fs-isac-greyscale](https://www.fsisac.com/hubfs/fs-isac-greyscale.svg "fs-isac-greyscale")](https://fsisac-5442200-hs-sites-com.sandbox.hs-sites.com/)

#### Site Map

- [About Us](https://www.fsisac.com/about-us) 
    - [Careers](https://www.fsisac.com/careers)
    - [Contact Us](https://www.fsisac.com/contact-fsisac)
    - [Events](https://www.fsisac.com/events-archive)
    - [FAQ](https://www.fsisac.com/who-we-are/faq)
    - [Newsroom](https://www.fsisac.com/newsroom)
- [Privacy Notice](https://www.fsisac.com/privacy-notice) 
    - [Responsible Disclosure](https://www.fsisac.com/responsible-disclosure)
    - [Scholarship Program](https://www.fsisac.com/scholarships)
    - [Subsidiaries](https://www.fsisac.com/who-we-are/sheltered-harbor)
    - [Terms](https://www.fsisac.com/terms)

Follow Us

[![Twitter](https://www.fsisac.com/hubfs/Icons/Twitter.svg) ](https://twitter.com/FSISAC) [![LinkedIn](https://www.fsisac.com/hubfs/Icons/Linkedin.svg) ](https://www.linkedin.com/company/fs-isac/)

© Copyright 1999 - 2026 FS-ISAC, Inc. All Rights Reserved.

[Terms and Policies](https://fsisac-5442200-hs-sites-com.sandbox.hs-sites.com/terms)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Burim Bivolaku",
    "url" : "https://www.fsisac.com/insights/author/burim-bivolaku"
  },
  "dateModified" : "2025-07-07T18:01:45.219Z",
  "datePublished" : "2024-05-14T17:46:10.000Z",
  "headline" : "Burim Bivolaku: Financial Sector Collaboration is Key to Third-Party Risk Management",
  "image" : [ "https://www.fsisac.com/hubfs/Podcast/Episode19-BurimBivolaku/FinCyberToday-Podcast_Website_Episode-19.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.fsisac.com/insights/podcast/burim-bivolaku-financial-sector-collaboration-is-key-to-third-party-risk-management",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.fsisac.com/hubfs/FS-ISAC_Logos/Logo.svg"
    },
    "name" : "FS-ISAC Inc"
  }
}
```