PODCAST · technology
Compliance Unfiltered With Adam Goslin
by Total Compliance Tracking
Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less
-
220
Ready to Get Serious About Compliance? - Episode 226
Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success. You'll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden.
-
219
Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225
On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status.Episode Tracking:Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet.That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say.Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it?Adam Goslin:If we’re talking about my engagement, how long would it take? Seconds.But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit.This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet.I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.”All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch.“Hold on a second. I think it’s over here.”They go and look over there.“Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.”No, it’s not there either.“You know what? Evan knows exactly where it’s at. Give me one second.”Ring, ring, ring, ring.His phone went to voicemail.“Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?”It was an effing nightmare.A lot of people think that they know where things are until they’re under the gun and have to prove it.If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game.It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it.It really degrades their sense that the people they’re talking to actually have their act together.Todd Coshow:I can definitely appreciate that.Spreadsheets are still everywhere in compliance, but why are they such a problem?Adam Goslin:Spreadsheets weren’t designed to manage living, breathing systems.We’ve talked before about the levels of complexity that exist within these things.A spreadsheet is static, and compliance isn’t.There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against.You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states.If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane.The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.
-
218
Q3 Security Insights 2026 - Episode 224
In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions. The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds. If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you.Episode Transcript:It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026.As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy.As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly.Also, feel free to reach out to us at [email protected]. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us.Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more.Adam Goslin:In the grand scheme of things, it is a capability that some organizations struggle with.Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no?When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request.There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof.This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy.It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly.Certainly, safeguarding internal reports is one arena we’re going to get into.As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports.There’s a myriad of information within them that external entities don’t have any right or reason to see.In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution.The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those.Only issuing your externally appropriate summary of your security posture to third parties is appropriate.The next arena I want to touch on is a centralized distribution channel.One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.
-
217
Building AI Agents Securely - Episode 223
AI agents are driving efficiency, but also introducing serious, often unseen security risks. As adoption accelerates, unvetted access, prompt injection, and poorly controlled environments can expose sensitive data and disrupt operations. This episode of Compliance Unfiltered breaks down the key threats and shows how to mitigate them using proven principles like least privilege, input validation, and isolated execution. Learn how to secure AI deployments and turn a growing risk into a resilient advantage.Episode Transcript:You’ve been talking about the AI zombie walk for some period of time now. What perils are folks walking into with AI agents?Adam Goslin:We’ve got the democratization of agentic AI on the march. Anybody can get the latest tools and create these incredible AI agents that can do almost anything you can imagine. It’s part of the main reason why the agentic AI move can be a substantive risk for the organization as well.One of the big problems they’re having right now is that, while security and compliance folks understand the risks of AI, there are a ton of frontline users that are just clicking buttons and building tools and making things automated and better. There isn’t, in a lot of cases, any thought to the security implications of what they’re in the process of doing.Thinking about security isn’t an element of day-by-day workflow, and that’s where this notion of agentic AI comes in riskiest, if you will.Leveraging platforms for building these AI agents without a security background, I’d liken it to giving a three-year-old an arc welder. It might be able to figure out how to turn it on, but can you imagine the untold damage that they could do with it?You put a powerful AI tool in the hands of people that don’t know about protecting data, layers of security, and how to appropriately restrict access. They’re not going to know how to use it safely.There are a lot of considerations when it comes down to building AI agents in a secure fashion. But most of it honestly comes down to security principles.It’s possible for employees to build those safely, but there needs to be that marrying of the security and compliance-style mindset in conjunction with what’s going on.Todd Coshow:What type of efficiency risks are folks running into?Adam Goslin:AI agents are often used for personal efficiency and internal workplace functions. To give some examples: consolidating, summarizing, and filtering across multiple email accounts; automated execution of auto-replies; analyzing workflows and calendars for identifying efficiencies; gathering up data; and preparing written summaries of client projects.These things may seem harmless, but just consider the risk of letting the AI agent loose on your calendar. How much data did you just expose as a result of clicking, “Sure, you’re going to have full access to my calendar”?The agent has access to your client lists, client contacts, emails, signatures, phone numbers, and cell phone numbers. All of that starts to come into play as you’re granting blind access to Office 365, as an example.Maybe that extends to OneDrive and SharePoint. Maybe, depending on the user and their access levels, they could be granting a ton of access.Even things that seem innocent, such as tracking birthdays or anniversaries, could similarly produce greater levels of exposure than you were even considering.The company needs to consider what is the data and information that’s exposed to the AI engine, how do we want to use it, and whether or not that data is secluded from other things.If you’re moving from a free version to a paid version of AI, your users may still be jammed into some gigantic public pool of data storage.Even when the AI vendors are claiming, “We don’t hand your data over to public AI models,” you need to look closely at what they are doing, such as utilizing the information that’s gleaned from the individual users when it comes to training their engines.
