<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="/global/feed/rss.xslt" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:podaccess="https://access.acast.com/schema/1.0/" xmlns:acast="https://schema.acast.com/1.0/">
    <channel>
		<ttl>60</ttl>
		<generator>acast.com</generator>
		<title>GRC Uncensored</title>
		<link>https://feeds.acast.com/public/shows/grc-uncensored</link>
		<atom:link href="https://feeds.acast.com/public/shows/6702dcb9c88f09c3e0b9a10a" rel="self" type="application/rss+xml"/>
		<language>en</language>
		<copyright>Elliot Volkman</copyright>
		<itunes:keywords>GRC,Cybersecurity,regulations,compliance,risk management</itunes:keywords>
		<itunes:author>Chaos</itunes:author>
		<itunes:subtitle>GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it.</itunes:subtitle>
		<itunes:summary><![CDATA[GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it. Your hosts are Troy Fine and Elliot Volkman.<hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		<description><![CDATA[GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it. Your hosts are Troy Fine and Elliot Volkman.<hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
		<itunes:explicit>false</itunes:explicit>
		<itunes:owner>
			<itunes:name>Elliot Volkman and Troy Fine</itunes:name>
			<itunes:email>elliot@elliotvolkman.com</itunes:email>
		</itunes:owner>
		<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
		<acast:showUrl>grc-uncensored</acast:showUrl>
		<acast:signature key="EXAMPLE" algorithm="aes-256-cbc"><![CDATA[wbG1Z7+6h9QOi+CR1Dv0uQ==]]></acast:signature>
		<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmTHg2/BXqPr07kkpFZ5JfhvEZqggcpunI6E1w81XpUaBscFc3skEQ0jWG4GCmQYJ66w6pH6P/aGd3DnpJN6h/CD4icd8kZVl4HZn12KicA2k]]></acast:settings>
        <acast:network id="6610cba5da0a080016302908" slug="elliot-volkman-6610cba5da0a080016302908"><![CDATA[Elliot Volkman]]></acast:network>
		<itunes:type>episodic</itunes:type>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<image>
				<url>https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg</url>
				<link>https://feeds.acast.com/public/shows/grc-uncensored</link>
				<title>GRC Uncensored</title>
			</image>
		<item>
			<title>AMA: GRC, SOC 2, and the State of Audits</title>
			<itunes:title>AMA: GRC, SOC 2, and the State of Audits</itunes:title>
			<pubDate>Wed, 31 Dec 2025 13:32:36 GMT</pubDate>
			<itunes:duration>47:23</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/695525f45f9b0b61aaaba4f2/media.mp3" length="45497033" type="audio/mpeg"/>
			<guid isPermaLink="false">695525f45f9b0b61aaaba4f2</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>695525f45f9b0b61aaaba4f2</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAUI1rr9WXxCYObkYvHTJ3PGuMxmGeHpGcmaUyPeR8wbPZhESXzwQYQS/R+ad/v6Zcu/JZqhgd8QkPKwi2W4ih9d]]></acast:settings>
			<itunes:subtitle>Our season one wrap is here, and we answered your questions (mostly)</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>22</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>It’s the last day of 2025, which means it’s time to wrap season one. When Troy and I piloted this series, we didn’t expect thousands of you to tune in, and certainly didn’t expect to pickup the wonderfully smart Kendra to join our crew.</p><br><p>With that, we want to thank you for encouraging us to keep this series going. We’ll be back for season 2 soon, and are taking in new pitches for episodes now. To wrap the year, we conducted a AMA on the current state of GRC. We pulled questions from <a href="https://old.reddit.com/r/cybersecurity/comments/1ppqcwg/ama_about_the_current_state_of_grc_conversation/" rel="noopener noreferrer" target="_blank">Reddit</a> and <a href="https://www.linkedin.com/posts/elliotv_join-troy-fine-and-kendra-cooley-of-grc-uncensored-activity-7407434398687703041-xrHw?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAJkq7oB5vp964tKu45smLzBSwV9ZnBhRPA" rel="noopener noreferrer" target="_blank">LinkedIn</a> and tackled them live in conversation.</p><p><br></p><h3>What we covered</h3><p><strong>Are we “anti–GRC automation tools”?</strong></p><p>Short answer: no. Long answer: automation isn’t the problem. It’s misuse, blind trust, and compromised audit integrity are.</p><br><p><strong>Cheap SOC 2s and bundled audits</strong></p><p>Why budget startups often <em>don’t</em> have a real incentive to avoid low-cost, bundled auditors, and what you give up when you go that route.</p><br><p><strong>SOC 2 pentesting vs PCI DSS</strong></p><p>Why SOC 2 allows weak or missing pentests, why PCI doesn’t, and how automated scans differ from real manual testing.</p><br><p><strong>Conflicts of interest in the GRC ecosystem</strong></p><p>Platforms, auditors, and vCISOs all partner, so where does objectivity break down, and is it even possible to keep it clean?</p><br><p><strong>Who’s really at fault: tools or auditors?</strong></p><p>A blunt discussion on incentives, accountability, and why low-quality audits keep winning.</p><br><p><strong>Offshoring and the race to the bottom</strong></p><p>When cost-cutting leads to offshoring, what should clients actually be worried about and what’s just noise.</p><br><p><strong>The future of audits and AI</strong></p><p>Will AI replace auditors? Where automation helps, where humans still matter, and what happens if we stop caring about independent assurance altogether.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>It’s the last day of 2025, which means it’s time to wrap season one. When Troy and I piloted this series, we didn’t expect thousands of you to tune in, and certainly didn’t expect to pickup the wonderfully smart Kendra to join our crew.</p><br><p>With that, we want to thank you for encouraging us to keep this series going. We’ll be back for season 2 soon, and are taking in new pitches for episodes now. To wrap the year, we conducted a AMA on the current state of GRC. We pulled questions from <a href="https://old.reddit.com/r/cybersecurity/comments/1ppqcwg/ama_about_the_current_state_of_grc_conversation/" rel="noopener noreferrer" target="_blank">Reddit</a> and <a href="https://www.linkedin.com/posts/elliotv_join-troy-fine-and-kendra-cooley-of-grc-uncensored-activity-7407434398687703041-xrHw?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAJkq7oB5vp964tKu45smLzBSwV9ZnBhRPA" rel="noopener noreferrer" target="_blank">LinkedIn</a> and tackled them live in conversation.</p><p><br></p><h3>What we covered</h3><p><strong>Are we “anti–GRC automation tools”?</strong></p><p>Short answer: no. Long answer: automation isn’t the problem. It’s misuse, blind trust, and compromised audit integrity are.</p><br><p><strong>Cheap SOC 2s and bundled audits</strong></p><p>Why budget startups often <em>don’t</em> have a real incentive to avoid low-cost, bundled auditors, and what you give up when you go that route.</p><br><p><strong>SOC 2 pentesting vs PCI DSS</strong></p><p>Why SOC 2 allows weak or missing pentests, why PCI doesn’t, and how automated scans differ from real manual testing.</p><br><p><strong>Conflicts of interest in the GRC ecosystem</strong></p><p>Platforms, auditors, and vCISOs all partner, so where does objectivity break down, and is it even possible to keep it clean?</p><br><p><strong>Who’s really at fault: tools or auditors?</strong></p><p>A blunt discussion on incentives, accountability, and why low-quality audits keep winning.</p><br><p><strong>Offshoring and the race to the bottom</strong></p><p>When cost-cutting leads to offshoring, what should clients actually be worried about and what’s just noise.</p><br><p><strong>The future of audits and AI</strong></p><p>Will AI replace auditors? Where automation helps, where humans still matter, and what happens if we stop caring about independent assurance altogether.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Do Ethical GRC auditors really exist?</title>
			<itunes:title>Do Ethical GRC auditors really exist?</itunes:title>
			<pubDate>Thu, 20 Nov 2025 13:30:00 GMT</pubDate>
			<itunes:duration>44:17</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/691d4e03295fc6e848f09498/media.mp3" length="42514053" type="audio/mpeg"/>
			<guid isPermaLink="false">691d4e03295fc6e848f09498</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>691d4e03295fc6e848f09498</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVTTDWqwvMfWwc2ivSL2uGmHkNqWkY5DC2bB2viA+3O2/yI5UdhZqlEgEXtX8NRzbSA9LHo4b/hCCiVZW9MU2Fs]]></acast:settings>
			<itunes:subtitle><![CDATA[The gang tries to define what ethics in compliance auditing is and if it's as elusive as Bigfoot]]></itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>21</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>In this episode, the crew digs into a messy but necessary topic: what does ethical auditing even mean in a market overrun with automation shortcuts, low-effort SOC 2 audits, and firms that self-declare “quality” without proving it?</p><br><p>With Troy actively auditing today and Kendra working with auditors in real time, the team breaks down where rigor actually shows up, where the system is broken, and why SOC 2’s value is slipping as fast as demand for speed is rising.</p><br><p><strong>03:00</strong> – “Quality theater” and firms self-labeling as high quality</p><p><strong>04:10</strong> – Who defines quality—auditors or customers?</p><p><strong>05:00</strong> – The four-hour SOC 2 audit example</p><p><strong>06:00</strong> – The danger of “better than the worst” logic</p><p><strong>07:00</strong> – What thorough auditing actually looks like (Kendra’s experience)</p><p><strong>09:30</strong> – SOC 2 inconsistency across auditors and firms</p><p><strong>11:00</strong> – Should audit firms be objectively measured?</p><p><strong>15:00</strong> – Kendra’s “secret shopper auditor” idea</p><p><strong>19:20</strong> – Automation platforms producing shallow “green checkmark” results</p><p><strong>22:00</strong> – Drive-by auditors rubber-stamping automated data</p><p><strong>26:00</strong> – Peer review and “enhanced oversight” gaps</p><p><strong>33:00</strong> – Why the industry isn’t incentivized to fix the quality problem</p><p><strong>39:00</strong> – Ethical auditors exist—but the system doesn’t reward them</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode, the crew digs into a messy but necessary topic: what does ethical auditing even mean in a market overrun with automation shortcuts, low-effort SOC 2 audits, and firms that self-declare “quality” without proving it?</p><br><p>With Troy actively auditing today and Kendra working with auditors in real time, the team breaks down where rigor actually shows up, where the system is broken, and why SOC 2’s value is slipping as fast as demand for speed is rising.</p><br><p><strong>03:00</strong> – “Quality theater” and firms self-labeling as high quality</p><p><strong>04:10</strong> – Who defines quality—auditors or customers?</p><p><strong>05:00</strong> – The four-hour SOC 2 audit example</p><p><strong>06:00</strong> – The danger of “better than the worst” logic</p><p><strong>07:00</strong> – What thorough auditing actually looks like (Kendra’s experience)</p><p><strong>09:30</strong> – SOC 2 inconsistency across auditors and firms</p><p><strong>11:00</strong> – Should audit firms be objectively measured?</p><p><strong>15:00</strong> – Kendra’s “secret shopper auditor” idea</p><p><strong>19:20</strong> – Automation platforms producing shallow “green checkmark” results</p><p><strong>22:00</strong> – Drive-by auditors rubber-stamping automated data</p><p><strong>26:00</strong> – Peer review and “enhanced oversight” gaps</p><p><strong>33:00</strong> – Why the industry isn’t incentivized to fix the quality problem</p><p><strong>39:00</strong> – Ethical auditors exist—but the system doesn’t reward them</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>SOC 2, Vibes, and the Audit Arms Race</title>
