Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED


Podcast Preview: GRC Uncensored and the commoditization of compliance
Manage episode 444512599 series 3462572
We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.
This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.
-----
In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.
The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.
00:00 Welcome to GRC Uncensored
01:34 Introducing Kendra Cooley
02:05 Love-Hate Relationship with GRC
03:16 The SOC 2 Debate
04:33 Challenges with SOC 2 Audits
09:10 The Value of SOC 2 in the Industry
12:04 The Evolution of Compliance Frameworks
20:39 False Sense of Security in Compliance
24:46 The Buzz Around AI and Quantum
25:10 Staying Updated as a Security Professional
26:45 Challenges in Penetration Testing and Vendor Assessments
27:37 Compliance and Its Impact on Security
30:10 Government Regulations and Their Effectiveness
32:23 The Complexity of Privacy Laws
38:29 The Role of GRC Teams in Risk Management
42:30 Concluding Thoughts and Future Episodes
56 episodes
Manage episode 444512599 series 3462572
We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.
This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.
-----
In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.
The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.
00:00 Welcome to GRC Uncensored
01:34 Introducing Kendra Cooley
02:05 Love-Hate Relationship with GRC
03:16 The SOC 2 Debate
04:33 Challenges with SOC 2 Audits
09:10 The Value of SOC 2 in the Industry
12:04 The Evolution of Compliance Frameworks
20:39 False Sense of Security in Compliance
24:46 The Buzz Around AI and Quantum
25:10 Staying Updated as a Security Professional
26:45 Challenges in Penetration Testing and Vendor Assessments
27:37 Compliance and Its Impact on Security
30:10 Government Regulations and Their Effectiveness
32:23 The Complexity of Privacy Laws
38:29 The Role of GRC Teams in Risk Management
42:30 Concluding Thoughts and Future Episodes
56 episodes
All episodes
×
1 How Critical Infrastructure Leaders Are Rethinking Cybersecurity 44:32

1 Shadows Within Shadows: How AI is Challenging IT Teams 48:12

1 Live at ZTW2025: Cyberwire Daily’s Dave Bittner + Dr. Zero Trust 32:50

1 Rapid fire update: Silk Typhoon and DOJ's indictment of twelve Chinese nationals 3:20

1 Predicting the year of cybersecurity ahead (minus regulations) 1:02:52

1 Kicking Off Season 4 of Adoption Zero Trust (AZT) 22:43

1 The key to growing a cybersecurity career are soft skills 50:38

1 Behind the scenes of cybersecurity media and reporting 1:04:53

1 GRC tool or spreadsheets, that is the question | GRC Uncensored Preview 43:13

1 Podcast Preview: GRC Uncensored and the commoditization of compliance 41:30

1 How to prepare your operations team for Zero Trust 46:17

1 Log4j Continues to act as Organizational Vulnerability 47:56

1 Overturning of Chevron Deference’s Impact on Cybersecurity Regulation 51:44

1 Applying Vulnerability Management to Zero Trust 45:43

1 The Unstoppable Phish: A Discussion with Vivek Ramachandran 26:31
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.