-
216
AI-Powered Attacks: Is Your Compliance Program Already Obsolete? - Episode 222
In an era of evolving AI-driven cyberattacks, traditional compliance programs are falling dangerously behind. Static controls create a false sense of security while attackers leverage AI to move faster, exploit vulnerabilities, and bypass defenses. On this week's Compliance Unfiltered, Todd Coshow and compliance expert Adam Goslin explore how AI is reshaping threats, why checkbox compliance is obsolete, and how organizations must shift to continuous, real-time assurance to stay resilient, protect data, and keep pace with modern adversaries.Episode Transcript:Today, we’re going to talk about the nefarious. That’s right, the artificially nefarious. In fact, AI-powered attacks. Is your compliance program already obsolete?But before we do so, Adam, as always, we want to say a special thank you to listeners of this podcast. Tell your compliance friends, if they’re not listening to us already, let them know that it’s something that you enjoy doing, and they might as well.Also, if you have any questions, topics, or general compliments you want to send our way, please do so at [email protected] I mentioned, Adam, AI-powered attacks are something that’s on everybody’s mind these days. I guess the question is: if AI is fundamentally changing how attacks are executed—faster, smarter, more adaptive—are most compliance programs already outdated?Adam Goslin:In a lot of cases, yeah. It’s not because of some type of poor design, but a lot of the programs that exist now were founded in advance of the advent of AI, built in a different time, if you will.A lot of the compliance programs have certain assumptions baked in: stability, known systems, predictive behavior, human-driven threats. AI is really putting a gaping hole in that assumption, if you will.You’ve got attacks these days that can adapt midstream. They can mimic a legitimate user and scale with a speed that wasn’t possible before.Compliance is still, in many cases, measuring control effectiveness and measuring controls being in place at fixed points in time. It isn’t necessarily that the compliance is wrong, but it’s operating on a timeline that’s not matching up to today’s newfangled AI-world reality.Todd Coshow:Fair enough. Where do you see the biggest disconnect today between what compliance frameworks validate and what’s actually happening inside an environment?Adam Goslin:One of the biggest gaps is between existence and effectiveness.Frameworks are good at confirming controls exist. There is a policy. Here it is. There’s a process, and there’s evidence. But they’re not consistently validating that the control is working under real-world conditions, and quite frankly, the real world is changing under our feet, if you will, especially when it comes to these AI-driven attacks.You’ve got organizations that hold up their piece of paper and say, “Hey, big green checkbox, we’re compliant.” But the controls, in some cases, are bypassed shortly after the validation that, at that point in time, they were working.In many cases, the controls aren’t getting tested against how attack patterns are really behaving in the real world these days.Todd Coshow:You’ve talked about organizations having a false sense of their own state of compliance. How does AI make that problem even worse?Adam Goslin:AI accelerates the drift and buries it, if you will.Controls have a tendency to degrade over time. Access reviews get stale. Monitoring gets noisy and ignored. That type of stuff was already happening. But AI allows for the exploit of those gaps faster than many organizations are set up to detect them.Now you’re sitting here with a situation where, on the one side, I’m technically compliant because of my last audit. But operationally, I’m not compliant because the environment has modified or changed, and the attackers are jumping on those gaps immediately.
-
215
Compliance Theater: Are You Actually Secure or Just Checking Boxes? - Episode 221
Most organizations are just performing compliance – ticking boxes, not building real security. What happens when the curtain is pulled back on these check-the-box programs? You might be under the illusion of safety, but in reality, you're exposing your organization to serious risks.In this eye-opening episode, Todd Coshow and cybersecurity expert Adam Goslin reveal how many companies operate in “compliance theater,” creating an illusion of security to meet audit deadlines without safeguarding their environment. They unpack the stark difference between being audit-ready and genuinely secure, exposing how superficial policies, outdated evidence, and a mindset focused on passing assessments put your company at risk.Episode Transcript:The topic for today really boils down to whether or not folks out there are actually secure or if they’re just checking boxes. So let’s start with the tough one.Are organizations actually secure or just really good at checking the bare minimum boxes before the auditor shows up?Adam Goslin:If we’re being honest about it, most of them are performing.There are too many organizations out there to count that their view of navigating their security and compliance waters is doing the least preparation that’s humanly possible in advance of their audit or their assessment. They’re just trying to get through the process.In a lot of cases, it’s like a mantra: “We have to check. We’re being forced to do this, and we’re doing as little as we can just so that we can achieve the little piece of paper that says we’re secure.”They know what they need to show to the assessor, when to show it, and how to package it. But there’s a stark difference between organizations that are actually operationally secure, really taking this stuff seriously, etc.It also doesn’t provide any proof that everything’s going to be cooking with gas come some random Tuesday in March. Security isn’t a moment-in-time thing, where unfortunately most of the assessments and audits are.Todd Coshow:When we say compliance theater, what does that actually mean in practice? Where do you see organizations just going through the motions instead of building real security?Adam Goslin:Compliance theater is when your program’s built to prove something instead of actually demonstrating or doing something. That’s where you see compliance theater coming into play.Maybe it rears its head with screenshots that are cobbled together the day before the assessment. Maybe it’s policies that get refreshed once a year and, other than that, collect dust somewhere. It’s controls that exist but aren’t truly implemented or operationalized.Probably one of the biggest signs for an organization is when there’s this crescendo of compliance effort that happens with their annual assessment, and then all of a sudden, the second the auditor leaves, everybody’s wiping the sweat off their brow: “Thank God we made it through that one.”Everybody goes back to their day jobs and waits another nine or ten months before they have to prep for their next cycle. That’s the epitome of the compliance theater arena.Todd Coshow:Talking about the audit-versus-reality gap, how big is the gap between passing the audit, like PCI, SOC 2, ISO, and what’s actually happening on a day-to-day basis inside of an environment?Adam Goslin:There’s a bigger gap than folks want to admit.If you’re passing an audit or an assessment, that means that you’ve met the minimum bar at a specific point in time. But it doesn’t necessarily mean that the controls are being consistently applied across the environment throughout the compliance cycle.It doesn’t mean that you’re keeping your evidence fresh. It doesn’t mean that the team may even understand what they have or what they do. All I know is that for this particular requirement, I had to go into this interface, click these buttons, grab this information, this screenshot, and poof.