			<itunes:title>SOC 2, Vibes, and the Audit Arms Race</itunes:title>
			<pubDate>Wed, 22 Oct 2025 21:14:26 GMT</pubDate>
			<itunes:duration>46:59</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68f94798237885ef40ec4eff/media.mp3" length="45112505" type="audio/mpeg"/>
			<guid isPermaLink="false">68f94798237885ef40ec4eff</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://shows.acast.com/grc-uncensored/episodes/68f94798237885ef40ec4eff</link>
			<acast:episodeId>68f94798237885ef40ec4eff</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAU5XiHXGlht4QgEUIIwW1cnfTm8YVCMH5tCtlILVgnBb+JLETMdzR3D3NV/TjrgEXEhLA72RgsHsSFVLYN5xtDx]]></acast:settings>
			<itunes:subtitle><![CDATA[7 Minute abs with Wiz's CISO Expert Zlatko Unger]]></itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>20</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>This episode dives deep into the messy, absurd, and sometimes hilarious world of SOC 2 audits and compliance frameworks. Wiz CISO Expert Zlatko Unger joins the crew to talk about the expanding “acronym soup” of frameworks, the blurred lines between automation and assurance, and why finding an auditor who vibes with your team might matter more than the name on the certificate.</p><br><p>The crew also debates the future of SOC 2 — from fast-track “15-hour audits” to the rise of AI-generated reports — and whether the entire model needs a ground-up rebuild.</p><br><p>Guest: Zlatko Unger, CISO Expert at Wiz</p><p>Hosts: Troy Fine, Kendra Cooley, Elliot Volkman</p><br><p>00:03 — Framework overload</p><p>00:07 — Auditor “vibe check”</p><p>00:11 — SOC 2’s fall from grace</p><p>00:16 — TPRM and audit fatigue</p><p>00:25 — SOC 2 for robots</p><p>00:36 — Reform or rebuild?</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>This episode dives deep into the messy, absurd, and sometimes hilarious world of SOC 2 audits and compliance frameworks. Wiz CISO Expert Zlatko Unger joins the crew to talk about the expanding “acronym soup” of frameworks, the blurred lines between automation and assurance, and why finding an auditor who vibes with your team might matter more than the name on the certificate.</p><br><p>The crew also debates the future of SOC 2 — from fast-track “15-hour audits” to the rise of AI-generated reports — and whether the entire model needs a ground-up rebuild.</p><br><p>Guest: Zlatko Unger, CISO Expert at Wiz</p><p>Hosts: Troy Fine, Kendra Cooley, Elliot Volkman</p><br><p>00:03 — Framework overload</p><p>00:07 — Auditor “vibe check”</p><p>00:11 — SOC 2’s fall from grace</p><p>00:16 — TPRM and audit fatigue</p><p>00:25 — SOC 2 for robots</p><p>00:36 — Reform or rebuild?</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Clean Reports, Flawed Systems, and the Future of GRC</title>
			<itunes:title>Clean Reports, Flawed Systems, and the Future of GRC</itunes:title>
			<pubDate>Thu, 09 Oct 2025 12:00:00 GMT</pubDate>
			<itunes:duration>46:29</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68e67c6f79fd6a22445bcb20/media.mp3" length="44635196" type="audio/mpeg"/>
			<guid isPermaLink="false">68e67c6f79fd6a22445bcb20</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://shows.acast.com/grc-uncensored/episodes/68e67c6f79fd6a22445bcb20</link>
			<acast:episodeId>68e67c6f79fd6a22445bcb20</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAWn9/2YTd53K+Q9Xs6YcLqDSdbraKy8P6fHv5DeFJEsg7h3CvZMzum2tgAxhGaPlxhnzgyWoNZF82PNnIELeaV5]]></acast:settings>
			<itunes:subtitle>Evan Millman, GRC Manager at Abnormal Security offers a look at compliance blind spots and the role of AI in GRC</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>19</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>TJ, Kendra, and Elliot are back, and welcomed <a href="https://www.linkedin.com/in/evan-millman-cissp-2291261a/" rel="noopener noreferrer" target="_blank">Evan Millman</a>, GRC Manager at Abnormal Security, for what started as a casual chat and evolved into a sharp look at compliance blind spots, the role of AI in GRC, and how professionals can shape their careers in a changing field.</p><br><p><strong>[00:02:00]</strong> Evan shares how he used ChatGPT to analyze a risk assessment report.</p><p><strong>[00:05:00]</strong> What GRC leadership looks like at Abnormal Security (ISO 27001, 27701, 42001, SOC 2).</p><p><strong>[00:07:00]</strong> The complicated relationship between organizations and auditors — bias, incentives, and the reality of “clean” reports.</p><p><strong>[00:12:00]</strong> Why third-party attestations are table stakes, not real assurance.</p><p><strong>[00:19:00]</strong> TJ and Evan debate solutions: peer reviews, government oversight, or is the system fundamentally flawed?</p><p><strong>[00:27:00]</strong> How Abnormal approaches vendor risk: criticality ratings, renewals, and compensating controls.</p><p><strong>[00:32:00]</strong> Tools and automation in GRC — benefits and buyer’s remorse.</p><p><strong>[00:36:00]</strong> The role of AI: evidence review, documentation search, and “trust but verify.”</p><p><strong>[00:39:00]</strong> Should GRC professionals become coders, or double down on soft skills?</p><p><strong>[00:44:00]</strong> Evan’s career advice: networking, persistence, and why soft skills matter more than technical depth.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>TJ, Kendra, and Elliot are back, and welcomed <a href="https://www.linkedin.com/in/evan-millman-cissp-2291261a/" rel="noopener noreferrer" target="_blank">Evan Millman</a>, GRC Manager at Abnormal Security, for what started as a casual chat and evolved into a sharp look at compliance blind spots, the role of AI in GRC, and how professionals can shape their careers in a changing field.</p><br><p><strong>[00:02:00]</strong> Evan shares how he used ChatGPT to analyze a risk assessment report.</p><p><strong>[00:05:00]</strong> What GRC leadership looks like at Abnormal Security (ISO 27001, 27701, 42001, SOC 2).</p><p><strong>[00:07:00]</strong> The complicated relationship between organizations and auditors — bias, incentives, and the reality of “clean” reports.</p><p><strong>[00:12:00]</strong> Why third-party attestations are table stakes, not real assurance.</p><p><strong>[00:19:00]</strong> TJ and Evan debate solutions: peer reviews, government oversight, or is the system fundamentally flawed?</p><p><strong>[00:27:00]</strong> How Abnormal approaches vendor risk: criticality ratings, renewals, and compensating controls.</p><p><strong>[00:32:00]</strong> Tools and automation in GRC — benefits and buyer’s remorse.</p><p><strong>[00:36:00]</strong> The role of AI: evidence review, documentation search, and “trust but verify.”</p><p><strong>[00:39:00]</strong> Should GRC professionals become coders, or double down on soft skills?</p><p><strong>[00:44:00]</strong> Evan’s career advice: networking, persistence, and why soft skills matter more than technical depth.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>AI Guardrails, Foot Guns, and the Ostrich Problem</title>
			<itunes:title>AI Guardrails, Foot Guns, and the Ostrich Problem</itunes:title>
			<pubDate>Thu, 25 Sep 2025 10:00:00 GMT</pubDate>
			<itunes:duration>43:19</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68d44770d4ea86dd593c5baa/media.mp3" length="41594549" type="audio/mpeg"/>
			<guid isPermaLink="false">68d44770d4ea86dd593c5baa</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>68d44770d4ea86dd593c5baa</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVKN57sPVLjky2xnrhzgMwU9Z99k/SEdG6RUi1AbD1Ipwe3gqBlvZp6wI2owm+zIM1x57fELdH+R46brAxobe4L]]></acast:settings>
			<itunes:subtitle>CSO Merritt Baer offers a candid conversation about the collision between AI, governance, and security. </itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>18</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>This week on <em>GRC Uncensored</em>, hosts Troy Fine and Elliot Volkman sat down with <a href="https://www.linkedin.com/in/merrittbaer/" rel="noopener noreferrer" target="_blank">Merritt Baer</a>, Chief Security Officer at <a href="https://www.enkryptai.com/" rel="noopener noreferrer" target="_blank">Enkrypt AI</a>, for a candid conversation about the collision between AI, governance, and security. Merritt brought decades of CISO experience — from AWS to the intelligence community — and didn’t hold back, fully embracing our podcast name, on what’s hype, what’s real, and what CISOs should be doing today.&nbsp;</p><p><br></p><h3>Key Moments</h3><ul><li><strong>[00:03:00]</strong> – How Merritt uses ChatGPT to re-voice her own drafts — and why she immediately strips out the “saccharine” endings.</li><li><strong>[00:05:30]</strong> – Why security and innovation don’t need to “hold hands” — they just need shared expectations.</li><li><strong>[00:08:45]</strong> – <em>The “foot guns” moment</em>: how an accounting firm’s chatbot started teaching customers to hide assets from the IRS.</li><li><strong>[00:13:30]</strong> – Why most enterprises don’t even know where AI is being used internally.</li><li><strong>[00:15:00]</strong> – How to build guardrails that are realistic, enforceable, and tuned over time.</li><li><strong>[00:24:30]</strong> – Why “ostrich” policies will fail — and how enforcement actions, not regulations, will shape AI accountability.</li><li><strong>[00:40:00]</strong> – Merritt’s closing advice for CISOs: you don’t need to be an expert, but you do need a plan.</li></ul><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>This week on <em>GRC Uncensored</em>, hosts Troy Fine and Elliot Volkman sat down with <a href="https://www.linkedin.com/in/merrittbaer/" rel="noopener noreferrer" target="_blank">Merritt Baer</a>, Chief Security Officer at <a href="https://www.enkryptai.com/" rel="noopener noreferrer" target="_blank">Enkrypt AI</a>, for a candid conversation about the collision between AI, governance, and security. Merritt brought decades of CISO experience — from AWS to the intelligence community — and didn’t hold back, fully embracing our podcast name, on what’s hype, what’s real, and what CISOs should be doing today.&nbsp;</p><p><br></p><h3>Key Moments</h3><ul><li><strong>[00:03:00]</strong> – How Merritt uses ChatGPT to re-voice her own drafts — and why she immediately strips out the “saccharine” endings.</li><li><strong>[00:05:30]</strong> – Why security and innovation don’t need to “hold hands” — they just need shared expectations.</li><li><strong>[00:08:45]</strong> – <em>The “foot guns” moment</em>: how an accounting firm’s chatbot started teaching customers to hide assets from the IRS.</li><li><strong>[00:13:30]</strong> – Why most enterprises don’t even know where AI is being used internally.</li><li><strong>[00:15:00]</strong> – How to build guardrails that are realistic, enforceable, and tuned over time.</li><li><strong>[00:24:30]</strong> – Why “ostrich” policies will fail — and how enforcement actions, not regulations, will shape AI accountability.</li><li><strong>[00:40:00]</strong> – Merritt’s closing advice for CISOs: you don’t need to be an expert, but you do need a plan.</li></ul><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>The Softer (and Sometimes Spicier) Side of GRC</title>
			<itunes:title>The Softer (and Sometimes Spicier) Side of GRC</itunes:title>
			<pubDate>Thu, 28 Aug 2025 10:00:00 GMT</pubDate>
