Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less
Listen to episodes
60 recent
August 20, 202633 min
PCI FAQs When You’re Starting Your Compliance Program - Episode 230
Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merchant versus service provider responsibilities. Learn why outsourcing payment processing doesn't eliminate your compliance obligations, how scope really works, and why treating PCI as a one-time paperwork exercise creates unnecessary risk. This episode is essential listening for merchants, service providers, and anyone navigating PCI compliance for the first time.
August 13, 202624 min
The Control Worked Yet The Company Still Got Breached - Episode 229
Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls can pass every audit yet still fail to stop modern attacks, and why continuous validation is replacing point-in-time evidence. Discover how organizations should test resilience through penetration testing, red teaming, tabletop exercises, backup recovery, and control effectiveness—not just documentation. If you think "audit passed" equals "risk reduced," this episode will change the way you measure security forever. Episode Transcript: Today’s topic, Adam, is one that I feel like too many folks are familiar with, and that is the company still got breached despite all of your controls working. So what happens when every box is checked, every control passes the audit, and the attacker still gets in? Adam Goslin: Controls can operate as designed, but still end up failing to protect the organization. Compliance is measuring whether or not a control exists and if that control was executed. Security measures whether that control actually reduced the risk. One of the earlier euphemisms that you would hear a lot is compliance doesn’t equal security. What those people were getting at is that just because I have checked this box that says this thing’s in place doesn’t mean I’m actually secure. The control working doesn’t necessarily mean the organization’s protected. We need to make a shift from control execution to control effectiveness so that we can gain risk mitigation. There’s also the possibility, and this happens to fewer of those organizations, but there’s a possibility that you’ve got a zero day out there. But even in the case of a zero day, you’ve got a myriad of other controls that ought to be effective, where those detection mechanisms still have the ability to identify, “Hey, Houston, you got a problem.” Whether it’s identifying control bypass through monitoring of central logging, unusual user activity with behavioral analytics, file integrity monitoring if you’re seeing files changing within the environment, failed attempts from inside the network as attackers are trying this, trying that, and trying the other thing. There’s a reason why, even with zero days, it ends up seeing the light of day. It’s about mitigating the amount of time between, “Houston, we got a problem,” and knowing that you have a problem. Todd Coshow: What’s the difference between a control operating as designed and a control actually being effective? Adam Goslin: When it’s operating, you’re checking the box. This thing happened. But when a control is effective, it means that the risk was meaningfully reduced. You can have every single person in your organization going and attending security awareness training and seeing their quarterly security reminders and the piece of paper that’s taped up on the inside of the bathroom door, and yet employees still fall for phishing attempts. Maybe you’ve got a situation where an organization went in, ran their vuln scans, but they left vulnerabilities unpatched for a period of time. There’s gonna be some period of time between recognition that I have a vulnerability and getting it cured, and depending on how long of a span that is. It doesn’t necessarily have to be just critical vulnerability. A lot of people will obviously focus in on critical vulnerabilities. But what they seem to miss in their vulnerability management is that oftentimes I can take two or three medium-level vulnerabilities and conjoin them to create something that’s far more impactful.
