Find partners
#AuditTuesday GRC Podcast

#AuditTuesday GRC Podcast

Hosted by YouAttest

TechnologyInterviews guests

Episodes

94

Latest episode

Sep 2026

Language

EN-US

About the show

Every Tuesday we're sharing valuable content for you with the leading authorities in GRC, Compliance and Identity Security.

Listen to episodes

60 recent
September 29, 2026Episode 1553 min

Worried About Rogue AI? Start with Identity Governance - #AuditTuesday w/ Justin Roy and Jeff Kushner

Worried About Rogue AI? Start with Identity Governance Enterprises are increasingly worried about rogue AI agents operating inside their environments. But one of the biggest risks may not be an unauthorized AI agent breaking in. It may be an authorized AI agent using the legitimate identity and access of an employee who is already inside. AI coding assistants and autonomous agents such as Claude Code and similar tools can operate directly from an employee's workstation. Depending on how they're configured, these agents may be able to interact with files, applications, APIs, databases, cloud resources, and other systems using credentials and permissions already available to that user. And here's the problem: many employees don't know how much access they actually have. An AI agent can rapidly discover what resources are available, what systems it can reach, and what actions its user's identity is permitted to perform. In effect, the agent can perform reconnaissance from inside the enterprise —starting with a legitimate, authenticated identity. If that employee is overprivileged, has accumulated unnecessary access, or hasn't had their permissions reviewed recently, the risk becomes significantly greater. AI doesn't create the entitlement problem. It magnifies it. That's why securing enterprise AI starts with strong Identity Governance. Organizations need to understand what their users can access, whether that access is still appropriate, when it was last reviewed, and which identities represent the greatest risk before AI agents begin operating with those same privileges. Join us for this #AuditTuesday discussion as we explore how organizations can prepare their identity environments for the rapidly growing use of internal AI agents. You'll learn: Understand the risk — How AI agents can inherit and leverage legitimate user identities and entitlements. Understand the impact — Why excessive, stale, and unreviewed access becomes significantly more dangerous when AI can act on a user's behalf. Reduce the risk — How Identity Governance and YouAttest can help organizations identify excessive access, continuously review entitlements, and establish stronger governance before deploying AI agents at scale. Featuring: Jeff Kushner —Compliance Expert/CMO, Allgress Justin Roy — Security Engineer, Microsoft Garret Grajek — CEO, YouAttest

September 15, 2026Episode 1452 min

The Shadow NHI Problem: What’s Hiding in Your Identity Environment?

Everybody is talking about governing AI agents. But before you can govern agents, you have to find the non-human identities already hiding in your environment. Join Dave Ackley and Andrew Berkuta of the Goliath Cyber Security Group, for a practical discussion on the growing Shadow NHI problem. Service accounts, workload identities, automation accounts, applications, and AI agents are accessing enterprise systems and data—often without the same visibility and governance applied to human users. We'll explore: How do you discover Shadow NHIs? Who owns them? What privileges and access do they have? When were they last used and reviewed? How do you identify the ones that represent the greatest risk? How should organizations govern and secure them? Not every NHI is an AI agent. But as AI adoption accelerates, knowing what non-human identities exist—and whether they should be trusted—is becoming critical. Featuring Dave Ackley – Founder & CEO, Goliath Cyber Security Group Andrew Berkuta - COO - Zero Trust Expert, Goliath Cyber Security Group LIVE Q&A as we uncover what may be hiding in your identity environment. #AuditTuesday #NHI #AISecurity #IdentitySecurity #IdentityGovernance #CyberSecurity #ZeroTrust #GRC #YouAttest

August 18, 2026Episode 1339 min

Building a World-Class GRC Program - Lessons from Jennifer Felix-Shannon

What separates a world-class Governance, Risk, and Compliance (GRC) program from one that simply checks compliance boxes? Join Jennifer Felix-Shannon, Director of IT Security GRC & Privacy, as she shares practical lessons learned from more than two decades leading enterprise GRC, cybersecurity governance, privacy, and audit programs. We'll explore what it takes to build and mature a successful GRC organization, align security with business objectives, work effectively with auditors and executive leadership, navigate today's evolving regulatory landscape, and create a culture where governance enables the business rather than slows it down. Whether you're building a new GRC program or looking to elevate an existing one, you'll leave with practical insights and real-world strategies from someone who has been in the trenches. Featuring Jennifer Felix-Shannon – Experience Global GRC Leadert Garret Grajek – CEO, YouAttest #AuditTuesday #IdentityGovernance #CyberSecurity #ZeroTrust #GRC #Compliance #Risk #YouAttest