			<itunes:duration>48:36</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68acb246982c36846e8d8072/media.mp3" length="46670663" type="audio/mpeg"/>
			<guid isPermaLink="false">68acb246982c36846e8d8072</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>68acb246982c36846e8d8072</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVo1H9jemjt2G/x3dYCCxKS11hyBQsuQcRfj8pRxmtk9TSyyW2sShAJ1bImkDFKzJG7nzjmDiXxJhzCFI3MeDtc]]></acast:settings>
			<itunes:subtitle>Why SOC 2 may be living on borrowed time, and what comes next for GRC</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>17</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>In the latest episode of <strong>GRC Uncensored</strong>, hosts <strong>Kendra Cooley</strong> and <strong>Troy Fine</strong> sat down with <a href="https://www.linkedin.com/in/jakeleobernardes/" rel="noopener noreferrer" target="_blank"><strong>Jake Bernardes</strong></a>, CISO of <a href="https://www.anecdotes.ai/" rel="noopener noreferrer" target="_blank">Anecdotes</a> and host of <em>Risking It All</em>, to talk about the positive side of GRC. What unfolded was less about sugar-coating and more about the tensions shaping our industry from AI disruption to the shaky future of SOC 2 reports. More specifically, is there a world where we see a consolidation of regulations and frameworks in response to the sprawl we see now?</p><br><p><strong>[00:02:00] AI and Auditing</strong> – Will automation replace auditors or make them indispensable?</p><p><strong>[00:06:00] The Positive Side of GRC</strong> – How automation is reshaping the auditor’s role.</p><p><strong>[00:15:00] Are Compliance Platforms Lowering the Bar?</strong> – Check-the-box programs vs. meaningful assurance.</p><p><strong>[00:23:00] The SOC 2 Debate</strong> – Is it still valuable, or creating a false sense of security?</p><p><strong>[00:30:00] Toward Continuous Assurance</strong> – Dynamic trust centers and evidence as the new currency.</p><p><strong>[00:40:00] The Future of Risk in GRC</strong> – Why risk registers must evolve and become data-driven.</p><p><strong>[00:46:00] Closing Thoughts</strong> – Optimism about where GRC is headed despite today’s challenges.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In the latest episode of <strong>GRC Uncensored</strong>, hosts <strong>Kendra Cooley</strong> and <strong>Troy Fine</strong> sat down with <a href="https://www.linkedin.com/in/jakeleobernardes/" rel="noopener noreferrer" target="_blank"><strong>Jake Bernardes</strong></a>, CISO of <a href="https://www.anecdotes.ai/" rel="noopener noreferrer" target="_blank">Anecdotes</a> and host of <em>Risking It All</em>, to talk about the positive side of GRC. What unfolded was less about sugar-coating and more about the tensions shaping our industry from AI disruption to the shaky future of SOC 2 reports. More specifically, is there a world where we see a consolidation of regulations and frameworks in response to the sprawl we see now?</p><br><p><strong>[00:02:00] AI and Auditing</strong> – Will automation replace auditors or make them indispensable?</p><p><strong>[00:06:00] The Positive Side of GRC</strong> – How automation is reshaping the auditor’s role.</p><p><strong>[00:15:00] Are Compliance Platforms Lowering the Bar?</strong> – Check-the-box programs vs. meaningful assurance.</p><p><strong>[00:23:00] The SOC 2 Debate</strong> – Is it still valuable, or creating a false sense of security?</p><p><strong>[00:30:00] Toward Continuous Assurance</strong> – Dynamic trust centers and evidence as the new currency.</p><p><strong>[00:40:00] The Future of Risk in GRC</strong> – Why risk registers must evolve and become data-driven.</p><p><strong>[00:46:00] Closing Thoughts</strong> – Optimism about where GRC is headed despite today’s challenges.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>The TPRM Tug-of-War: Trust, Tools, and the AI Tradeoff</title>
			<itunes:title>The TPRM Tug-of-War: Trust, Tools, and the AI Tradeoff</itunes:title>
			<pubDate>Thu, 31 Jul 2025 10:00:00 GMT</pubDate>
			<itunes:duration>50:22</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/688ab3d5be8bca0ca2c692d7/media.mp3" length="48355038" type="audio/mpeg"/>
			<guid isPermaLink="false">688ab3d5be8bca0ca2c692d7</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>688ab3d5be8bca0ca2c692d7</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVmALi62quypTHTgEELctwjQbpv4jhPGyfT4IE8wKmUijOVVj3zTXTbpl1aPh18H9vgh5Dw+lnYWYwpzU02d2DZ]]></acast:settings>
			<itunes:subtitle>Henry Stanley joins to talk third-party risk management. He covers why it isn’t broken, but rather fragmented, inefficient, and ripe for a more human-centered approach.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>16</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>This week, the crew sits down with Henry Stanley—founder of Fabrik and engineer-turned-GRC troublemaker-to dig into the messy reality of third-party risk management (TPRM). With experience across fintech, startups, and security consulting, Henry brings a pragmatic but optimistic view of how the industry can move forward.</p><br><p>From the limits of SOC 2 and the myth of standardization to the risks and rewards of AI-powered questionnaires, the group unpacks why TPRM is so fragmented—and why that’s not necessarily a bad thing. They also get real about AI in audits, the future role of assurance professionals, and why human connection still matters.</p><br><p>06:30 – Why TPRM Is Fragmented by Nature</p><p>09:00 – SOC 2 Isn’t Enough (And Never Was)</p><p>13:30 – Does Anyone Really Trust Audit Reports?</p><p>17:30 – Blacklists, Quality Checks &amp; the SOC 2 Vibe Check</p><p>20:00 – The Rise of AI in Vendor Assessments</p><p>25:30 – AI Answers vs. AI Confidence</p><p>28:30 – Auditing the Auditors (and Their AI)</p><p>32:00 – Reasonable Assurance in an AI World</p><p>35:30 – Skepticism, Trust, and Human-in-the-Loop Auditing</p><p>38:00 – Does AI Kill Creativity? A Side Quest</p><p>44:00 – Will TPRM Be Agent-to-Agent in the Future?</p><br><p>Guest: Henry Stanley, Founder of Security Program.io</p><p>Hosts: Troy Fine, Kendra Cooley</p><p>Producer: Elliot Volkman</p><p>Runtime: ~56 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>This week, the crew sits down with Henry Stanley—founder of Fabrik and engineer-turned-GRC troublemaker-to dig into the messy reality of third-party risk management (TPRM). With experience across fintech, startups, and security consulting, Henry brings a pragmatic but optimistic view of how the industry can move forward.</p><br><p>From the limits of SOC 2 and the myth of standardization to the risks and rewards of AI-powered questionnaires, the group unpacks why TPRM is so fragmented—and why that’s not necessarily a bad thing. They also get real about AI in audits, the future role of assurance professionals, and why human connection still matters.</p><br><p>06:30 – Why TPRM Is Fragmented by Nature</p><p>09:00 – SOC 2 Isn’t Enough (And Never Was)</p><p>13:30 – Does Anyone Really Trust Audit Reports?</p><p>17:30 – Blacklists, Quality Checks &amp; the SOC 2 Vibe Check</p><p>20:00 – The Rise of AI in Vendor Assessments</p><p>25:30 – AI Answers vs. AI Confidence</p><p>28:30 – Auditing the Auditors (and Their AI)</p><p>32:00 – Reasonable Assurance in an AI World</p><p>35:30 – Skepticism, Trust, and Human-in-the-Loop Auditing</p><p>38:00 – Does AI Kill Creativity? A Side Quest</p><p>44:00 – Will TPRM Be Agent-to-Agent in the Future?</p><br><p>Guest: Henry Stanley, Founder of Security Program.io</p><p>Hosts: Troy Fine, Kendra Cooley</p><p>Producer: Elliot Volkman</p><p>Runtime: ~56 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Will FedRAMP 20x Repeat SOC 2’s Mistakes?</title>
			<itunes:title>Will FedRAMP 20x Repeat SOC 2’s Mistakes?</itunes:title>
			<pubDate>Thu, 17 Jul 2025 09:00:00 GMT</pubDate>
			<itunes:duration>58:27</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/6877eaf46fb6cef50fe4c568/media.mp3" length="56123224" type="audio/mpeg"/>
			<guid isPermaLink="false">6877eaf46fb6cef50fe4c568</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>6877eaf46fb6cef50fe4c568</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVvKZVhjLYq1sNGD8RyMLp05PjVCGmPeehUB/8ykoZ0la1vENcKL4F7lw12JzISo7HRM8avzpEiekmh2DN3tqQJ]]></acast:settings>
			<itunes:subtitle>The shift to streamlined controls and automation sounds promising, until you remember what happened last time. We chat with FedRAMP expert John Santore.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>15</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>This week on GRC Uncensored, the crew welcomes John Santore, a longtime FedRAMP and SOC 2 practitioner who has seen firsthand how compliance frameworks evolve, and sometimes unravel. Now serving as Director of Cyber Acceleration at Constellation GovCloud, John joins Troy and Elliot to unpack FedRAMP 20x, a new pilot program designed to streamline the U.S. government’s cloud authorization process dramatically.</p><br><p>The promise? Fewer controls, faster approvals, and greater automation.The concern? That all sounds a little too familiar.</p><br><p>Together, they explore whether&nbsp;FedRAMP 20x&nbsp;is an overdue modernization or the start of a dangerous slide toward the kind of checkbox compliance that has made SOC 2 certifications easier to get but harder to trust. From control mapping and auditor disruption to agency adoption and AI-assisted audits, this episode provides a deep dive into what happens when good frameworks move too quickly and how to maintain trust when they do.</p><br><p>[00:01:00] – Guest intro: John’s history with SOC 2, FedRAMP, and working with Troy</p><p>[00:06:00] – How SOC 2 influenced John’s transition into federal compliance</p><p>[00:08:00] – What is FedRAMP 20x, and why is it happening now?</p><p>[00:10:00] – From 12-month review cycles to fast-tracking assessments</p><p>[00:14:00] – Key Security Indicators (KSIs): replacing hundreds of controls with a handful of validations</p><p>[00:18:00] – Are KSIs basically just vague control summaries? (Spoiler: yes)</p><p>[00:22:00] – Why GRC platforms are being prioritized in the pilot</p><p>[00:25:00] – Potential expansion to FedRAMP Moderate and High</p><p>[00:28:00] – Will agencies even accept this?</p><p>[00:31:00] – Advice for cloud service providers evaluating FedRAMP now</p><p>[00:34:00] – Is FedRAMP on the path to commoditization?</p><p>[00:39:00] – Evaluating rigor vs. relevance: security posture ≠ certification</p><p>[00:44:00] – The problem of vague frameworks and audit inconsistency</p><p>[00:48:00] – Comparing SOC 2, FedRAMP, and the race to the bottom</p><p>[00:54:00] – Closing thoughts on AI, automation, and the future of white-collar work</p><br><p>Guest: John Santore, Director of Cyber Acceleration, Constellation GovCloud</p><p>Hosts: Troy Fine &amp; Elliot Volkman</p><p>Runtime: ~58 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>This week on GRC Uncensored, the crew welcomes John Santore, a longtime FedRAMP and SOC 2 practitioner who has seen firsthand how compliance frameworks evolve, and sometimes unravel. Now serving as Director of Cyber Acceleration at Constellation GovCloud, John joins Troy and Elliot to unpack FedRAMP 20x, a new pilot program designed to streamline the U.S. government’s cloud authorization process dramatically.</p><br><p>The promise? Fewer controls, faster approvals, and greater automation.The concern? That all sounds a little too familiar.