August 6, 202629 min
Government AI Regulations That Could Impact Your Company - Episode 228
AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement and the growing patchwork of U.S. state laws to California’s sweeping AI legislation and the EU AI Act. Learn why AI compliance is now a business-critical issue, how third-party AI doesn’t shift liability, and what organizations must do to avoid enforcement, reputational damage, and costly mistakes. Essential listening for compliance, security, legal, product, and business leaders. Episode Transcript: Today, Adam, we are going to do a deep dive specifically about government AI regulations that could apply to your company. There are a lot of moving parts related to AI these days. Get us started on this one, Adam. Adam Goslin: Sure thing. As AI has left the barn and is starting to become a barn burner of sorts, it’s more integrated into our lives. Government entities are realizing that they need to regulate the use for both consumer and citizen safety. There’s new government laws that are constantly being introduced. Organizations are gonna find themselves trying to accommodate a bunch of different laws that aren’t aligned with one another. This reminds me a lot of how breach notification laws started splaying out within the US, with having state-level regulations and there being a ton of complication coming into that arena. We’re heading down the same path with the AI arena. Both in the US and EU, there have been AI laws and regulations that have been enacted that will affect businesses today, even if you aren’t located within those jurisdictions. The problem is that failures for complying with those regulations could result in millions of dollars in fines for a given company. It’s definitely something that the folks out there are gonna wanna pay attention to and keep their ear to the ground on. Todd Coshow: What do we have in the US at the federal level right now related to AI? Adam Goslin: Some, not a ton. There isn’t yet a federal-level law that’s regulating AI. But there’s two different governing arms of AI regulation in the US, namely coming into play in terms of there’s a federal executive order out there. There’s also a Federal Trade Commission, or FTC. Those two are laying the foundation for the eventual federal AI. The FTC isn’t exactly taking prisoners, so to speak. We’ll start with the executive order. There was an executive order put out that just came out on June 2nd of ’26, promoting advanced artificial intelligence innovation security. That’s the closest thing we have to really a federal-level edict at this point in the game. The key provisions within that directive included a frontier model framework that was directing federal agencies, including NSA, CISA, to put together classified benchmarks for advanced AI. It also establishes a voluntary process for developers to grant the government early access to covered frontier models for up to 30 days in advance of the public release. For those that aren’t in the know, what’s an AI frontier model? It’s a really large general-purpose AI system that represents the bleeding edge or state-of-the-art in AI technology. The frontier models are trained on vast data sets. It often costs organizations either tens to hundreds of millions of dollars to develop. Those systems will possess advanced reasoning and planning capabilities for predictive work, multi-step workflows, debugging code, solving complex novel problems. They can also act as digital agents that use external tools, otherwise known as APIs, and trigger autonomous action. That executive order is pushing for the creation of an AI cybersecurity clearing house. It’s a voluntary collaboration with the AI industry and critical infrastructure operators to coordinate vulnerability scanning, patch distribution, threat validation, creating a central repository that’s fed into by a bunch of different organizations.
July 30, 202621 min
Making Sure Your Compliance Program Keeps Up - Episode 227
Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up. Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations. Episode Transcript: Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic. How far behind is your compliance program, and how would you even know, Adam? Adam Goslin: My compliance program’s amazing. Todd Coshow: Answering the philosophical question, not being a smartass. Adam Goslin: A lot of organizations don’t know. Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak. Part of the problem is that the expectations are changing fast these days. You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation. In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.” Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.” But from the outside perspective, you’re starting off already behind the eight ball, if you will. Todd Coshow: It definitely feels that way. It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that? Adam Goslin: Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable. Kind of a combination of boogeyman sense and Skynet vibes going on. Effectively, it’s a matter of risk is moving faster than regulators are comfortable with. AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time. You’re seeing a lot of changes happening. Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc. AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws. It’s a lot of different things all simultaneously churning. It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there. In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up. Todd Coshow: Where do organizations tend to fall apart when responding to all of this change? Adam Goslin: A lot of times they’ll treat each regulation like a separate project. Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream. In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.
