Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success. You'll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden.


Episode Transcript:

Adam, today we are ready to get serious. That’s right, we are ready to get serious about compliance.

If there’s anyone that I know that’s serious about compliance, it’s you, sir. Help set the stage on this one.

Adam Goslin:
For a lot of organizations, when they started going up against security and compliance, they didn’t have any clue when they started just how much of an investment it was going to end up being.

Maybe the organization was initially hoping they could do a check-the-box approach to compliance.

“Oh, if we just put all our crap there, everything magically happens,” or whatever the snake oil salesman was busy hawking your direction at the time.

But if you actually care about the security posture of your organization, then you know that approach isn’t going to make the grade.

You can rest assured your customers expect to see detailed proof that you are indeed taking security and compliance seriously.

More and more, it’s becoming the standard or the norm that organizations will validate and vet the organizations that they choose to trust with their data. Your organization’s going to be no different.

If your organization fits into this category and it’s time to take your compliance program to the next level, then it’s a major step forward for the organization.

You’re going to need to get strategic about making sure you’re covering all the bases and evaluating and addressing several parts: people resources, the processes that you undertake, as well as where your existing technological approach to compliance stands in the grand scheme of things.

All of those are going to come into play as you’re going through the process.

If you fall into that category, you landed on the right podcast.

Todd Coshow:
Indeed.

As part of an organization’s leveling up their compliance program, tell me more about the people they should be looking to have as part of their compliance strategy, and some of the pitfalls that organizations run into there.

Adam Goslin:
It’s all about having the right people.

One of the big mistakes that I’ll see organizations make time after time when they say, “Okay, we’re going to take compliance seriously,” is that, no offense to the assessors of the world, they just go hire an assessor out of the gate.

They think, “The assessor knows what they’re doing, and the assessor will be able to get the answers and help to get the company’s act together.”

But I wouldn’t recommend that be step one.

It doesn’t work well because the assessor, as weird as this sounds to articulate, isn’t responsible for sitting and guiding the company through a compliance engagement.

They may be happy to charge you a hell of a lot more to hold your hand and walk you through it. But effectively, the organizations that do that become the problem children to the assessors.

It’s like, “Oh my God, this is the never-ending engagement because these guys aren’t anywhere near ready to go.”

For many assessors, they’ll have a readiness notion because they’ve been burned so many times with this exact thing happening.

They’ll do an assessment up front of, “Is this organization actually ready to bring in an assessor or not?”

You’ll be having conversations about the things that you don’t have in place with the person who is charged with assessing your organization’s current state of compliance.

You end up revealing a whole ton of dirty laundry through the process.


Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Syys 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Syys 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Elo 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Elo 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Elo 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Elo 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Heinä 21min