</p><br><p>Together, they explore whether&nbsp;FedRAMP 20x&nbsp;is an overdue modernization or the start of a dangerous slide toward the kind of checkbox compliance that has made SOC 2 certifications easier to get but harder to trust. From control mapping and auditor disruption to agency adoption and AI-assisted audits, this episode provides a deep dive into what happens when good frameworks move too quickly and how to maintain trust when they do.</p><br><p>[00:01:00] – Guest intro: John’s history with SOC 2, FedRAMP, and working with Troy</p><p>[00:06:00] – How SOC 2 influenced John’s transition into federal compliance</p><p>[00:08:00] – What is FedRAMP 20x, and why is it happening now?</p><p>[00:10:00] – From 12-month review cycles to fast-tracking assessments</p><p>[00:14:00] – Key Security Indicators (KSIs): replacing hundreds of controls with a handful of validations</p><p>[00:18:00] – Are KSIs basically just vague control summaries? (Spoiler: yes)</p><p>[00:22:00] – Why GRC platforms are being prioritized in the pilot</p><p>[00:25:00] – Potential expansion to FedRAMP Moderate and High</p><p>[00:28:00] – Will agencies even accept this?</p><p>[00:31:00] – Advice for cloud service providers evaluating FedRAMP now</p><p>[00:34:00] – Is FedRAMP on the path to commoditization?</p><p>[00:39:00] – Evaluating rigor vs. relevance: security posture ≠ certification</p><p>[00:44:00] – The problem of vague frameworks and audit inconsistency</p><p>[00:48:00] – Comparing SOC 2, FedRAMP, and the race to the bottom</p><p>[00:54:00] – Closing thoughts on AI, automation, and the future of white-collar work</p><br><p>Guest: John Santore, Director of Cyber Acceleration, Constellation GovCloud</p><p>Hosts: Troy Fine &amp; Elliot Volkman</p><p>Runtime: ~58 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title><![CDATA[Why the "Why" Matters in GRC]]></title>
			<itunes:title><![CDATA[Why the "Why" Matters in GRC]]></itunes:title>
			<pubDate>Tue, 01 Jul 2025 10:00:00 GMT</pubDate>
			<itunes:duration>48:43</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68629a4f653df36e7b023028/media.mp3" length="46775989" type="audio/mpeg"/>
			<guid isPermaLink="false">68629a4f653df36e7b023028</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>68629a4f653df36e7b023028</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAULlwif9l67T9bDGuQ7ooIX5TxnR8zNh4iBzW+ejBrnsyup3KZrcs2l4mk7nVmvGzLUg1miWauQiTEglPktnZXt]]></acast:settings>
			<itunes:subtitle>Startup founder Richa shares why “SOC 2 in a box” won’t cut it, and how tailored GRC automation with a privacy-first AI strategy can empower overstretched mid-market teams.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>14</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>In this episode of <em>GRC Uncensored</em>, Richa, founder and CEO of <strong>Complyance</strong>, joins the hosts to unpack the growing tension between scalable compliance tooling and the real needs of maturing GRC teams. The conversation examines why SOC 2 in a box solutions fall short for mid-market organizations and what it truly means to integrate AI without compromising privacy. Along the way, the group debates the future of entry-level roles, the role of trust in automation, and whether AI is truly replacing, or simply reshaping, the GRC profession.</p><br><p><strong>[00:01:00]</strong> — Intro &amp; guest introduction: Who is Richa and what is Complyance?</p><p><strong>[00:03:00]</strong> — Why Complyance is not “SOC 2 in a box” and how their ethos differs</p><p><strong>[00:06:00]</strong> — Segmenting the GRC tooling market: Startups vs mid-market vs enterprise</p><p><strong>[00:08:00]</strong> — Mid-market struggles: From Excel to Airtable to tailored automation</p><p><strong>[00:12:00]</strong> — The audit bundling debate: Why Complyance refuses to package audits</p><p><strong>[00:15:00]</strong> — Saying no to venture capital pressure and building for the right customer</p><p><strong>[00:18:00]</strong> — What GRC software should enable: peace of mind, not paperwork</p><p><strong>[00:19:00]</strong> — Roundtable: Troy and Kendra weigh in on AI in GRC</p><p><strong>[00:27:00]</strong> — Conversational AI, embedded AI, and the rise of Agentic AI</p><p><strong>[00:31:00]</strong> — Risk owners, vendor reviews, and trust in automation</p><p><strong>[00:34:00]</strong> — Is AI replacing entry-level jobs or just reshaping them?</p><p><strong>[00:38:00]</strong> — Teaching with AI: From education to GRC upskilling</p><p><strong>[00:42:00]</strong> — The risk treatment plan case study: AI as a draft, not a decision</p><p><strong>[00:47:00]</strong> — Closing thoughts on AI, SaaS disruption, and Jetsons-level predictions</p><br><p><strong>Hosts:</strong> Troy Fine, Kendra Cooley</p><p><strong>Producer:</strong> Elliot Volkman</p><p><strong>Runtime:</strong> ~49 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode of <em>GRC Uncensored</em>, Richa, founder and CEO of <strong>Complyance</strong>, joins the hosts to unpack the growing tension between scalable compliance tooling and the real needs of maturing GRC teams. The conversation examines why SOC 2 in a box solutions fall short for mid-market organizations and what it truly means to integrate AI without compromising privacy. Along the way, the group debates the future of entry-level roles, the role of trust in automation, and whether AI is truly replacing, or simply reshaping, the GRC profession.</p><br><p><strong>[00:01:00]</strong> — Intro &amp; guest introduction: Who is Richa and what is Complyance?</p><p><strong>[00:03:00]</strong> — Why Complyance is not “SOC 2 in a box” and how their ethos differs</p><p><strong>[00:06:00]</strong> — Segmenting the GRC tooling market: Startups vs mid-market vs enterprise</p><p><strong>[00:08:00]</strong> — Mid-market struggles: From Excel to Airtable to tailored automation</p><p><strong>[00:12:00]</strong> — The audit bundling debate: Why Complyance refuses to package audits</p><p><strong>[00:15:00]</strong> — Saying no to venture capital pressure and building for the right customer</p><p><strong>[00:18:00]</strong> — What GRC software should enable: peace of mind, not paperwork</p><p><strong>[00:19:00]</strong> — Roundtable: Troy and Kendra weigh in on AI in GRC</p><p><strong>[00:27:00]</strong> — Conversational AI, embedded AI, and the rise of Agentic AI</p><p><strong>[00:31:00]</strong> — Risk owners, vendor reviews, and trust in automation</p><p><strong>[00:34:00]</strong> — Is AI replacing entry-level jobs or just reshaping them?</p><p><strong>[00:38:00]</strong> — Teaching with AI: From education to GRC upskilling</p><p><strong>[00:42:00]</strong> — The risk treatment plan case study: AI as a draft, not a decision</p><p><strong>[00:47:00]</strong> — Closing thoughts on AI, SaaS disruption, and Jetsons-level predictions</p><br><p><strong>Hosts:</strong> Troy Fine, Kendra Cooley</p><p><strong>Producer:</strong> Elliot Volkman</p><p><strong>Runtime:</strong> ~49 minutes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>From Engineering to GRC: A first-hand account of the GRC talent gap</title>
			<itunes:title>From Engineering to GRC: A first-hand account of the GRC talent gap</itunes:title>
			<pubDate>Thu, 19 Jun 2025 09:42:00 GMT</pubDate>
			<itunes:duration>55:00</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68535d73cf39b4f29a2e92e0/media.mp3" length="52805886" type="audio/mpeg"/>
			<guid isPermaLink="false">68535d73cf39b4f29a2e92e0</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>68535d73cf39b4f29a2e92e0</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAXRCzGusVUGAj4OEiNg7JK+iP5FcWr14LDWZRe8h+fM6tV4ovDJhrdTUD4H1flewldAfodc7JnwyRJv69kAGrfK]]></acast:settings>
			<itunes:subtitle>Shruti Mukherjee joins us to share her perspective on the talent gap associated with GRC</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>13</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p><br></p><p>As organizations contend with growing threats and shrinking GRC teams, this episode explores the widening talent gap in governance, risk, and compliance. Guest Shruti Mukherjee, a former software engineer turned GRC practitioner, shares her journey, her insights on the evolving nature of the field, and her call to action for both professionals and organizations to rethink what GRC careers can look like.</p><br><p><strong>Guests:</strong> Shruti (GRC Professional)</p><p><strong>Hosts:</strong> Troy Fine, Kendra Cooley</p><p><strong>Producer:</strong> Elliot Volkman</p><p><strong>Runtime:</strong> ~55 minutes</p><br><p><strong>Show Notes &amp; Segments:</strong></p><br><p>00:00 – Intro &amp; Banter</p><p>Casual chatter and AI banter with the crew, including Shruti’s first ChatGPT query and a few carrot cake recipes.</p><br><p>09:00 – GRC’s Image Problem: Is It Just Boring?</p><p>Shruti discusses the perception problem around GRC, generational gaps in interest, and why it’s often viewed as unsexy or undervalued work.</p><br><p>14:30 – Reframing the Pipeline: Who Should We Be Recruiting?</p><p>The group considers alternative talent pipelines, especially mid-career professionals who better understand the strategic value of GRC.</p><p>Quote: “Maybe it’s time to come to the good side.” – Kendra</p><br><p>20:30 – The Role of AI and Automation: Friend or Foe?</p><p>Shruti and the hosts weigh in on how automation platforms are shaping the field—for better or worse—and whether GRC jobs are at risk of being replaced.</p><p>Quote: “I treat AI like an intern. It can do some of the work, but I’ll always check it before it leaves the building.” – Shruti</p><br><p>26:00 – What Should New GRC Pros Learn?</p><p>Shruti shares what she wishes she had known earlier—especially around audit practices—and the value of soft skills and continuous learning.</p><br><p>30:30 – Critical Thinking, Not Just Checkboxes</p><p>Why GRC professionals must retain their ability to think critically, validate automation outputs, and question assumptions.</p><p>Quote: “We are losing our ability to be critical thinkers.” – Kendra</p><br><p>36:00 – Does GRC Need to Be Technical Now?</p><p>Shruti unpacks how her technical background helps her talk with engineers, understand tooling, and embrace AI; arguing that technical fluency is becoming essential.</p><br><p>44:30 – Final Thoughts: Risk Culture, Knowledge Transfer, and the Future</p><p>The group reflects on the need to pass down GRC fundamentals, resist overreliance on AI, and target new demographics for hiring.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p><br></p><p>As organizations contend with growing threats and shrinking GRC teams, this episode explores the widening talent gap in governance, risk, and compliance. Guest Shruti Mukherjee, a former software engineer turned GRC practitioner, shares her journey, her insights on the evolving nature of the field, and her call to action for both professionals and organizations to rethink what GRC careers can look like.</p><br><p><strong>Guests:</strong> Shruti (GRC Professional)</p><p><strong>Hosts:</strong> Troy Fine, Kendra Cooley</p><p><strong>Producer:</strong> Elliot Volkman</p><p><strong>Runtime:</strong> ~55 minutes</p><br><p><strong>Show Notes &amp; Segments:</strong></p><br><p>00:00 – Intro &amp; Banter</p><p>Casual chatter and AI banter with the crew, including Shruti’s first ChatGPT query and a few carrot cake recipes.</p><br><p>09:00 – GRC’s Image Problem: Is It Just Boring?</p><p>Shruti discusses the perception problem around GRC, generational gaps in interest, and why it’s often viewed as unsexy or undervalued work.</p><br><p>14:30 – Reframing the Pipeline: Who Should We Be Recruiting?</p><p>The group considers alternative talent pipelines, especially mid-career professionals who better understand the strategic value of GRC.</p><p>Quote: “Maybe it’s time to come to the good side.” – Kendra</p><br><p>20:30 – The Role of AI and Automation: Friend or Foe?</p><p>Shruti and the hosts weigh in on how automation platforms are shaping the field—for better or worse—and whether GRC jobs are at risk of being replaced.</p><p>Quote: “I treat AI like an intern. It can do some of the work, but I’ll always check it before it leaves the building.” – Shruti</p><br><p>26:00 – What Should New GRC Pros Learn?</p><p>Shruti shares what she wishes she had known earlier—especially around audit practices—and the value of soft skills and continuous learning.</p><br><p>30:30 – Critical Thinking, Not Just Checkboxes</p><p>Why GRC professionals must retain their ability to think critically, validate automation outputs, and question assumptions.</p><p>Quote: “We are losing our ability to be critical thinkers.” – Kendra</p><br><p>36:00 – Does GRC Need to Be Technical Now?</p><p>Shruti unpacks how her technical background helps her talk with engineers, understand tooling, and embrace AI; arguing that technical fluency is becoming essential.</p><br><p>44:30 – Final Thoughts: Risk Culture, Knowledge Transfer, and the Future</p><p>The group reflects on the need to pass down GRC fundamentals, resist overreliance on AI, and target new demographics for hiring.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>What It Really Takes to Get Hired in GRC</title>