July 23, 202636 min
Ready to Get Serious About Compliance? - Episode 226
Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success. You'll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden. Episode Transcript: Adam, today we are ready to get serious. That’s right, we are ready to get serious about compliance. If there’s anyone that I know that’s serious about compliance, it’s you, sir. Help set the stage on this one. Adam Goslin: For a lot of organizations, when they started going up against security and compliance, they didn’t have any clue when they started just how much of an investment it was going to end up being. Maybe the organization was initially hoping they could do a check-the-box approach to compliance. “Oh, if we just put all our crap there, everything magically happens,” or whatever the snake oil salesman was busy hawking your direction at the time. But if you actually care about the security posture of your organization, then you know that approach isn’t going to make the grade. You can rest assured your customers expect to see detailed proof that you are indeed taking security and compliance seriously. More and more, it’s becoming the standard or the norm that organizations will validate and vet the organizations that they choose to trust with their data. Your organization’s going to be no different. If your organization fits into this category and it’s time to take your compliance program to the next level, then it’s a major step forward for the organization. You’re going to need to get strategic about making sure you’re covering all the bases and evaluating and addressing several parts: people resources, the processes that you undertake, as well as where your existing technological approach to compliance stands in the grand scheme of things. All of those are going to come into play as you’re going through the process. If you fall into that category, you landed on the right podcast. Todd Coshow: Indeed. As part of an organization’s leveling up their compliance program, tell me more about the people they should be looking to have as part of their compliance strategy, and some of the pitfalls that organizations run into there. Adam Goslin: It’s all about having the right people. One of the big mistakes that I’ll see organizations make time after time when they say, “Okay, we’re going to take compliance seriously,” is that, no offense to the assessors of the world, they just go hire an assessor out of the gate. They think, “The assessor knows what they’re doing, and the assessor will be able to get the answers and help to get the company’s act together.” But I wouldn’t recommend that be step one. It doesn’t work well because the assessor, as weird as this sounds to articulate, isn’t responsible for sitting and guiding the company through a compliance engagement. They may be happy to charge you a hell of a lot more to hold your hand and walk you through it. But effectively, the organizations that do that become the problem children to the assessors. It’s like, “Oh my God, this is the never-ending engagement because these guys aren’t anywhere near ready to go.” For many assessors, they’ll have a readiness notion because they’ve been burned so many times with this exact thing happening. They’ll do an assessment up front of, “Is this organization actually ready to bring in an assessor or not?” You’ll be having conversations about the things that you don’t have in place with the person who is charged with assessing your organization’s current state of compliance. You end up revealing a whole ton of dirty laundry through the process.
July 16, 202619 min
Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225
On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status. Episode Tracking: Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet. That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say. Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it? Adam Goslin: If we’re talking about my engagement, how long would it take? Seconds. But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit. This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet. I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.” All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch. “Hold on a second. I think it’s over here.” They go and look over there. “Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.” No, it’s not there either. “You know what? Evan knows exactly where it’s at. Give me one second.” Ring, ring, ring, ring. His phone went to voicemail. “Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?” It was an effing nightmare. A lot of people think that they know where things are until they’re under the gun and have to prove it. If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game. It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it. It really degrades their sense that the people they’re talking to actually have their act together. Todd Coshow: I can definitely appreciate that. Spreadsheets are still everywhere in compliance, but why are they such a problem? Adam Goslin: Spreadsheets weren’t designed to manage living, breathing systems. We’ve talked before about the levels of complexity that exist within these things. A spreadsheet is static, and compliance isn’t. There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against. You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states. If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane. The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.
July 9, 202626 min
Q3 Security Insights 2026 - Episode 224
In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions. The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds. If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you. Episode Transcript: It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026. As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy. As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly. Also, feel free to reach out to us at complianceunfiltered@totalcompliancetracking.com. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us. Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more. Adam Goslin: In the grand scheme of things, it is a capability that some organizations struggle with. Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no? When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request. There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof. This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy. It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly. Certainly, safeguarding internal reports is one arena we’re going to get into. As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports. There’s a myriad of information within them that external entities don’t have any right or reason to see. In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution. The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those. Only issuing your externally appropriate summary of your security posture to third parties is appropriate. The next arena I want to touch on is a centralized distribution channel. One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.
