EPISODE · Aug 14, 2026 · 13 MIN
Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin
from The ITSPmagazine Podcast · host ITSPmagazine, Redefining Cybersecurity Podcast, Travis Howerton, RegScale
Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose. RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project. Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again. Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react. That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue. The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Travis Howerton, Co-Founder and CEO at RegScale LinkedIn: https://www.linkedin.com/in/travishowerton/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas RegScale: https://regscale.com OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance
Embed this episode
What this episode covers
The first CTO of the US Nuclear Weapons Program left government convinced that the checklist approach to audits was holding the whole industry back. At Black Hat USA 2026 he explains how compliance as code turns an 18-month authority to operate into something closer to 30 days, with a better risk posture on the other side.
NOW PLAYING
Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.