			<itunes:title>What It Really Takes to Get Hired in GRC</itunes:title>
			<pubDate>Thu, 05 Jun 2025 13:00:00 GMT</pubDate>
			<itunes:duration>44:53</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/684062895de209b54b1f8c72/media.mp3" length="43092099" type="audio/mpeg"/>
			<guid isPermaLink="false">684062895de209b54b1f8c72</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>684062895de209b54b1f8c72</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAX+9QJubChw4kNOgnuTBIR7s9/W5fwpn5vUTqAYmyFWjHsb5UVOiwWLti/TO2Cl1OlG2K7kWmB9yU+7joTHym2M]]></acast:settings>
			<itunes:subtitle>S1 EP 12: Pete Strouse on GRC Hiring: Who Gets In, Who Gets Cut</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>12</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p><strong>Guest:</strong> Pete Strouse, Cybersecurity Talent Advisor &amp; Host of <em>The Talent Gap Fireside Chat</em></p><br><p>This episode explores how governance, risk, and compliance (GRC) roles are filled, and why it's getting harder to land one. Pete Strouse unpacks the current job market, share recruiter insights, and offer advice to job seekers and hiring managers navigating a GRC landscape shaped by automation, offshoring, and unrealistic expectations.</p><br><p><strong>[02:30] – GRC Careers Usually Start in Consulting</strong></p><p><strong>[09:45] – Are Candidates Using ChatGPT to Fake It?</strong></p><p><strong>[17:00] – How Recruiters Actually Source Talent</strong></p><p><strong>[23:00] – Red Flags: What Turns Recruiters Off Immediately</strong></p><p><strong>[28:30] – Is There Really a Talent Shortage in GRC?</strong></p><p><strong>[36:00] – How Automation and Offshoring Are Reshaping GRC Roles</strong></p><p><strong>[42:00] – Advice for Candidates and Hiring Managers</strong></p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p><strong>Guest:</strong> Pete Strouse, Cybersecurity Talent Advisor &amp; Host of <em>The Talent Gap Fireside Chat</em></p><br><p>This episode explores how governance, risk, and compliance (GRC) roles are filled, and why it's getting harder to land one. Pete Strouse unpacks the current job market, share recruiter insights, and offer advice to job seekers and hiring managers navigating a GRC landscape shaped by automation, offshoring, and unrealistic expectations.</p><br><p><strong>[02:30] – GRC Careers Usually Start in Consulting</strong></p><p><strong>[09:45] – Are Candidates Using ChatGPT to Fake It?</strong></p><p><strong>[17:00] – How Recruiters Actually Source Talent</strong></p><p><strong>[23:00] – Red Flags: What Turns Recruiters Off Immediately</strong></p><p><strong>[28:30] – Is There Really a Talent Shortage in GRC?</strong></p><p><strong>[36:00] – How Automation and Offshoring Are Reshaping GRC Roles</strong></p><p><strong>[42:00] – Advice for Candidates and Hiring Managers</strong></p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>The Unfiltered Truth About CPAs and Audits</title>
			<itunes:title>The Unfiltered Truth About CPAs and Audits</itunes:title>
			<pubDate>Tue, 20 May 2025 10:00:00 GMT</pubDate>
			<itunes:duration>40:08</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/682b8ef93e2c04fd7a706ed7/media.mp3" length="38530084" type="audio/mpeg"/>
			<guid isPermaLink="false">682b8ef93e2c04fd7a706ed7</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>682b8ef93e2c04fd7a706ed7</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAWFzkytgpqmubjnX80FLFtbFW74wVIb5wlt+YQzZ5jPq+f3vqxnKQv1coffbggTX3LAmWO5oWwwsduciNsl5GDm]]></acast:settings>
			<itunes:subtitle>Troy, Kendra, and Elliot attempt to unpack why CPAs, with backgrounds in finance, are skilled enough to audit cybersecurity programs.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>11</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>This episode of <em>GRC Uncensored</em> goes full behind-the-scenes as Troy Fine, Kendra Cooley, and producer Elliot Volkman sit down for an unscripted discussion. From the challenges CPAs face in the security world to the ethics of auditing, the team explores what happens when trust, risk, and reputation collide. Plus, a big reveal: Troy is starting his own CPA firm—Fine Assurance.</p><br><p><strong>[00:10:00] The CPA Debate</strong></p><p> Troy breaks down the CPA backlash in cybersecurity, explaining why the criticism isn’t always fair—and why the problem might be deeper than just the credential.</p><p><strong>[00:16:00] What Does “Technical” Really Mean?</strong></p><p> The team explores what it means to be “technical” in security and whether that should be a requirement for auditors or GRC pros.</p><p><strong>[00:30:00] Kendra’s Take: Use Your Auditor to Scale Security</strong></p><p> Kendra flips the audit narrative: instead of hiding problems, she embraces audits as an opportunity to advocate for budget and resources.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>This episode of <em>GRC Uncensored</em> goes full behind-the-scenes as Troy Fine, Kendra Cooley, and producer Elliot Volkman sit down for an unscripted discussion. From the challenges CPAs face in the security world to the ethics of auditing, the team explores what happens when trust, risk, and reputation collide. Plus, a big reveal: Troy is starting his own CPA firm—Fine Assurance.</p><br><p><strong>[00:10:00] The CPA Debate</strong></p><p> Troy breaks down the CPA backlash in cybersecurity, explaining why the criticism isn’t always fair—and why the problem might be deeper than just the credential.</p><p><strong>[00:16:00] What Does “Technical” Really Mean?</strong></p><p> The team explores what it means to be “technical” in security and whether that should be a requirement for auditors or GRC pros.</p><p><strong>[00:30:00] Kendra’s Take: Use Your Auditor to Scale Security</strong></p><p> Kendra flips the audit narrative: instead of hiding problems, she embraces audits as an opportunity to advocate for budget and resources.</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Going Beyond Compliance: The Intersection of Security and Risk Management</title>
			<itunes:title>Going Beyond Compliance: The Intersection of Security and Risk Management</itunes:title>
			<pubDate>Thu, 24 Apr 2025 13:45:43 GMT</pubDate>
			<itunes:duration>57:09</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/680a40876f5bfb044f5f1654/media.mp3" length="109740396" type="audio/mpeg"/>
			<guid isPermaLink="false">680a40876f5bfb044f5f1654</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>680a40876f5bfb044f5f1654</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVuvIkfeEAVTNz6mfmr6pIyhhRJkzPcl//W26kh7S3NGGuaE6OqSnj7YmTubHFWZHKVQDu0HeSukaO2JtXFufpH]]></acast:settings>
			<itunes:subtitle>Rob Wood on bridging the gap between compliance and security—and why treating controls as checkboxes sells your program short.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>10</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Kendra Cooley, along with producer Elliot Volkman chat with Rob Wood, founder and CEO of Sidekick Security, to explore the relationship between compliance and security. They dig into topics such as the limitations of compliance as a security measure, the role of compliance tools and platforms, and the importance of effective communication and leadership in fostering robust security programs. Various perspectives on compliance as a foundational element for security, contrasting viewpoints on automation tools, and the impact of breaches highlight the intricate balance between meeting compliance requirements and achieving genuine security improvements.</p><br><p>05:38 Compliance vs. Security: A Deeper Dive</p><p>11:26 The Role of Compliance in Building Security</p><p>25:19 The Impact of Breaches on Security Practices</p><p>32:35 Balancing Security Spending and Compliance</p><p>34:08 Risk Reduction and Customer Trust</p><p>38:03 Quantifying Risk and Compliance</p><p>47:09 Compliance Tools and Automation</p><p>51:00 High Trust Certification and Breach Impact</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Kendra Cooley, along with producer Elliot Volkman chat with Rob Wood, founder and CEO of Sidekick Security, to explore the relationship between compliance and security. They dig into topics such as the limitations of compliance as a security measure, the role of compliance tools and platforms, and the importance of effective communication and leadership in fostering robust security programs. Various perspectives on compliance as a foundational element for security, contrasting viewpoints on automation tools, and the impact of breaches highlight the intricate balance between meeting compliance requirements and achieving genuine security improvements.</p><br><p>05:38 Compliance vs. Security: A Deeper Dive</p><p>11:26 The Role of Compliance in Building Security</p><p>25:19 The Impact of Breaches on Security Practices</p><p>32:35 Balancing Security Spending and Compliance</p><p>34:08 Risk Reduction and Customer Trust</p><p>38:03 Quantifying Risk and Compliance</p><p>47:09 Compliance Tools and Automation</p><p>51:00 High Trust Certification and Breach Impact</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Oversight Over Auditors and Peer Reviews</title>
			<itunes:title>Oversight Over Auditors and Peer Reviews</itunes:title>
			<pubDate>Thu, 10 Apr 2025 10:00:00 GMT</pubDate>
			<itunes:duration>34:16</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67f6dd65027873197870502c/media.mp3" length="65809240" type="audio/mpeg"/>
			<guid isPermaLink="false">67f6dd65027873197870502c</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>67f6dd65027873197870502c</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAXLTWpPe37fc1sggxQ622u3033Og4M5vOfD+QmzPLEi6d7GnGroIK+VazflWGjXkYZvNBiAQIJnigmrzAodvGUK]]></acast:settings>
			<itunes:subtitle>Jeff Cook offers a deep dive on AICPA, auditor independence, and peer reviews.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>9</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1744231503663-d66f56f0-f650-41ab-9b46-c6bfe79e9592.jpeg"/>