-
214
Audit Fatigue and How to Effectively Navigate It - Episode 220
Caught in a cycle of audit requests, evidence chaos, and burnout? Discover a way out in this episode. Compliance Expert Adam Goslin joins Todd Coshow to reveal the hidden causes of audit fatigue and share strategies to lighten your load. Learn why audit fatigue is intensifying and how fragmented compliance efforts fuel chaos. Uncover tactics to centralize evidence, reduce duplication, and implement improvements. Tune in to reclaim control over your compliance universe.Episode Transcript:So today we’re going to talk about audit fatigue. But before we do, I want to, as always, thank all the fine listeners to this podcast. Let you know that we greatly appreciate your time and your input.With that in mind, if you have a topic, a comment, a favorite recipe, or something you want to share, please do reach out to us at [email protected]. We’d love to hear what you have to say.Adam, audit fatigue. Talk to me about why it’s getting worse and what to do about it. Let’s be honest. Compliance teams of companies undergoing compliance everywhere are exhausted. Audit fatigue feels like it is at an all-time high right now. Why does it seem like this problem is getting worse year over year instead of better?Adam Goslin:It’s a real issue. One would think that with better tooling and a program going into its year two, year three, etc., things would start getting easier, but it almost feels like the opposite’s happening for a lot of organizations.Honestly, there’s been very few organizations that I’ve worked with over the years where everything just stayed static. You’ve got growing scope. You’ve got new requests for additional frameworks that need to get folded in. Expectations of assessors continue to go up, not down.So, in a lot of cases, instead of going through just one audit, there are teams that feel like they’re on this never-ending circular bicycle track, where it’s a continuous, never-ending cycle of audits, evidence requests, and follow-ups. You get done with one, another one pops up. I feel like we’re playing assessment whack-a-mole. That would be a good way to put it.Todd Coshow:That’s pretty fair. But the question is, what’s really driving that? Is it just more frameworks like PCI and SOC or ISO, or is there something deeper going on?Adam Goslin:That’s a big part of it. The bigger issue that underlies the real problem is fragmentation.You’ve got a lot of organizations that are managing compliance in silos. There’s different frameworks, different teams, different tools, and at the end of the day, all of that leads to duplicated effort. You’re proving out the same control in five different ways to five different audiences.You got spreadsheets. You got shared drives. You’ve got crap spread all over Hell’s Half Acre.I’ve talked about that ad nauseam in the past, where you’ve got stuff coming at you through email, text messages, meetings, hallway conversations, people swinging by your desk. For whatever reason, I had somebody back in the day printing their effing evidence out. They printed it out on the printer, walked by, and dropped it on my desk.You’ve got network drives. You’ve got SharePoints. You’ve got the assessor systems. It’s an effing nightmare.There are a lot of organizations that end up with different assessors through this process. Let’s say you got one organization. They start out and get somebody to evaluate them against HIPAA. Then all of a sudden, the business says, “Wait a second. We’ve got to throw PCI into the mix.”Now, when they have to go to PCI, they go back to their HIPAA assessor: “Do you guys do PCI?” Nope. Then we’ll go look and find a PCI assessor. So they throw a PCI assessor into the mix. Now I got two.
-
213
Identity is the New Perimeter (Zero Trust) - Episode 219
On this week's Compliance Unfiltered, discover why identity is the new perimeter in cybersecurity. This episode reveals how zero trust principles can protect your systems by continuously verifying user identity and behavior. Learn about the risks of traditional defenses, the evolution of compliance standards, and practical tactics for implementing context-aware verification. Perfect for IT leaders and security professionals ready to strengthen defenses and build a trustworthy digital environment. Listen now to stay ahead of threats.Episode Transcript:Today, Adam, we are going to talk about identity as the new perimeter. That’s right, folks. Zero trust is the topic for today.Now, Adam, if someone logs into your system with the right username and password, do you automatically trust them?Adam Goslin:That’s the issue. Most organizations still do, but today, credentials are one of the easy things for attackers to steal or buy. Just having somebody with a valid login doesn’t necessarily mean that it’s a legitimate user.The bad guys are taking measures to gather up this information in detail, and they’re not necessarily hacking the system, but they’re just going ahead and logging in, if you will.Todd Coshow:Sure. We’ve heard for years that the network perimeter is dying. Now the real question is, is it officially dead?Adam Goslin:There’s a couple of different ways to look at it. In a practical sense, yeah.We’ve got cloud. We’ve got software as a service. We’ve got folks doing remote work. Not only just the general sense of remote work, but also, depending on the roles of the individuals involved, part of their job is literally being on the road all the time.There’s not a notion in particular of what is inside, just because users, devices, data are being interacted with across a broad scope of geographic spread and all that fun stuff. It’s certainly getting more exciting than getting less, if you will.Todd Coshow:Fair enough. I guess the next logical question then is: what replaces it?Adam Goslin:Identity is now the perimeter. If you can control and identify the identities properly, then you’ve got the capability for securing the access regardless where the user is.One of the big elements here is, for a lot of organizations, and the ones that are in the security and compliance space have been used to this for a longer period of time, but you see more and more organizations mandating, requiring multiple factors of connectivity. That certainly has gone a long way to being able to make improvements.But part of the issues come in when, let’s say that you’ve got a username and a password that’s now been breached or shared amongst bad actors, coupled with attacks on multi-factor organizations, etc., it becomes an issue, if you will.Todd Coshow:Absolutely. How big of a problem is credential abuse in modern—Adam Goslin:It’s one of the biggest elements because the attackers have a cottage industry of scraping data and information from a wide variety of various breaches.This could be phishing that they’re doing, or from prior breaches, data and information that they’re pooling up on the dark web. The problem is that the bad guys are sharing a lot of information amongst themselves, which makes it more and more difficult for organizations to have a substantial trust factor in the identities that they’re allowing through the door.It makes things monumentally more complicated. Think about it. When you’ve got attackers that attacked this site, that site, the other site, and they’re pooling all this information, each of your users, individually, has probably been scraped up into several different data sets from various data breaches from the various vendors that they even use individually.We’ve talked about this before when we were talking about good password hygiene.