August 4, 2026Episode 1241 min

The CFO’s Role in Cybersecurity & Compliance, w/ Steve Shaw, Fractional CFO - #AuditTuesday GRC Podcast

The CFO's Role in Cybersecurity & Compliance Cybersecurity and compliance are no longer just IT responsibilities—they're business priorities that increasingly land on the CFO's desk. From financial audits and regulatory compliance to cybersecurity investments, board reporting, AI governance, and mergers & acquisitions, today's finance leaders play a critical role in managing organizational risk. Join Steve Shaw, Founder of Shaw Financial Growth and experienced Fractional CFO, together with Garret Grajek, CEO of YouAttest, as they discuss how finance and security leaders can work together to build stronger, more resilient organizations. We'll discuss: Why CFOs are becoming key stakeholders in cybersecurity and compliance How finance teams evaluate cyber risk, governance, and ROI Preparing for financial, SOX, and cybersecurity audits Budgeting for security while supporting business growth The CFO's role in AI governance and regulatory readiness How identity governance helps reduce risk and improve audit outcomes Lessons learned from board reporting, M&A due diligence, and executive leadership Featuring Steve Shaw – Founder & Fractional CFO, Shaw Financial Growth Garret Grajek – CEO, YouAttest Bring your questions for a live Q&A as we explore how finance and cybersecurity leaders can better align to reduce risk, strengthen compliance, and enable business growth. #AuditTuesday #CFO #CyberSecurity #Compliance #GRC #SOX #IdentityGovernance #RiskManagement #CorporateGovernance #Finance #YouAttest

June 24, 2026Episode 111 hr 0 min

Designing the Secure Data Center: Identity Governance and Zero Trust by Design

Join #AuditTuesday hosts and experts from EdgeRealm.ai and YouAttest for an executive-level discussion on how modern infrastructure teams are rethinking data center security from the ground up. What’s on the Agenda? Identity-First Infrastructure Security: Learn why Identity Governance is becoming a core design requirement for modern data centers, hybrid cloud environments, and AI-driven infrastructure. Zero Trust by Design: Discover how Zero Trust principles help reduce risk, limit lateral movement, and strengthen operational security across distributed environments. Building for Compliance and Resilience: Explore strategies for designing infrastructure that supports compliance, operational visibility, and secure access governance from day one. Featured Speakers Robert Hiliker — Data Center Visionary, EdgeRealm.ai Jerry Sisson — Data Center Transformation Leader, EdgeRealm.ai Garret Grajek — Identity and GRC Expert, YouAttest Join us for a forward-looking discussion on securing the modern data center through Identity Governance, Zero Trust, and resilient infrastructure design. Don’t miss this high-impact #AuditTuesday session for security leaders, infrastructure architects, MSPs, and compliance professionals. Follow up: https://youattest.com

June 9, 2026Episode 1043 min

Turning Identity Data Into Cyber Risk Intelligence - RKON + YouAttest, #AuditTuesday

Identity data is everywhere — but turning it into actionable cyber risk insight? That’s where most organizations struggle. IAMs get deployed, 2FA turned on, Access reviews get completed. But the real question remains: 👉 What is your identity risk right now? After a year in the making, RKON has developed the IAM Maturity Intelligence Center — a cyber risk portal designed to transform identity activity into real-time, measurable risk. In this live session, RKON and YouAttest will walk through how organizations can move beyond static governance and into continuous identity risk intelligence. 🔍 What you’ll learn: - How to turn identity audits into real cyber risk signals - The KPIs that actually matter (audit coverage, user review cadence, stale access) - How the IAM Maturity Intelligence Center delivers a single view of identity risk - How YouAttest integrates to provide continuous identity GRC visibility 👥 Featuring: Duane Clouse – Senior Manager, IAM & Zero Trust, RKON Garret Grajek – CEO, YouAttest Kashif Mehmood – Technical Field Director, YouAttest If you’re still relying on periodic reviews and spreadsheets to understand identity risk, this session will challenge that model — and show what’s next. For more information, reach out to us @YouAttest , https://youattest.com and info@youattest.com. RKON can be reached at sales@youattest.com, https://rkon.com.