			<description><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Elliot Volkman invite Jeff Cook, a compliance expert with over 20 years of experience, to discuss the intricacies of auditor oversight and peer reviews. Jeff shares insights into the complexities of the peer review process, including the role of State Boards of Accountancy, AICPA, and the challenges of maintaining quality in SOC reports. The conversation also addresses potential improvements in the peer review system, market education, and the impact of GRC tools.</p><br><p>05:08 Diving into CPA and Compliance</p><p>08:50 Challenges in Peer Review and Quality Control</p><p>12:09 Market Influence and Future Directions</p><p>25:22 The Role of GRC Tools</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Elliot Volkman invite Jeff Cook, a compliance expert with over 20 years of experience, to discuss the intricacies of auditor oversight and peer reviews. Jeff shares insights into the complexities of the peer review process, including the role of State Boards of Accountancy, AICPA, and the challenges of maintaining quality in SOC reports. The conversation also addresses potential improvements in the peer review system, market education, and the impact of GRC tools.</p><br><p>05:08 Diving into CPA and Compliance</p><p>08:50 Challenges in Peer Review and Quality Control</p><p>12:09 Market Influence and Future Directions</p><p>25:22 The Role of GRC Tools</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Third-Party Risk Management: When to Accept or Reject Vendor Documentation</title>
			<itunes:title>Third-Party Risk Management: When to Accept or Reject Vendor Documentation</itunes:title>
			<pubDate>Thu, 27 Mar 2025 10:30:00 GMT</pubDate>
			<itunes:duration>53:43</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67e4a41cd6912226b5d693e9/media.mp3" length="103152473" type="audio/mpeg"/>
			<guid isPermaLink="false">67e4a41cd6912226b5d693e9</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>67e4a41cd6912226b5d693e9</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAU+X/XI9jloi0JlEc29jSvJo7eRLoSIPOaEAwgAJVDp9yEbPB7NnlOzW72wJ1uObzAk6hueDcLXB2TQJRGqdgIx]]></acast:settings>
			<itunes:subtitle>Stanley Krochik, the Senior Security Third Party Risk Manager at Handshake, shares his POV on receiving low-quality SOC 2s.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>8</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[<p>On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest <a href="https://www.linkedin.com/in/stanleyk19/" rel="noopener noreferrer" target="_blank">Stanley Krochik</a>, a now seasoned GRC professional and former city security program manager, to discuss the realities of third-party risk Management (TPRM). The conversation focused on the growing issue of low-quality audits, the challenge of assessing vendor security postures, and the dilemma risk managers face when reviewing third-party documentation.</p><br><p>04:43 The Importance of Third Party Risk Management</p><p>05:45 Challenges with Low Quality Audits</p><p>07:45 Evaluating SOC 2 Reports</p><p>12:55 Issues with Sales-Focused GRC Tools</p><p>14:44 The Need for Better Compliance Programs</p><p>27:50 High-Risk Vendor Architecture Review</p><p>29:07 SOC 2 Reports and Vendor Risk Management</p><p>31:50 Challenges with SOC 2 and Auditor Quality</p><p>36:49 Financial Impact of Data Breaches</p><p>38:10 Differences in Security Between Old and New Systems</p><p>47:43 Proactive vs. Reactive Security Measures</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest <a href="https://www.linkedin.com/in/stanleyk19/" rel="noopener noreferrer" target="_blank">Stanley Krochik</a>, a now seasoned GRC professional and former city security program manager, to discuss the realities of third-party risk Management (TPRM). The conversation focused on the growing issue of low-quality audits, the challenge of assessing vendor security postures, and the dilemma risk managers face when reviewing third-party documentation.</p><br><p>04:43 The Importance of Third Party Risk Management</p><p>05:45 Challenges with Low Quality Audits</p><p>07:45 Evaluating SOC 2 Reports</p><p>12:55 Issues with Sales-Focused GRC Tools</p><p>14:44 The Need for Better Compliance Programs</p><p>27:50 High-Risk Vendor Architecture Review</p><p>29:07 SOC 2 Reports and Vendor Risk Management</p><p>31:50 Challenges with SOC 2 and Auditor Quality</p><p>36:49 Financial Impact of Data Breaches</p><p>38:10 Differences in Security Between Old and New Systems</p><p>47:43 Proactive vs. Reactive Security Measures</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>AI Governance: Insights on ISO 42001 from GRC Two Experts</title>
			<itunes:title>AI Governance: Insights on ISO 42001 from GRC Two Experts</itunes:title>
			<pubDate>Thu, 13 Mar 2025 10:00:00 GMT</pubDate>
			<itunes:duration>52:56</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67d23656ba1ef91ed08184ce/media.mp3" length="101649498" type="audio/mpeg"/>
			<guid isPermaLink="false">67d23656ba1ef91ed08184ce</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/</link>
			<acast:episodeId>67d23656ba1ef91ed08184ce</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAWyfoC2ACd1LweUtAg93kahtukRH7MiYHCEFNYRLhyc515JWHs+1oXRsYMuJyKqkLwy0n1GZVxTlHNDhlvprteK]]></acast:settings>
			<itunes:subtitle>Season 1, Episode 7: Chris Honda of Whistic and Jonathan LeBaron of MasterControl share their experience with ISO 42001 adoption.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>7</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741829346506-7aca08ae-5a39-4dda-9d8c-ef1741f66345.jpeg"/>
			<description><![CDATA[<p>The latest episode of GRC Uncensored dove deep into the magical world of AI governance, specifically on ISO 42001. This week, our guests are <a href="https://www.linkedin.com/in/ichirohonda/" rel="noopener noreferrer" target="_blank">Chris Honda</a>, Whistic’s Manager of Security, Risk, and Compliance; and <a href="https://www.linkedin.com/in/jlebaron-qgrc/" rel="noopener noreferrer" target="_blank">Jonathan LeBaron</a>, MasterControl Senior GRC Engineer with the golden voice. Our due shared their firsthand experiences navigating compliance, business adoption, and the broader implications of AI risk management.</p><p><br></p><h3><strong>Key Takeaways</strong></h3><ul><li><strong>ISO 42001 is becoming essential</strong> for companies adopting AI, not just for compliance but to build customer trust.</li><li><strong>AI risk assessments are more complex</strong> than traditional security frameworks, requiring new approaches to impact analysis.</li><li><strong>Shadow IT and vendor AI features</strong> introduce unexpected risks—companies must proactively monitor and review new AI functionalities.</li><li><strong>AI governance isn’t just about compliance; it’s about trust.</strong> Businesses that prioritize transparency and ethical AI use will have a competitive edge. Also, AI may or may not be making us dumber.</li></ul><p><br></p><p>02:23 Discussing AI in GRC and ISO 42001</p><p>02:56 ChatGPT and AI Experiences</p><p>08:07 Implementing ISO 42001: Challenges and Insights</p><p>19:20 Third-Party Risk Management and AI</p><p>26:43 Scope and Complexity of AI in Software Products</p><p>27:57 Challenges in High-Risk AI Applications</p><p>29:43 Regulatory Landscape and AI</p><p>32:02 Driving Forces Behind ISO Certification</p><p>38:53 AI Risks and Business Understanding</p><p>43:56 Ethical and Societal Impacts of AI</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>The latest episode of GRC Uncensored dove deep into the magical world of AI governance, specifically on ISO 42001. This week, our guests are <a href="https://www.linkedin.com/in/ichirohonda/" rel="noopener noreferrer" target="_blank">Chris Honda</a>, Whistic’s Manager of Security, Risk, and Compliance; and <a href="https://www.linkedin.com/in/jlebaron-qgrc/" rel="noopener noreferrer" target="_blank">Jonathan LeBaron</a>, MasterControl Senior GRC Engineer with the golden voice. Our due shared their firsthand experiences navigating compliance, business adoption, and the broader implications of AI risk management.</p><p><br></p><h3><strong>Key Takeaways</strong></h3><ul><li><strong>ISO 42001 is becoming essential</strong> for companies adopting AI, not just for compliance but to build customer trust.</li><li><strong>AI risk assessments are more complex</strong> than traditional security frameworks, requiring new approaches to impact analysis.</li><li><strong>Shadow IT and vendor AI features</strong> introduce unexpected risks—companies must proactively monitor and review new AI functionalities.</li><li><strong>AI governance isn’t just about compliance; it’s about trust.</strong> Businesses that prioritize transparency and ethical AI use will have a competitive edge. Also, AI may or may not be making us dumber.</li></ul><p><br></p><p>02:23 Discussing AI in GRC and ISO 42001</p><p>02:56 ChatGPT and AI Experiences</p><p>08:07 Implementing ISO 42001: Challenges and Insights</p><p>19:20 Third-Party Risk Management and AI</p><p>26:43 Scope and Complexity of AI in Software Products</p><p>27:57 Challenges in High-Risk AI Applications</p><p>29:43 Regulatory Landscape and AI</p><p>32:02 Driving Forces Behind ISO Certification</p><p>38:53 AI Risks and Business Understanding</p><p>43:56 Ethical and Societal Impacts of AI</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>The Good, The Bad, and The Underrated of Compliance Audits</title>
			<itunes:title>The Good, The Bad, and The Underrated of Compliance Audits</itunes:title>
			<pubDate>Thu, 27 Feb 2025 11:00:00 GMT</pubDate>
			<itunes:duration>1:05:54</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67bfb6233beb1d1463c901f1/media.mp3" length="126547290" type="audio/mpeg"/>
			<guid isPermaLink="false">67bfb6233beb1d1463c901f1</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://shows.acast.com/grc-uncensored/episodes/67bfb6233beb1d1463c901f1</link>
			<acast:episodeId>67bfb6233beb1d1463c901f1</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAW0QK0BDvC9dKQk+70fY5nMdCtyQPkZOvQP9E/Ziu3Na5ZbJyOMBbWbLxkKwpYM019fXZsOyRl15Uaz8MQbQueh]]></acast:settings>
			<itunes:subtitle>Season 1, Episode 6: We chat with Joseph Kirkpatrick and get his perspective on the current state of compliance audits and how to improve it.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>6</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1740617236171-8704da6f-ee8a-43e4-b397-706664f920e5.jpeg"/>