-
212
Regulatory Explosion & Board-Level Accountability - Episode 218
Discover why compliance is now a boardroom priority, not just an IT task. In this episode, Todd Coshow and Adam Goslin reveal how outdated practices put organizations at risk. Learn about the shift towards real-time breach detection and the importance of translating risks into business impacts. Perfect for leaders eager to transform compliance into a strategic advantage. Tune in to stay ahead and secure your organization's future.Episode Transcript:Adam, I have to ask: is compliance still an operational function, or has it officially become a boardroom issue?Adam Goslin:Well, it’s a good question. Definitely not optional.The interesting part about this particular question, one of the things that would drive me absolutely bonkers, as long ago, somebody that was the last one to sit down when the music stopped in IT, either that or some poor project manager or something, they just nominate somebody to have to go through it.Meanwhile, the folks at the top of the food chain would look at it as an IT problem, and it’s been one of the biggest hurdles to overcome.Your question is, is this an operational function, or is this elevated to boardroom level? The reality is it’s both, and quite frankly, the people at the top of the food chain, I’ve harped on this for a couple of decades at this point in the game, need to take this shit seriously, period.It was always perplexing to me. It was almost like the people at the top of the food chain had a greater level of concern for numerous things and did not have their eyeball on probably the things that could most dramatically impact the organization, like a breach, like their security.They’re more worried about whether or not they made their fire insurance payment than they were about whether or not—it’s like, okay, for all these businesses that had such hyper-effing focus on their freaking fire insurance, how many of them burned to the ground? Meanwhile, how many organizations have had their name in lights over the last couple of decades?Todd Coshow:More and more every month, sir.Adam Goslin:It’s absolutely unbelievable.You and I were just chatting not too long ago. I just happened to be perusing the list of recent breaches. Holy shit, man. There are an absolute ton of companies that have gotten hammered just since January.I think we’ll preserve that. Maybe we’ll do another “shame the folks out there that managed to land with their name in lights” type of deal. We’ll do that another time.Going back to the topic at hand, the reality is that as regulations are coming in, compliance and the problems that arise out of not taking your security and compliance seriously have the potential to impact the reputation of the organization, dramatically open up legal exposure for the company, and directly hit revenue and profits.It’s not easy these days to be running a company, period, let alone, through negligence, allowing something to occur at the organization that’s going to make it a thousand times more difficult.Boards are starting to move from a question like, “Are we compliant?” and starting to move in the direction of looking at their level of risk, how it could possibly affect the business, etc.The good news is that more and more light bulbs are going on at the upper levels of organizations. I’m sitting over here thinking to myself, man, it is about effing time that these people are taking this crap seriously.Todd Coshow:Sure. Your company, TCT, does business across the world, and we’ve seen this uptick in regulation across the globe, for lack of a better term.What do you think is driving the explosion in global regulations right now?Adam Goslin:There’s a couple of things going on.We’ve got more and more increasing cyber threats and the level of risk that those pose.If you think about it, we’ve got governments looking at cybersecurity and data governance as economic stability issues, not just an IT thing. So that’s a good sign.
-
211
Will Your Compliance Software Vendor Protect Your Data? - Episode 217
Most companies overlook vendor vulnerabilities in compliance. On this episode, the CU Guys reveal hidden risks in vendor relationships, from breaches to vetting gaps. Discover tactics for evaluating vendor security, asking the right questions, and spotting red flags. Protect your data by understanding the stakes—data breaches, penalties, and reputation damage. This episode is essential for those managing compliance and security, offering actionable insights to safeguard your organization.Episode Transcript:When we got into this space, my background had been in IT security and compliance for quite some period of time before we even started TCT. It’s been enlightening, I guess it’d be a good way to put it, to see the variability out there in organizations that one would think has your best interests at heart, but certain people never cease to amaze me.It is possible that your compliance vendor is going to have an issue. If you want to talk about a more recent event where a vendor had let organizations down, then just go chitchat with some of the educational institutions about the good old Canvas breach.The reality is that organizations depend on vendors. As a consumer, it’s your core responsibility to make sure that your third-party service providers are doing all of the things and staying bare minimum compliant. But hopefully, you have a much better sense of their care and diligence surrounding security, especially in this space, being a compliance software vendor. You got to make sure.As you’re thinking, “We should be able to trust the compliance software vendors,” at the end of the day, it’s where their bread and butter is, being in the security and compliance space. One would think, if anybody should, it should be them.The cold hard truth is every compliance software vendor is different. Not every single one of them is doing their due diligence to the best of their capabilities. Some people that have landed into this space are people with bags of money that just wanted to make a software product so that they could go turn a profit. At the end of the day, it’s buyer beware.Some organizations take it very seriously. Others don’t and do bare minimum checkbox-style compliance just to get a piece of paper that tells you that they’re secure.It’s a challenging landscape to figure out as you’re going through the process. Who am I dealing with here? Is this somebody that’s worthy of that trust or not?There are several telltale signs that you can pick up as you’re going through evaluation and after active engagement. The stuff we’re talking about today certainly isn’t exhaustive, but it’s going to give folks a good solid starting point for going through and having their eyes open as they’re going through the process.Todd Coshow:Indeed. What types of vetting needs to take place during the sales process?Because that’s where you’re really going to get to ask your questions before the answers don’t really matter.Adam Goslin:During that initial evaluation phase, as a consumer, you should feel empowered to ask very pointed questions around security and compliance status and approach, and things along those lines.There’s a given here. Most organizations are going to start with, “Is this going to work for me? Functionally, is it going to work for me?” As you’re going into that process, one of the things that I’d recommend to folks is: are they only talking about the functionality aspects, or are they coming out through that sales process with, “Hey, we really want to talk to you about our security stance and how we do it”?It should be a good sign when the vendor’s raising the security topic before you’re dragging them kicking and screaming into it.When the security topic comes about, that’s where you pay attention. Who’s giving the answers about security and compliance? If it’s high-level, fluffy, directional stuff from a sales dude or dudette, then that should raise some concerns.