July 2, 202624 min
Building AI Agents Securely - Episode 223
AI agents are driving efficiency, but also introducing serious, often unseen security risks. As adoption accelerates, unvetted access, prompt injection, and poorly controlled environments can expose sensitive data and disrupt operations. This episode of Compliance Unfiltered breaks down the key threats and shows how to mitigate them using proven principles like least privilege, input validation, and isolated execution. Learn how to secure AI deployments and turn a growing risk into a resilient advantage. Episode Transcript: You’ve been talking about the AI zombie walk for some period of time now. What perils are folks walking into with AI agents? Adam Goslin: We’ve got the democratization of agentic AI on the march. Anybody can get the latest tools and create these incredible AI agents that can do almost anything you can imagine. It’s part of the main reason why the agentic AI move can be a substantive risk for the organization as well. One of the big problems they’re having right now is that, while security and compliance folks understand the risks of AI, there are a ton of frontline users that are just clicking buttons and building tools and making things automated and better. There isn’t, in a lot of cases, any thought to the security implications of what they’re in the process of doing. Thinking about security isn’t an element of day-by-day workflow, and that’s where this notion of agentic AI comes in riskiest, if you will. Leveraging platforms for building these AI agents without a security background, I’d liken it to giving a three-year-old an arc welder. It might be able to figure out how to turn it on, but can you imagine the untold damage that they could do with it? You put a powerful AI tool in the hands of people that don’t know about protecting data, layers of security, and how to appropriately restrict access. They’re not going to know how to use it safely. There are a lot of considerations when it comes down to building AI agents in a secure fashion. But most of it honestly comes down to security principles. It’s possible for employees to build those safely, but there needs to be that marrying of the security and compliance-style mindset in conjunction with what’s going on. Todd Coshow: What type of efficiency risks are folks running into? Adam Goslin: AI agents are often used for personal efficiency and internal workplace functions. To give some examples: consolidating, summarizing, and filtering across multiple email accounts; automated execution of auto-replies; analyzing workflows and calendars for identifying efficiencies; gathering up data; and preparing written summaries of client projects. These things may seem harmless, but just consider the risk of letting the AI agent loose on your calendar. How much data did you just expose as a result of clicking, “Sure, you’re going to have full access to my calendar”? The agent has access to your client lists, client contacts, emails, signatures, phone numbers, and cell phone numbers. All of that starts to come into play as you’re granting blind access to Office 365, as an example. Maybe that extends to OneDrive and SharePoint. Maybe, depending on the user and their access levels, they could be granting a ton of access. Even things that seem innocent, such as tracking birthdays or anniversaries, could similarly produce greater levels of exposure than you were even considering. The company needs to consider what is the data and information that’s exposed to the AI engine, how do we want to use it, and whether or not that data is secluded from other things. If you’re moving from a free version to a paid version of AI, your users may still be jammed into some gigantic public pool of data storage. Even when the AI vendors are claiming, “We don’t hand your data over to public AI models,” you need to look closely at what they are doing, such as utilizing the information that’s gleaned from the individual users when it comes to training their engines.
June 25, 202618 min
AI-Powered Attacks: Is Your Compliance Program Already Obsolete? - Episode 222
In an era of evolving AI-driven cyberattacks, traditional compliance programs are falling dangerously behind. Static controls create a false sense of security while attackers leverage AI to move faster, exploit vulnerabilities, and bypass defenses. On this week's Compliance Unfiltered, Todd Coshow and compliance expert Adam Goslin explore how AI is reshaping threats, why checkbox compliance is obsolete, and how organizations must shift to continuous, real-time assurance to stay resilient, protect data, and keep pace with modern adversaries. Episode Transcript: Today, we’re going to talk about the nefarious. That’s right, the artificially nefarious. In fact, AI-powered attacks. Is your compliance program already obsolete? But before we do so, Adam, as always, we want to say a special thank you to listeners of this podcast. Tell your compliance friends, if they’re not listening to us already, let them know that it’s something that you enjoy doing, and they might as well. Also, if you have any questions, topics, or general compliments you want to send our way, please do so at ComplianceUnfiltered@TotalComplianceTracking.com. As I mentioned, Adam, AI-powered attacks are something that’s on everybody’s mind these days. I guess the question is: if AI is fundamentally changing how attacks are executed—faster, smarter, more adaptive—are most compliance programs already outdated? Adam Goslin: In a lot of cases, yeah. It’s not because of some type of poor design, but a lot of the programs that exist now were founded in advance of the advent of AI, built in a different time, if you will. A lot of the compliance programs have certain assumptions baked in: stability, known systems, predictive behavior, human-driven threats. AI is really putting a gaping hole in that assumption, if you will. You’ve got attacks these days that can adapt midstream. They can mimic a legitimate user and scale with a speed that wasn’t possible before. Compliance is still, in many cases, measuring control effectiveness and measuring controls being in place at fixed points in time. It isn’t necessarily that the compliance is wrong, but it’s operating on a timeline that’s not matching up to today’s newfangled AI-world reality. Todd Coshow: Fair enough. Where do you see the biggest disconnect today between what compliance frameworks validate and what’s actually happening inside an environment? Adam Goslin: One of the biggest gaps is between existence and effectiveness. Frameworks are good at confirming controls exist. There is a policy. Here it is. There’s a process, and there’s evidence. But they’re not consistently validating that the control is working under real-world conditions, and quite frankly, the real world is changing under our feet, if you will, especially when it comes to these AI-driven attacks. You’ve got organizations that hold up their piece of paper and say, “Hey, big green checkbox, we’re compliant.” But the controls, in some cases, are bypassed shortly after the validation that, at that point in time, they were working. In many cases, the controls aren’t getting tested against how attack patterns are really behaving in the real world these days. Todd Coshow: You’ve talked about organizations having a false sense of their own state of compliance. How does AI make that problem even worse? Adam Goslin: AI accelerates the drift and buries it, if you will. Controls have a tendency to degrade over time. Access reviews get stale. Monitoring gets noisy and ignored. That type of stuff was already happening. But AI allows for the exploit of those gaps faster than many organizations are set up to detect them. Now you’re sitting here with a situation where, on the one side, I’m technically compliant because of my last audit. But operationally, I’m not compliant because the environment has modified or changed, and the attackers are jumping on those gaps immediately.