			<description><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine, Kendra Cooley, and producer Elliot Volkman dive into an unfiltered discussion with Joseph Kirkpatrick, founder and president of KirkpatrickPrice. The focus is on the implications of private equity and compliance automation tools in GRC. </p><br><p>Joseph shares his insights on how the influx of private equity funding and the rise of 'SOC in a box' platforms have transformed the GRC landscape, often negatively impacting audit quality and independence. Key topics include the challenge of maintaining ethics in auditing, the adverse effects of aggressive marketing by compliance tools, and the importance of conducting thorough, unbiased audits. The conversation also touches on the difficulty audit firms face when pressured to lower costs or cut corners to retain business.</p><br><p>01:21 The Impact of SOC 2 Platforms</p><p>02:51 Private Equity's Influence on the Industry</p><p>03:04 Challenges Faced by Licensed Practitioners</p><p>04:32 Marketing Dollars and Industry Perception</p><p>06:06 The Role of Compliance Tools</p><p>10:51 Conflicts of Interest in Auditing</p><p>21:08 The Reality of Zero-Touch Audits</p><p>24:46 Trusting Compliance Platforms</p><p>33:44 Challenging the Status Quo in Auditing</p><p>34:27 Targeting the Right Market</p><p>35:09 The Role of Audit and Customer Expectations</p><p>35:44 Critique of AICPA and Cybersecurity Education</p><p>36:55 Practitioners' Responsibility in Auditing</p><p>39:13 The Problem with Automation Tools</p><p>43:30 Shady Business Practices in Auditing</p><p>47:29 Ethics and Integrity in Auditing</p><p>50:34 The Importance of Thorough Audits</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine, Kendra Cooley, and producer Elliot Volkman dive into an unfiltered discussion with Joseph Kirkpatrick, founder and president of KirkpatrickPrice. The focus is on the implications of private equity and compliance automation tools in GRC. </p><br><p>Joseph shares his insights on how the influx of private equity funding and the rise of 'SOC in a box' platforms have transformed the GRC landscape, often negatively impacting audit quality and independence. Key topics include the challenge of maintaining ethics in auditing, the adverse effects of aggressive marketing by compliance tools, and the importance of conducting thorough, unbiased audits. The conversation also touches on the difficulty audit firms face when pressured to lower costs or cut corners to retain business.</p><br><p>01:21 The Impact of SOC 2 Platforms</p><p>02:51 Private Equity's Influence on the Industry</p><p>03:04 Challenges Faced by Licensed Practitioners</p><p>04:32 Marketing Dollars and Industry Perception</p><p>06:06 The Role of Compliance Tools</p><p>10:51 Conflicts of Interest in Auditing</p><p>21:08 The Reality of Zero-Touch Audits</p><p>24:46 Trusting Compliance Platforms</p><p>33:44 Challenging the Status Quo in Auditing</p><p>34:27 Targeting the Right Market</p><p>35:09 The Role of Audit and Customer Expectations</p><p>35:44 Critique of AICPA and Cybersecurity Education</p><p>36:55 Practitioners' Responsibility in Auditing</p><p>39:13 The Problem with Automation Tools</p><p>43:30 Shady Business Practices in Auditing</p><p>47:29 Ethics and Integrity in Auditing</p><p>50:34 The Importance of Thorough Audits</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Drata Talks Navigating Audit Integrity and Independence</title>
			<itunes:title>Drata Talks Navigating Audit Integrity and Independence</itunes:title>
			<pubDate>Thu, 12 Dec 2024 11:00:31 GMT</pubDate>
			<itunes:duration>45:13</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/6759b21d859d1b450fff0ca6/media.mp3" length="86828635" type="audio/mpeg"/>
			<guid isPermaLink="false">6759b21d859d1b450fff0ca6</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://shows.acast.com/grc-uncensored/episodes/6759b21d859d1b450fff0ca6</link>
			<acast:episodeId>6759b21d859d1b450fff0ca6</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAUxFE1u0bVuqYIuLiUHGLJaWpET+rbeDSXShO7h0nYQbIuVSnanUO5roz9sKC3oD4YGkM+RK8/HAUwMxRj7FV8a]]></acast:settings>
			<itunes:subtitle><![CDATA[Troy and Elliot chat with Drata's Kevin Kriebel about how vendors should support neutrality and auditor independence.]]></itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>5</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1733931522365-1f3f80af-ace5-46ab-b0de-7273025ed688.jpeg"/>
			<description><![CDATA[<p>In this episode, host Troy Fine and producer Elliot Volkman welcome guest Kevin Kriebel, VP of Business Development at Drata. The conversation focuses on the challenges and intricacies of maintaining auditor independence and integrity in the compliance automation landscape. Key topics include the impact of bundling and price fixing on audit quality, the need for improved TPRM functionality, and the role of enterprises in ensuring higher standards. The discussion also addresses the importance of education and transparency in mitigating the risks associated with low-quality audits and driving market changes.</p><br><p>01:04 Introductions and Ground Rules </p><p>02:23 Discussing Auditor Independence </p><p>04:30 Challenges in the Audit Industry </p><p>06:19 Vendor Relationships and Audit Integrity </p><p>10:14 Education Gap in Compliance </p><p>23:58 Industry Price Fixing Concerns </p><p>27:30 Discussing Audit Automation and Vendor Practices </p><p>28:19 The Problem with Bundling Services </p><p>29:02 Challenges in Vendor Accountability </p><p>30:34 The Role of TPRM and AI in Compliance </p><p>33:29 The Importance of Education in Compliance </p><p>38:24 Market Dynamics and Compliance Requirements</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode, host Troy Fine and producer Elliot Volkman welcome guest Kevin Kriebel, VP of Business Development at Drata. The conversation focuses on the challenges and intricacies of maintaining auditor independence and integrity in the compliance automation landscape. Key topics include the impact of bundling and price fixing on audit quality, the need for improved TPRM functionality, and the role of enterprises in ensuring higher standards. The discussion also addresses the importance of education and transparency in mitigating the risks associated with low-quality audits and driving market changes.</p><br><p>01:04 Introductions and Ground Rules </p><p>02:23 Discussing Auditor Independence </p><p>04:30 Challenges in the Audit Industry </p><p>06:19 Vendor Relationships and Audit Integrity </p><p>10:14 Education Gap in Compliance </p><p>23:58 Industry Price Fixing Concerns </p><p>27:30 Discussing Audit Automation and Vendor Practices </p><p>28:19 The Problem with Bundling Services </p><p>29:02 Challenges in Vendor Accountability </p><p>30:34 The Role of TPRM and AI in Compliance </p><p>33:29 The Importance of Education in Compliance </p><p>38:24 Market Dynamics and Compliance Requirements</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Episode Zero: Behind the Concept of GRC Uncensored</title>
			<itunes:title>Episode Zero: Behind the Concept of GRC Uncensored</itunes:title>
			<pubDate>Tue, 26 Nov 2024 11:00:04 GMT</pubDate>
			<itunes:duration>23:17</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/6744e5f5c11fbabc61c4db5e/media.mp3" length="44732265" type="audio/mpeg"/>
			<guid isPermaLink="false">6744e5f5c11fbabc61c4db5e</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://shows.acast.com/grc-uncensored/episodes/6744e5f5c11fbabc61c4db5e</link>
			<acast:episodeId>6744e5f5c11fbabc61c4db5e</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVCRQKPzRST9XS56Iy+9IrRA28tamQ4xtxr6FwFjMLxj7CC+hOkFRBER3vFotQgsNKyjYGG5eZ3G6td5ENlwL1I]]></acast:settings>
			<itunes:subtitle>Troy and Elliot have a brief rambling conversation about their plans for a podcast that you now know as GRC Uncensored.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>4</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1732568616909-b02590ad-1f5c-4caa-a6c0-c08b3cc4131a.jpeg"/>
			<description><![CDATA[<p>In the pilot episode of GRC Uncensored, hosts Troy Fine and Elliot Volkman introduce the podcast aimed at having unfiltered discussions about Governance, Risk, and Compliance (GRC). This episode was recorded before any interviews and offers some retrospectives of what became reality or not. They detail their professional backgrounds, especially highlighting Troy's unexpected journey into auditing and meme culture on LinkedIn. The hosts share the focus of future episodes (which have already been published), including the commoditization of compliance and the quality of audits, while emphasizing the importance of honest and authentic conversations in the GRC field. They also discuss the potential for disagreement among industry professionals and encourage audience engagement and feedback.</p><br><p>00:00 Introduction to GRC Uncensored</p><p>00:42 Meet the Hosts: Troy Fine and Elliot Volkman</p><p>01:34 Troy's Journey into Auditing and Memes</p><p>03:10 The Role of CPAs in Cybersecurity</p><p>05:29 The Purpose of GRC Uncensored</p><p>07:08 Pilot Season and Episode Preview</p><p>09:51 Commoditization of Compliance</p><p>19:02 Quality of Audits and Future Topics</p><p>21:45 Conclusion and Call for Feedback</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In the pilot episode of GRC Uncensored, hosts Troy Fine and Elliot Volkman introduce the podcast aimed at having unfiltered discussions about Governance, Risk, and Compliance (GRC). This episode was recorded before any interviews and offers some retrospectives of what became reality or not. They detail their professional backgrounds, especially highlighting Troy's unexpected journey into auditing and meme culture on LinkedIn. The hosts share the focus of future episodes (which have already been published), including the commoditization of compliance and the quality of audits, while emphasizing the importance of honest and authentic conversations in the GRC field. They also discuss the potential for disagreement among industry professionals and encourage audience engagement and feedback.</p><br><p>00:00 Introduction to GRC Uncensored</p><p>00:42 Meet the Hosts: Troy Fine and Elliot Volkman</p><p>01:34 Troy's Journey into Auditing and Memes</p><p>03:10 The Role of CPAs in Cybersecurity</p><p>05:29 The Purpose of GRC Uncensored</p><p>07:08 Pilot Season and Episode Preview</p><p>09:51 Commoditization of Compliance</p><p>19:02 Quality of Audits and Future Topics</p><p>21:45 Conclusion and Call for Feedback</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Unpacking audit quality (or lack thereof)</title>
			<itunes:title>Unpacking audit quality (or lack thereof)</itunes:title>
			<pubDate>Thu, 14 Nov 2024 11:00:59 GMT</pubDate>
			<itunes:duration>49:18</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/673370ea16fd6db3c5447444/media.mp3" length="94663000" type="audio/mpeg"/>
			<guid isPermaLink="false">673370ea16fd6db3c5447444</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/p/unpacking-audit-quality-or-lack-thereof</link>
			<acast:episodeId>673370ea16fd6db3c5447444</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAWkSHVJLpLYbIvq/jxzp5bM2w9oBiHXAV9s7+9w4O4YHRH4xdHBwhNfm45DQ4RxJ7XDERBortA+EvGv6zVlYuLq]]></acast:settings>
			<itunes:subtitle>David Forman, founder of Mastermind and former EY auditor, provides some optimism around compliance audit quality.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>3</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1731424481033-a7ee48d9-34ab-4bcf-ad8d-f256e25668d2.jpeg"/>