May 26, 2026Episode 946 min

From SBOM to Access Governance: Closing the Supply Chain Gap

Software supply chain risk is exploding — but most organizations still treat it as a code problem, not a control problem. In this live session, Interlynk and YouAttest connect the dots between software composition risk and identity governance — showing how SBOM insights must tie back to who can access, build, and ship software. 🔍 What you’ll learn: - How SBOMs expose hidden risk in your software supply chain - How identity governance applies to developers, pipelines, and build systems - How to connect SBOM findings to access reviews and least privilege enforcement - How YouAttest helps operationalize identity controls across the SDLC 👥 Featuring: Surendra Pathak – CEO, Interlynk Garret Grajek – CEO, YouAttest Shannon Noonan - CEO, HiNoon Consulting If you’re investing in SBOMs but not governing who controls the software lifecycle, you’re only solving half the problem. Register now to see how software supply chain security and identity governance finally come together. To learn more - contact us at YouAttest: https://youatest.com/contact

April 29, 2026Episode 839 min

Who Has Access to Your Systems? Featuring Dino Price of AgileGRC

Identity is still the #1 control auditors and attackers look at first — but most small and mid-sized organizations are still struggling to answer: Who has access to what… and is it a risk? Join us for a live conversation with Dino Price (AgileGRC) as we break down how identity directly impacts: - SOC 2, HITRUST, and CMMC readiness - Day-to-day security operations - Real-world risk (not just audit checkboxes) No theory. No enterprise fluff. Just what actually works. What we’ll cover (more practical framing) ✅ What an Identity Risk Assessment actually looks like for SMBs ✅ The most common identity gaps we see in SOC 2, HITRUST, and CMMC ✅ How to find orphaned accounts, stale users, and over-permissioned access ✅ Why service accounts and shared access are still a major blind spot ✅ Practical steps you can take this quarter (not a 12-month roadmap)

April 7, 2026Episode 736 min

Let's talk to The GRC Recruiter - #AuditTuesday w/ Pete Strouse

Thinking about a career in GRC—or trying to hire the right talent? Join us for this live #AuditTuesday session featuring Pete Strouse, “The GRC Recruiter”, CEO & Founder of InfoSec Connect. Pete brings deep, real-world insight from the front lines of GRC hiring—and will share what he’s seeing across the market today. This isn’t just theory—Pete will break down what actually works, what employers are looking for, and where opportunities are emerging. Plus, he’ll be taking your live questions during the session. In this episode, we’ll cover: The most in-demand GRC roles for 2026 What backgrounds, certifications, and experience actually matter How the GRC job market is evolving with AI, identity, and compliance pressures Practical insights for both job seekers and hiring managers Whether you're looking to break into GRC, level up your career, or understand how to build a high-performing GRC team—this session will give you real-world perspective you won’t get from job boards.

March 24, 2026Episode 640 min

Time for an Identity Risk Assessment w/ Neil Chapman, Ph.D., and IntraSystems

Identity has become the control plane for modern security — yet most organizations still don’t have a clear answer to one critical question: Who has access to what… and should they? Join us for a live conversation with Neil Chapman, PhD (IntraSystems) as we explore why identity is now at the center of cyber security. In this session, we’ll break down: ✅ What an Identity Risk Assessment is — and why it’s overdue ✅ How to uncover orphaned, stale, and over-privileged accounts ✅ Why service accounts and key roles create hidden exposure ✅ What auditors and attackers look for first in the identity layer ✅ Practical steps security and governance teams can take immediately 🎙 Featuring: Neil Chapman, Ph.D – IntraSystems Garret Grajek – YouAttest If identity governance, least privilege, and modern risk assessments are on your 2026 roadmap, this is a discussion you won’t want to miss. 💬 Live Q&A included — bring your real-world identity challenges.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts