EP 29 — Age of Learning's Carl Stern on Why Certifications Are Side Effects, Not Final Goals episode artwork

EPISODE · Feb 10, 2026 · 29 MIN

EP 29 — Age of Learning's Carl Stern on Why Certifications Are Side Effects, Not Final Goals

from Future of Data Security · host Qohash

Carl Stern, VP of Information Security at Age of Learning, explains why forcing controls into place without executive alignment guarantees you'll fight uphill battles every single day, as people begin to see security as a blocker rather than a business enabler. Instead, he starts with identifying crown jewels and acceptable risk levels before selecting any frameworks or tools, ensuring the program fits company culture instead of working against it. He also asserts that certifications like HITRUST and SOC 2 validate you're already operating securely; the real program is the daily processes people follow because they understand why, not compliance theatre. Carl also argues the cybersecurity industry exists at its current scale because of a systemic failure: companies ship insecure software without liability, pushing security costs downstream. Most breaches exploit preventable defects that should never reach production, not sophisticated zero-days. Topics discussed:Building security programs from scratch versus inheriting existing programs and why executive alignment prevents daily uphill battlesTreating certifications as validation of operational security rather than the primary program goalPairing administrative controls with technical monitoring to establish baselines before enforcement for unstructured data security policiesApplying three-part investment calculus for lean teams: measurable risk reduction, manual work automation, and crown jewel protectionCalculating true cost of 24/7 internal SOC coverage including shift staffing, turnover, training, and tooling versus managed servicesWhy attack patterns remain consistent across healthcare, education, gaming, and retail despite different compliance requirementsExplaining how AI lowers the barrier for exploit development and expands zero-day risk beyond traditional high-value enterprise targetsArguing that the cybersecurity industry exists at current scale because companies ship insecure software without liability, pushing costs downstream

Carl Stern, VP of Information Security at Age of Learning, explains why forcing controls into place without executive alignment guarantees you'll fight uphill battles every single day, as people begin to see security as a blocker rather than a business enabler. Instead, he starts with identifying crown jewels and acceptable risk levels before selecting any frameworks or tools, ensuring the program fits company culture instead of working against it. He also asserts that certifications like HITRUST and SOC 2 validate you're already operating securely; the real program is the daily processes people follow because they understand why, not compliance theatre. Carl also argues the cybersecurity industry exists at its current scale because of a systemic failure: companies ship insecure software without liability, pushing security costs downstream. Most breaches exploit preventable defects that should never reach production, not sophisticated zero-days. Topics discussed:Building security programs from scratch versus inheriting existing programs and why executive alignment prevents daily uphill battlesTreating certifications as validation of operational security rather than the primary program goalPairing administrative controls with technical monitoring to establish baselines before enforcement for unstructured data security policiesApplying three-part investment calculus for lean teams: measurable risk reduction, manual work automation, and crown jewel protectionCalculating true cost of 24/7 internal SOC coverage including shift staffing, turnover, training, and tooling versus managed servicesWhy attack patterns remain consistent across healthcare, education, gaming, and retail despite different compliance requirementsExplaining how AI lowers the barrier for exploit development and expands zero-day risk beyond traditional high-value enterprise targetsArguing that the cybersecurity industry exists at current scale because companies ship insecure software without liability, pushing costs downstream

NOW PLAYING

EP 29 — Age of Learning's Carl Stern on Why Certifications Are Side Effects, Not Final Goals

0:00 29:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Ask A Spaceman Archives - 365 Days of Astronomy Ask A Spaceman Archives - 365 Days of Astronomy Podcasting Astronomy Every Day of the Year Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? That Hoarder: Overcome Compulsive Hoarding That Hoarder Hoarding disorder is stigmatised and people who hoard feel vast amounts of shame. This podcast began life as an audio diary, an anonymous outlet for somebody with this weird condition. That Hoarder speaks about her experiences living with compulsive hoarding, she interviews therapists, academics, researchers, children of hoarders, professional organisers and influencers, and she shares insight and tips for others with the problem. Listened to by people who hoard as well as those who love them and those who work with them, Overcome Compulsive Hoarding with That Hoarder aims to shatter the stigma, share the truth and speak openly and honestly to improve lives.

Frequently Asked Questions

How long is this episode of Future of Data Security?

This episode is 29 minutes long.

When was this Future of Data Security episode published?

This episode was published on February 10, 2026.

What is this episode about?

Carl Stern, VP of Information Security at Age of Learning, explains why forcing controls into place without executive alignment guarantees you'll fight uphill battles every single day, as people begin to see security as a blocker rather than a...

Can I download this Future of Data Security episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!