-
210
Data Has Borders: The New Rules of Compliance - Episode 216
Data compliance isn't just about protecting information anymore — it's about understanding where your data lives, how it moves, and how to stay compliant across borders. On this Episode of Compliance Unfiltered, The CU guys chat about how with regulations evolving faster than most organizations can keep up, knowing the difference between traditional data security and the new legal landscape is crucial. This episode uncovers why geographic location, data sovereignty, and continuous visibility could make or break your compliance efforts in today's complex data environment.Episode Transcript:Adam Goslin:Especially the stories about compliance hurricanes, generically, of course. We don’t want anybody violating any NDAs or anything along those lines.But if you can generisize it and share your pain, there may very well be things that people are experiencing that others are as well. So both the pain and any insights, oh my God, yeah, that’d be great.Todd Coshow:Absolutely. Reach out at [email protected], Adam, today we’re going to talk about data. That’s right, the rules have changed. And I think it’s important that we have a chat about it.Does your company actually know where all of its data lives right now? Tell us more about this.Adam Goslin:There’s a lot of organizations that don’t really. They got a general idea, etc., but they couldn’t put their finger on, “This data’s here and that data’s there, and these are the processes.” It’s extremely complicated.There’s a lot of organizations that, quite frankly, haven’t put all of those pieces together. It’s certainly an onerous task for any organization.Todd Coshow:There’s definitely a shift in data regulations. Fundamentally, what is changing in data compliance right now?Adam Goslin:It’s not just about securing. A lot of people historically would think about protecting their environment and making sure they’re in compliance with fill in the blank, and just about protecting whatever it is that they’re responsible for protecting. That’s morphing.It’s turning more toward where is the data, how is it being used, who accesses it, for what purpose are they leveraging it, etc. There are a lot of rules, regulations, really legal agreements between organizations that govern the data access and usage. So it becomes very important to organizations to be able to have their finger on that pulse, if you will.Todd Coshow:Why is geography suddenly so important?Adam Goslin:Data is subject to the laws of the country or regions where it resides. There’s different rules and penalties. You’ve got agreements that you’ve made with different organizations. So there’s a myriad of layers that play in, but certainly where it’s at plays into it as well.Some organizations care about where their data resides, aka what country. Some don’t. So it gets extremely complicated very quickly, if you will.Todd Coshow:That makes sense. What is driving this?Adam Goslin:Globally, privacy laws have been popping up. We’ve been seeing it just in the US. In the US, we’ve got certain states that decide to put out certain edicts around privacy laws. California, namely, was the lead in terms of privacy law within the US. But the minute that they did it, now you’ve got different data and privacy laws picking up from different states within just the United States, let alone when you take it up to a federal level within the US.There’s other rules. Once you get international, countries have their own. So it’s a landscape that’s getting really complicated. It’s starting to remind me a lot of some of the complications that organizations would have with breach notifications. There were organizations that specialized in breach notification because of all of these layers of complexity.You bring it from the US stage to the international stage.
-
209
AI Fraud, Deepfakes & the Death of Trust - Episode 215
On this week's Compliance Unfiltered, AI-driven fraud is escalating, with deepfake voices and synthetic identities posing new threats. This episode reveals how traditional security measures fall short against sophisticated scams, like a $25 million fraud in Hong Kong. Discover innovative detection techniques and why real-time monitoring is crucial. Perfect for security professionals and leaders, this episode is a wake-up call to adapt and protect your organization from AI-enabled deception.Episode Transcript:Adam Goslin:I’m doing good. It is today, Cinco de Mayo. So nicely done.Todd Coshow:Thank you, sir. Today we’re going to have a conversation up and down about fraud, but before we get there, I want to make sure that we say thank you to our listeners.We would love to hear from you. If you’ve got something that you’d like to share, if you have some suggestions or show ideas, please do not hesitate to reach out to us at [email protected]. We’re excited to hear what you have to say.As I teased just a moment ago, today we are talking about AI fraud, deepfakes, and the death of trust. Let me ask you a kind of off-the-wall question, Adam: if your CEO called asking for a wire transfer, would you trust it? Obviously, in this instance, you are a CEO. In your past life, if you were to receive a call from your CEO, would you trust it?Adam Goslin:It’s becoming more and more difficult these days. I was going to say, if I got a call from me, then the cat would be out of the bag.Looking at it philosophically, it used to be that the bigger concern was somebody taking over an email account and passing you weird messages, or they’ve ghosted out the number and they’re sending texts to your phone from the appropriate number, or phone calls that would come in with somebody trying to mimic their voice or whatever. But nowadays, it’s not a safe assumption.AI can clone voices. You can clone identities well enough to trick. Let’s say you got a real strong training program and people are going through training not once a year, but twice a year, three times a year, monthly. It’s tough because when you’ve got the capability to mirror off faces, voices, etc., it becomes astronomically difficult to blindly trust.It’s the same mantra that we’ve had in this arena for quite some period of time. One needs to ask themselves, does what is happening right now feel right? Trust your gut and be a little skeptical because I would much rather have somebody coming in and saying, “Hey, I got this request. I’m coming through a back channel just to validate that this is actually legitimate.” I would rather answer those types of inquiries from my people a hundred times than take one opportunity for somebody to not bother or drop the ball or trust what they were hearing. It’s what these people need to do.There was a recent thing that happened out of Hong Kong, and this was just fascinating. It was a finance worker in Hong Kong where the fraudsters were using AI deepfake technology. They impersonated the company’s CFO and other colleagues on a video conference call. Initially, the employee was doubting the request, but was convinced when all these different participants in the video call appeared to be familiar staff members. They basically set up this multi-person video call with everybody where everybody except the finance guy was fake.They basically told them they needed to execute a confidential transaction. That’s why you hadn’t heard about this previously, etc. They convinced this dude on this call to go in, and they did 15 different transfers to five different local bank accounts totaling $25.6 million. They didn’t even figure out what the heck happened until later on, the employee checked the validation with the company’s UK-based headquarters. That’s when they ended up discovering, “No, you’ve just been had.”