			<description><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Kendra Cooley, along with producer Elliot Volkman, continue their pursuit of trying to understand what is explicitly holding the GRC world back. Joined by ISO expert David Foreman, the discussion tackles the roles of auditors, tech vendors, and market forces in shaping audit quality. </p><br><p>They explore the significance of audit integrity, the staying power of governance programs, and the varying expectations of companies undergoing audits. Amidst an insightful dialogue, the hosts debate the future of automated compliance tools, check-the-box audits, and the elusive definition of audit quality. Ultimately, the episode underscores the issue's complexity, emphasizing that it's not just about the vendors or auditors but also market demands and expectations.</p><br><p>00:00 Introduction to GRC uncensored </p><p>00:42 Meet the hosts: Troy and Kendra </p><p>01:05 Controversies and LinkedIn debates </p><p>01:37 International expansion and podcast updates </p><p>02:28 Commoditization of compliance 03:07 Introduction to Dave and his expertise </p><p>04:43 The role of vendors in compliance </p><p>07:49 Audit quality and market dynamics </p><p>09:49 The importance of audit integrity </p><p>13:11 Defining audit quality </p><p>20:26 Market expectations and audit quality </p><p>23:48 Staying power in compliance programs </p><p>28:00 High-quality vs. low-quality audit firms </p><p>28:59 Top qualities of a good auditor </p><p>29:19 Importance of knowledge in auditing </p><p>31:06 Compliance automation tools </p><p>32:26 Challenges in finding quality auditors </p><p>34:30 The reality of check-box audits </p><p>35:34 Accreditation and certification nuances </p><p>42:12 The future of auditing and trust centers </p><p>43:42 Closing remarks and shameless plugs </p><p>47:05 Final thoughts and tagline</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In this episode of GRC Uncensored, hosts Troy Fine and Kendra Cooley, along with producer Elliot Volkman, continue their pursuit of trying to understand what is explicitly holding the GRC world back. Joined by ISO expert David Foreman, the discussion tackles the roles of auditors, tech vendors, and market forces in shaping audit quality. </p><br><p>They explore the significance of audit integrity, the staying power of governance programs, and the varying expectations of companies undergoing audits. Amidst an insightful dialogue, the hosts debate the future of automated compliance tools, check-the-box audits, and the elusive definition of audit quality. Ultimately, the episode underscores the issue's complexity, emphasizing that it's not just about the vendors or auditors but also market demands and expectations.</p><br><p>00:00 Introduction to GRC uncensored </p><p>00:42 Meet the hosts: Troy and Kendra </p><p>01:05 Controversies and LinkedIn debates </p><p>01:37 International expansion and podcast updates </p><p>02:28 Commoditization of compliance 03:07 Introduction to Dave and his expertise </p><p>04:43 The role of vendors in compliance </p><p>07:49 Audit quality and market dynamics </p><p>09:49 The importance of audit integrity </p><p>13:11 Defining audit quality </p><p>20:26 Market expectations and audit quality </p><p>23:48 Staying power in compliance programs </p><p>28:00 High-quality vs. low-quality audit firms </p><p>28:59 Top qualities of a good auditor </p><p>29:19 Importance of knowledge in auditing </p><p>31:06 Compliance automation tools </p><p>32:26 Challenges in finding quality auditors </p><p>34:30 The reality of check-box audits </p><p>35:34 Accreditation and certification nuances </p><p>42:12 The future of auditing and trust centers </p><p>43:42 Closing remarks and shameless plugs </p><p>47:05 Final thoughts and tagline</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>Should you invest in a GRC tool for compliance?</title>
			<itunes:title>Should you invest in a GRC tool for compliance?</itunes:title>
			<pubDate>Thu, 24 Oct 2024 10:00:50 GMT</pubDate>
			<itunes:duration>42:42</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/6719918483ac9fccac3342c7/media.mp3" length="81994073" type="audio/mpeg"/>
			<guid isPermaLink="false">6719918483ac9fccac3342c7</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/p/grc-tool-vs-spreadsheet</link>
			<acast:episodeId>6719918483ac9fccac3342c7</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAUnzomlAsUAsfj7UtfDUbwNeicLdpxBtOclJpKVn/R0Fq2urh73J7TXN2MXaaQRQgfL9KzD7663rn3PKvPk6DnN]]></acast:settings>
			<itunes:subtitle>Martin Cozzi, CEO of Pima, joins the podcast to stoke the fire around whether spreadsheets are sufficient or GRC tools are the new standard.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>2</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1729728859515-d86be188-150d-4efa-b514-d0605f6ca33c.jpeg"/>
			<description><![CDATA[<p>GRC Uncensored is back, and your hosts Troy Fine and Elliot Volkman are joined by Martin Cozzi, CEO of Pima, to discuss when, if at all, it makes sense to invest in a GRC tool to support a company's compliance efforts. </p><br><p>The discussion spans the necessity and use of various compliance tools, the challenges of scaling compliance, and the importance of having well-defined processes and dedicated personnel. They highlight the actual costs and benefits of compliance, questioning superficial practices and emphasizing the need for personalized solutions. The episode also addresses misconceptions and executive decisions crucial for maintaining compliance, offering comprehensive insights into modern GRC strategies and the evolving role of tools in achieving SOC 2 compliance.</p><br><p>00:00 Introduction to GRC Uncensored</p><p>00:22 Meet the Hosts and Guest Introduction</p><p>00:38 The Need for GRC Tools</p><p>02:52 Legacy vs. Modern GRC Tools</p><p>05:26 Challenges with GRC Tools</p><p>12:12 When to Choose GRC Tools</p><p>12:49 The Role of Processes in GRC</p><p>20:49 GRC Tools for Startups</p><p>23:20 The Cost of Compliance</p><p>24:43 The Role of Auditors</p><p>26:47 Touchless Audits: Pros and Cons</p><p>28:19 The Value of SOC 2 Reports</p><p>30:50 Choosing the Right Compliance Tools</p><p>32:31 The Future of Compliance Tools</p><p>40:46 Final Thoughts and Reflections</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>GRC Uncensored is back, and your hosts Troy Fine and Elliot Volkman are joined by Martin Cozzi, CEO of Pima, to discuss when, if at all, it makes sense to invest in a GRC tool to support a company's compliance efforts. </p><br><p>The discussion spans the necessity and use of various compliance tools, the challenges of scaling compliance, and the importance of having well-defined processes and dedicated personnel. They highlight the actual costs and benefits of compliance, questioning superficial practices and emphasizing the need for personalized solutions. The episode also addresses misconceptions and executive decisions crucial for maintaining compliance, offering comprehensive insights into modern GRC strategies and the evolving role of tools in achieving SOC 2 compliance.</p><br><p>00:00 Introduction to GRC Uncensored</p><p>00:22 Meet the Hosts and Guest Introduction</p><p>00:38 The Need for GRC Tools</p><p>02:52 Legacy vs. Modern GRC Tools</p><p>05:26 Challenges with GRC Tools</p><p>12:12 When to Choose GRC Tools</p><p>12:49 The Role of Processes in GRC</p><p>20:49 GRC Tools for Startups</p><p>23:20 The Cost of Compliance</p><p>24:43 The Role of Auditors</p><p>26:47 Touchless Audits: Pros and Cons</p><p>28:19 The Value of SOC 2 Reports</p><p>30:50 Choosing the Right Compliance Tools</p><p>32:31 The Future of Compliance Tools</p><p>40:46 Final Thoughts and Reflections</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>The Commoditization of Compliance and SOC 2</title>
			<itunes:title>The Commoditization of Compliance and SOC 2</itunes:title>
			<pubDate>Thu, 10 Oct 2024 10:00:45 GMT</pubDate>
			<itunes:duration>40:19</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67051e89ed8ff5205ed9d4a5/media.mp3" length="77421401" type="audio/mpeg"/>
			<guid isPermaLink="false">67051e89ed8ff5205ed9d4a5</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcpod.substack.com/p/the-commoditization-of-compliance</link>
			<acast:episodeId>67051e89ed8ff5205ed9d4a5</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAVt9X2dWI4l1LVfJT1Aj4VJBIpc4p5xwnk1dwkGQwJNZdQD/ouQgRvPm+9u4RvSwLoZvAara+CbABhetzC+bEAR]]></acast:settings>
			<itunes:subtitle>Season 1, Episode 1: Troy Fine and Elliot Volkman kick off the pilot for GRC Uncensored with special guest Kendra Cooley.</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:episode>1</itunes:episode>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1728388304063-c23668ff-e7ba-4978-a194-a915895310b0.jpeg"/>
			<description><![CDATA[<p>In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time. </p><br><p>The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.</p><br><p>00:00 Welcome to GRC Uncensored </p><p>01:34 Introducing Kendra Cooley </p><p>02:05 Love-Hate Relationship with GRC </p><p>03:16 The SOC 2 Debate </p><p>04:33 Challenges with SOC 2 Audits </p><p>09:10 The Value of SOC 2 in the Industry </p><p>12:04 The Evolution of Compliance Frameworks </p><p>20:39 False Sense of Security in Compliance </p><p>24:46 The Buzz Around AI and Quantum </p><p>25:10 Staying Updated as a Security Professional </p><p>26:45 Challenges in Penetration Testing and Vendor Assessments </p><p>27:37 Compliance and Its Impact on Security </p><p>30:10 Government Regulations and Their Effectiveness </p><p>32:23 The Complexity of Privacy Laws </p><p>38:29 The Role of GRC Teams in Risk Management </p><p>42:30 Concluding Thoughts and Future Episodes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[<p>In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time. </p><br><p>The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.</p><br><p>00:00 Welcome to GRC Uncensored </p><p>01:34 Introducing Kendra Cooley </p><p>02:05 Love-Hate Relationship with GRC </p><p>03:16 The SOC 2 Debate </p><p>04:33 Challenges with SOC 2 Audits </p><p>09:10 The Value of SOC 2 in the Industry </p><p>12:04 The Evolution of Compliance Frameworks </p><p>20:39 False Sense of Security in Compliance </p><p>24:46 The Buzz Around AI and Quantum </p><p>25:10 Staying Updated as a Security Professional </p><p>26:45 Challenges in Penetration Testing and Vendor Assessments </p><p>27:37 Compliance and Its Impact on Security </p><p>30:10 Government Regulations and Their Effectiveness </p><p>32:23 The Complexity of Privacy Laws </p><p>38:29 The Role of GRC Teams in Risk Management </p><p>42:30 Concluding Thoughts and Future Episodes</p><hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<item>
			<title>GRC Uncensored Trailer</title>
			<itunes:title>GRC Uncensored Trailer</itunes:title>
			<pubDate>Sun, 06 Oct 2024 18:58:02 GMT</pubDate>
			<itunes:duration>0:43</itunes:duration>
			<enclosure url="https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/6702ddbafc23de57639f6902/media.mp3" length="1377121" type="audio/mpeg"/>
			<guid isPermaLink="false">6702ddbafc23de57639f6902</guid>
			<itunes:explicit>false</itunes:explicit>
			<link>https://grcuncensored.com/</link>
			<acast:episodeId>6702ddbafc23de57639f6902</acast:episodeId>
			<acast:showId>6702dcb9c88f09c3e0b9a10a</acast:showId>
			<acast:settings><![CDATA[FYjHyZbXWHZ7gmX8Pp1rmbKbhgrQiwYShz70Q9/ffXZMTtedvdcRQbP4eiLMjXzCKLPjEYLpGj+NMVKa+5C8pL4u/EOj1Vw4h5MMJYp0lCcFAe0fnxBJy/1ju4Qxy1fh8gO4DvlGA40yms2g0/hOkcrfHIopjTygHFqGwwOPKFIai4SuTvs86Lx3UYCyl6ZstrJCOGo+mTs1jWjg6MRg+Wg2tW63fJb7YMon2k/FgAW+RCmL8AJ8A6BPIgMIX4VCrpZBi3+hQ7/ROahlC1wjmkqJSAjVAmyptIiwUyrV3X6iu84VHsOxDGLxOUdwK6qg]]></acast:settings>
			<itunes:subtitle>A new series brought to you by Chaos explores the world of GRC</itunes:subtitle>
			<itunes:episodeType>full</itunes:episodeType>
			<itunes:season>1</itunes:season>
			<itunes:image href="https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg"/>
			<description><![CDATA[GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it. Your hosts are Troy Fine and Elliot Volkman.<hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></description>
			<itunes:summary><![CDATA[GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it. Your hosts are Troy Fine and Elliot Volkman.<hr><p style='color:grey; font-size:0.75em;'> Hosted on Acast. See <a style='color:grey;' target='_blank' rel='noopener noreferrer' href='https://acast.com/privacy'>acast.com/privacy</a> for more information.</p>]]></itunes:summary>
		</item>
		<itunes:category text="News">
			<itunes:category text="Tech News"/>
		</itunes:category>
		<itunes:category text="Business">
			<itunes:category text="Management"/>
		</itunes:category>
    </channel>
</rss>