June 18, 202620 min
Compliance Theater: Are You Actually Secure or Just Checking Boxes? - Episode 221
Most organizations are just performing compliance – ticking boxes, not building real security. What happens when the curtain is pulled back on these check-the-box programs? You might be under the illusion of safety, but in reality, you're exposing your organization to serious risks.In this eye-opening episode, Todd Coshow and cybersecurity expert Adam Goslin reveal how many companies operate in “compliance theater,” creating an illusion of security to meet audit deadlines without safeguarding their environment. They unpack the stark difference between being audit-ready and genuinely secure, exposing how superficial policies, outdated evidence, and a mindset focused on passing assessments put your company at risk. Episode Transcript: The topic for today really boils down to whether or not folks out there are actually secure or if they’re just checking boxes. So let’s start with the tough one. Are organizations actually secure or just really good at checking the bare minimum boxes before the auditor shows up? Adam Goslin: If we’re being honest about it, most of them are performing. There are too many organizations out there to count that their view of navigating their security and compliance waters is doing the least preparation that’s humanly possible in advance of their audit or their assessment. They’re just trying to get through the process. In a lot of cases, it’s like a mantra: “We have to check. We’re being forced to do this, and we’re doing as little as we can just so that we can achieve the little piece of paper that says we’re secure.” They know what they need to show to the assessor, when to show it, and how to package it. But there’s a stark difference between organizations that are actually operationally secure, really taking this stuff seriously, etc. It also doesn’t provide any proof that everything’s going to be cooking with gas come some random Tuesday in March. Security isn’t a moment-in-time thing, where unfortunately most of the assessments and audits are. Todd Coshow: When we say compliance theater, what does that actually mean in practice? Where do you see organizations just going through the motions instead of building real security? Adam Goslin: Compliance theater is when your program’s built to prove something instead of actually demonstrating or doing something. That’s where you see compliance theater coming into play. Maybe it rears its head with screenshots that are cobbled together the day before the assessment. Maybe it’s policies that get refreshed once a year and, other than that, collect dust somewhere. It’s controls that exist but aren’t truly implemented or operationalized. Probably one of the biggest signs for an organization is when there’s this crescendo of compliance effort that happens with their annual assessment, and then all of a sudden, the second the auditor leaves, everybody’s wiping the sweat off their brow: “Thank God we made it through that one.” Everybody goes back to their day jobs and waits another nine or ten months before they have to prep for their next cycle. That’s the epitome of the compliance theater arena. Todd Coshow: Talking about the audit-versus-reality gap, how big is the gap between passing the audit, like PCI, SOC 2, ISO, and what’s actually happening on a day-to-day basis inside of an environment? Adam Goslin: There’s a bigger gap than folks want to admit. If you’re passing an audit or an assessment, that means that you’ve met the minimum bar at a specific point in time. But it doesn’t necessarily mean that the controls are being consistently applied across the environment throughout the compliance cycle. It doesn’t mean that you’re keeping your evidence fresh. It doesn’t mean that the team may even understand what they have or what they do. All I know is that for this particular requirement, I had to go into this interface, click these buttons, grab this information, this screenshot, and poof.
Is this your show?
Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.