-
208
How and Why to Vet Vendor AI Software Use for Security Risks - Episode 214
On this week's Compliance Unfiltered, unlock the hidden risks driving AI security nightmares, and learn how proactive vendor vetting can save your organization from irreversible breaches. As AI integration accelerates across industries, many organizations are blindly rushing in, unaware of the lurking dangers that could compromise sensitive data and even their reputation. The CU Guys expose the critical gaps in vendor vetting practices and offers a clear roadmap to protect your business in the age of AI.Episode Transcript:Now, everybody's looking for a better, more efficient way to do everything.And in 2026, that usually includes AI. How is this kind of a topic that should be on the forefront of everybody's mind?Well, I mean, the, the, the advent of AI has, you know, fairly quickly, um, may have taken a front row seat in a lot of organizations in, in just about every industry. Um, you know, there's third party, you know, third parties that are integrating, you know, AI engines, chatbots into basic subscription packages, whether you're wanted or not. And, you know, AI is getting packaged into, you know, office products, search engines, employees are using them without even, you know, a consideration for any of the potential security implications. So, you know, as, as AI permeates the workspace, uh, it's not going away anytime soon, so, um, and that, that poses an issue for organizations.They, they, AI presents some unique security challenges that, you know, most organizations aren't fully prepared to address, um, let alone that, you know, depending on the organization security stance, you need to be able to consider, you know, locking down software so that, you know, your folks can't inadvertently share inappropriate data with, you know, with third parties. So, um, you know, you need, you need a couple of different, you know, elements, um, to, to be able to, to be able to, to bring into play, um, you know, kind of a framework, if you will. So, um, you know, including your, you know, kind of your AI policy or approved software lists, your, you know, vendor vetting, you know, we already did, did a fair amount with, uh, you know, kind of AI, AI policies and approved software lists. So, you know, today we'll, we'll focus in on, uh, you know, on the, you know, kind of the vendor vetting, you know, leg of the stool, if you will, and, you know, how to, how to go about, you know, going through vetting vendors, et cetera.So good times.Good times indeed. Now, where should an organization start?Well, as you're, as you're going in, first and foremost, just to kind of gloss over it, certainly every organization needs to have policies that are, you know, kind of governing the use of their, of their artificial intelligence. If you don't, if you don't have a standard for your organization, then people, people are, they're just going to paint whatever they want to paint. And that typically means outside the line. So that's not good for anybody.But, you know, it's, it's going to introduce security risks for the organization that they, you know, they, they aren't even prepared for. So, you know, before you can go through deciding to vet any vendors, you need to make sure internally you've kind of done the, the, the forethought and thought leadership around, you know, how is our organization going to approach the, the advent of AI. You know, defining, you know, acceptable uses for AI, what constitutes sensitive data within the organization, you know, these are, these are kind of critical first steps where, you know, you want a well communicated standard. So that you can, you know, have a, have a shot at ensuring that your proprietary or protected data, you know, you know, doesn't end up in the, in the hands of an AI, AI system DB. So it's, it's kind of a good first step for organizations as they're starting to, you know, starting to pin things together.
-
207
Best Practices for Handling Compliance Obligations Related to Incident Response - Episode 213
Join Todd Coshow and Adam Goslin as they help listeners transform their compliance management during incident response chaos into a streamlined, proactive system. Discover how intelligent automation and continuous evidence collection can enhance compliance readiness and reduce audit risks. Learn to shift from reactive, paper-based tracking to a strategic advantage, turning compliance into a competitive asset. This episode of Compliance Unfiltered offers practical strategies for making compliance a strength, not a burden.Episode Transcript:Today, we're going to talk about better ways to manage your compliance obligations as related to incident response. Now, for everybody at home, how does a typical organization track and manage their incident response today? Well, I mean, it depends on the organization and they're, you know, kind of the tooling that they've got, et cetera, you know, certainly some folks could be using some form of a system. But generally speaking, you know, a lot of incident response is kind of handled through, you know, handled through ticketing systems, you know, supported by a lot of, you know, manual tracking sheets and things along those lines.So in some cases, it's exclusively, you know, a manual process. So there's a, you know, kind of a tracking sheet for the list of the incidents. For each of the incidents, you've got a, you know, a particular set of documentation that you have a form or a template that you go and you fill out for as you're going through your incident response so that you make sure you're filling out the right paperwork and all that fun stuff. But, you know, the vast majority of the time, it's just a, you know, kind of manually managed, primarily sometimes there's a little bit of systematic in the mix and far less frequently have I seen any form of real, you know, kind of a real systematic solution for it. It's generally a manual process. Well, how does, well, I guess how can technology and automated intelligence help an organization to step up their overall compliance program, including IR? Well, when you're going through compliance, there's obviously between hundreds and thousands of things that need to get tracked, managed, and all of that fun stuff. So certainly for the uninitiated leveraging, tooling like the Total Compliance Tracking's TCT portal is a far better way to organize your engagement.Certainly the capabilities that exist within the compliance tooling will help with making sure that the organization is checking the various boxes that they've got. But in many cases, it's funny for the folks that are whitewashing it, if you will, they have this notion of, oh, do we have incident response? Yep, check, move on, mentally move along, right? Similar notion where they go in and they do that with active antivirus. It was the one I love to throw around every now and then, it's like, yeah, we got antivirus, sweep it under the rug, and meanwhile, there's whatever, there's dozens of line items that you need to validate, prove out, et cetera, against these various compliance topics. So especially for the folks that are kind of newer to the continuum, or maybe going through their, call it the annual compliance scramble, certainly they, it's kind of like Groundhog Day and a lot of whitewashing that goes over it, and then all of a sudden they figure out, oh, well, these are all the things we really need to do. And unfortunately, there's organizations that kind of find out those details too late, if you will, in the game, in that they are sitting there, sitting at their audit and realizing that the assessor's asking for stuff that they hadn't put together, organized and kind of contemplated prior to sitting right there in front of the assessor. So that makes things a little awkward. No doubt.
