• Cyber Safety
  • Posts
  • Your Security Depends on Vendors You Don’t Control

Your Security Depends on Vendors You Don’t Control

In partnership with

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

Your Attack Surface Extends Beyond Your Company

Payroll providers, cloud platforms, agencies, payment processors, IT partners, and SaaS vendors may all handle your data or connect directly to your systems.

Attackers Can Target the Easier Organization First

If your defenses are strong, compromising a smaller supplier with privileged access may provide attackers with an indirect route into your environment.

Integrations Turn Vendor Risk Into Your Risk

API keys, OAuth permissions, VPN access, shared accounts, and support integrations can give third parties significant capabilities inside your infrastructure.

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

A Security Questionnaire Isn’t Continuous Monitoring

A vendor may look secure during onboarding and experience major changes six months later. New infrastructure, employees, subcontractors, or incidents can alter the risk profile.

Vendor Access Should Have Boundaries

Third parties should receive only the systems, data, and permissions required for their work — ideally with expiration dates and monitoring around privileged activity.

Plan for the Vendor Breach Before It Happens

Inventory critical suppliers, document their access, enforce least privilege, review integrations regularly, and create procedures for rapidly revoking third-party access. You can't control every vendor’s security — but you can control how much damage their compromise can cause.

Leave Granola and get up to 12 months free of Wispr Flow Notetaker + Dictation

If you have paid time left on an individual Granola plan, we'll match it with a Wispr Flow subscription that includes Notetaker and dictation, and add bonus time, up to 12 months total. Sign in or create a Wispr account and submit proof of your plan to check eligibility.