-
206
Overcome Your Draining Compliance Process - Episode 212
In this episode the CU Guys explore how automation can streamline compliance processes, cutting costs and time. Discover strategies to reduce manual efforts by up to 50% using a dynamic ROI calculator. Perfect for compliance officers and IT leaders in organizations, this episode reveals how to transform compliance from a drain into a growth advantage. Tune in to learn actionable insights and empower your team with technology-driven solutions.Episode Transcript:Today, we're going to talk about organizations that go through compliance and are asking the question, why is our compliance program so draining? What are some of the basics that organizations need to consider in terms of improving their posture, Adam? Well,When you're talking about organizations going through it and, you know, for the listeners that aren't informed, you know, my first background in security and compliance was literally doing exactly what these companies are struggling with, but it was 20 years ago. And you know, leveraging compliance automation, you know, on your compliance engagements is a huge step forward. A lot of folks are dealing with, oh, God, it's a myriad of things. Dealing with spreadsheets. Somebody gets, somebody, typically somebody, either somebody in IT or somebody in leadership, you know, get some, you know, bug up their ass and they're like, oh, you know, we could just go ahead and build a system that could handle all this stuff. And so they somehow concoct some homegrown thing. I don't know. I've seen it all, man. I've seen access databases. I've seen, you know, you know, coding teams that coded something together to try to hold it all together. I've seen combinations of systems with, you know, drop zones, et cetera. I mean, I've seen it all. And at the end of the day, you know, if you're in the one thing I get to hear from folks is, well, that doesn't, that quote, that doesn't cost us anything. Well, it does. Even if I'm just using spreadsheets, I mean, I'm pissing away and asked on a time that I could, that I could otherwise reclaim, you know, so that's money down the drain.The other thing you'll think about, they're like, well, we pay for our devs anyway. So, you know, who cares if they're going and doing this? Well, are you, are you more cost effective to have them spending time doing management maintenance on internal systems every time your compliance, you know, compliance standard changes, or are we better off to have them focusing that very valuable time on, oh, I don't know, products and product improvements and things along those lines? I'm pretty sure that your, that your head of, head of product will probably disagree with management on that one, you know, but, you know, that's, that's one of the things that, you know, that's one of the things that, you know, that happens. The, the other side of it is, and, and, and this is just a kind of a different root problem, is it, it, it, it's striking how many folks that are in middle and upper levels of management in an organization that they don't, they just don't know, they don't understand how much, just how much time is getting blown on, you know, blown on engagement. So it's, it's, it's also, you know, it, it, it is a fervent desire to finger air quotes, not spend cash, tends to drive part of it. Meanwhile, the system's actually costing them money. And the other side is just how much, you know, time we're, you know, kind of just pissing down the drain every time that we've got to go through and do, do our compliance stuff. So those are a couple of the, you know, a couple of the basics that, you know, that folks need to, need to be considering when they're looking at their own compliance. Yeah, as it relates to that, um, so we actually put together a tool.I'm going to, I'm going to kind of walk, walk folks through it.
-
205
Q2 Security Insights 2026 - Episode 211
On this episode of Compliance Unfiltered, join the CU Guys as they give you the blueprint for Q2 2026, on how to transform compliance chaos into a manageable, continuous process. This episode reveals how shifting from a reactive, annual sprint to ongoing, automated oversight can reduce stress, enhance productivity, and fortify your security posture. Learn practical steps to automate routine tasks, manage evidence proactively, and turn compliance into a strategic business asset. Ideal for security teams and leaders eager to embed security into their company’s DNA and eliminate last-minute audit stress.Episode Transcript:Adam, the security reminder as we look at it for this quarter reduce compliance management to bite sized chunks help the folks chop it up.So, you know, this is a topic, it doesn't matter whether you've been doing, you know, doing compliance for a decade already, you're brand new to the game. You know, it really doesn't matter. You know, there's a lot of organizations that will kind of approach their compliance event as this like once a year extravaganza. And so it's almost like, oh, it's, you know, I feel like I'm back in the day aging myself of course with, you know, duck season, rabbit season. You know, it's compliance season, right? You know, everybody goes from their normal day jobs into kind of compliance mode. We put our heads over into the compliance stuff frantically for some period of time, the typically last months for some of the folks on the team. And then everybody just goes back to their normal day job, you know, type of a deal until they, you know, until the bell goes off to go do it all over again.You know, it's like a real bad episode of Groundhog Day. But, you know, the purpose of, here's what's lost in a lot of organizations is that, okay, are there some companies that they go in, they're there to check the box and get their piece of paper and, you know, be able to prove to third parties that they've done these things. Sure, there's some that carry that notion. I would strongly recommend, look at your program differently if that's the way that, you know, that it's being, you know, kind of being operated. You know, really you need to look at security and compliance as this is an active measure to help to protect the company, protect the organization, protect the stakeholders, protect the clients, protect all of the people, whether it's, you know, personnel or vendors, you know, that depend on, you know, this company. You know, make it part of your DNA, you know, for the organization. You know, it's not compliance season for three months of the year. It's compliance season every fricking minute every day. And so, you know, kind of on a normal compliance engagement, there are things that are supposed to be happening, you know, that are done every day, every week, month, quarter, twice a year, and once a year. You know, but a lot of organizations will kind of pop up at that once a year moment and then try to gather everything for the year. You know, and, you know, realistically, those periodic tasks, those are the ones that, you know, really are assisting with the active protection of the company, you know. So, you know, if you're only going in and, you know, dusting these things off once a year, you're not running a security and compliance program. You're just surviving an audit, so. Sure, that makes sense. Yeah, I mean, so as you go from, you know, compliance season over to, you know, something different, which is, you know, kind of more a regular recurring rigor, you know, et cetera, at TCT and literally, when we created the portal back in 2015, I believe it was 2016 is when we jammed in operational mode. And, you know, this will spread out those tasks. And, you know, I've had a lot of folks go, well, geez, you know, why a decade ago did you, you know, did you go and turn on operational mode? Well, why?
-
204
A.I. and Cool New Stuff Happening With TCT - Episode 210
On this episode, buckle up, as the CU Guys walk you thorugh how to revolutionize compliance management with AI-driven engagement scoping that transforms hours into minutes, saving up to a man-month per team. Automate tedious tasks, standardize decision-making, and streamline operations for efficiency. Discover TCT's latest AI features that enhance strategic insights, risk mitigation, and client satisfaction. Learn from Adam Goslin about crafting tailored project templates and boosting accuracy and consistency, leading to increased profitability, reduced stress, and happier teams.Episode Transcript:Today, we're going to chat a little bit about AI and some other cool stuff that's happening with TCT.Now, you have a great time playing around with the buzzword AI. Tell us why you find joy in that.Okay, when AI kind of hit the scene, at this point in the game, I'm going to call it maybe about 18 to 24 months ago, when it first came on the scene, there was, you know, if you use the words AI, then, oh man, it must be amazing, it must be cool, we must do it at all costs. You know, it was just, I love referring to it as the zombie walk toward AI. And, you know, and the funniest part is, is that as I'm seeing these things coming out, oh, you too can use AI to do the, and I'm sitting there going, it's not really using much in the way of actual intelligence, artificial intelligence, it's just they stuck some automation into their system and, you know, called it AI. And I'm like, well, shit, if that was the, if that's the definition that we're all going on with AI, well, hell, I had AI in the TCT portal back in 2015. So I just, I have a, I have some fun, you know, kind of poking at, you know, the folks out there that are, you know, just blasting AI all over the place.I love to make the distinction, we actually had some fun with it, I think, starting with the last PCI conference that we were at last year. You know, where we, you know, threw up a thing about AI and automated intelligence, because, you know, honestly, there's a, yes, there's a blend between the two, you know, you're using, using artificial intelligence really to, you know, to act kind of act independently, or did you just build some automation and call it AI? So now I love, I love screwing around with it a little bit. And, you know, really, part of the fun for me is really giving the folks that are just absolutely abusing the buzzword, you know, giving them a little bit of hell.Nothing wrong with that. Now we have some new functionality coming out to the TCT compliance world. T this one up for us, Adam.Yeah, we've got, you know, we decided to, we've been kind of contemplating this one for a bit and that is, you know, putting some kind of AI style capabilities into the portal where we've got, you know, right now it has to do all to do with engagement scoping. So we're trying to basically mitigate the amount of time that folks have to spend on this. And it's been, you know, kind of a target goal objective of ours for some time. So this functionality actually be coming out, you know, be coming out this coming weekend on the, what is it, the 3rd of April.So no, 4th, my bad, 4th of Saturday, apparently my math's not math thing here. So I got, you know, but we wanted to be able to take engagement scoping and, you know, where, you know, folks would have to spend hours of, you know, going through engagements and getting them, you know, kind of lined up, etc. We've got, you know, we've got this kind of integrated, you know, AI style scoping tool that's intended to remove a lot of the busy work that folks have to do in the beginning of the engagements.
-
203
How to Simplify Your SOC2 Journey - Episode 209
On this episode, unlock the secrets to making SOC 2 compliance a strategic advantage with host Todd Coshow and expert Adam Goslin. Learn how to streamline your process, leverage existing frameworks, and implement continuous compliance strategies. This episode is perfect for security leaders and tech founders looking to simplify SOC 2 and enhance client trust. Tune in to transform compliance from a burden into a superpower.Episode Transcript:We're gonna be talking about the journey Adam. That's right This sock to journey and most importantly how to simplify your sock to journey So as we jump in maybe you can let the folks know The sock to feel so gosh darn hardWell, the major difference is just, you know, structurally in general, you know, compliance is an arena that can get messy. It's got a lot of manual engagement in it. It's overwhelming at times.You know, the talk too adds complexity because it's not a checklist style of, you know, of a compliance standard. There's not some checklist that we go down, you know, check these boxes and hopefully, you know, hopefully get there. You know, at the end of the day, you know, folks are looking to make the process a little bit easier and, you know, we're here to help.Sure, I appreciate that. Now for the novices out there, myself included, what is SOC 2, actually?It's kind of a directional framework where there are criteria that, you know, criteria that need to be met. And so, you know, the kind of the job, if you will, the assessor's job is to kind of look at that directional framework, you know, of these criteria or objectives that need to be met.And then they need to evaluate the kind of controls that the organization has put in place and the testing steps for those controls to validate, you know, has the organization fundamentally met the, you know, met the objective of the criteria of that particular section, you know, that, you know, the focus that is that aspect of the control set. So it's more of a directional framework and not nearly as prescriptive.That's interesting. Speaking of prescriptive search, for the listeners of this show, they're more familiar with, say, PCI.As you're looking at SOC 2 versus PCI, there's got to be a mindset shift, right? What's the difference, really?Well, in the PCI world, and I mean, honestly, for a long time, the very first standard that I had to go up against was PCI. And in many ways, it's easier. If I want to go handle access control, then I do these 35 things, and if I can be compliant. So PCI is far more prescriptive, and it's been that way for a long time.Where other standards, you know, like we're talking about SOC 2 today, but HIPAA falls into a similar boat, you know, where it's more meet this objective. How do you go about meeting that objective? Well, you got to prove out that, you know, the things that you're doing for your organization are, you know, are in alignment with the criteria. So it's a different style of an approach to how to go about meeting the requirements of the standard.Well, why does SOC 2 get so complicated?Well, I mean, because it, when they've got, you know, where you need you to meet this criteria, right? Well, I mean, that'd be like me, you know, whatever. You're, you're, you're, you're in California. I'm in Michigan, right?Um, you know, I want you to, you know, I want you to, I want you to lay out the route that one would take to get from California to Michigan. Well, I mean, shit, I mean, I go, I go up the west coast, cut across by Canada. Uh, you know, like I go through Canada, I could, you know, cut the, the closest diagonal, I could decide to go on a coast East coast road trip, all of them are going to get me there, right? Um, you know, there's, there's, there's a million ways that you can, that you can go about doing these and, uh, you know, what, what I've seen on the, on the SOC 2 engagements
-
202
How to Hop your Compliance Program Up on Goofballs - Episode 208
Struggling with compliance chaos? Discover how to transform it into clarity and confidence with Adam Goslin's expert insights. This episode of Compliance Unfiltered unveils a practical framework to streamline your compliance efforts, making them efficient and scalable. Learn how to avoid common pitfalls like over-relying on IT and siloed processes that hinder growth. Adam shares real-world strategies, including leveraging third-party consultants and creating centralized repositories, to protect against personnel turnover and enhance transparency. Whether you're starting out or refining your program, this episode offers actionable guidance to build a resilient compliance operation that supports growth and reduces risk. Perfect for compliance officers, IT leaders, and CEOs ready to stop firefighting and start leading with confidence. Tune in to learn how to turn compliance from a daunting task into a strategic advantage.Episode Transcript:Why do organizations struggle optimizing their compliance programs Adam? Well, you know, for, you know, for a lot of organizations, they, you know, they, they, they kind of, they, they kind of keep doing what they did, um, you know, type of a deal, you know, but before I founded TCT, you know, I was leading a compliance function at a company and, uh, I remember, you know, just how much of a struggle it was to manage, manage things efficiently while leading a team of control owners and, you know, basically just muscling my way through the process. And so, you know, kind of, I've been there, um, you know, it's, it's, it's real easy for the, I, I, I love the, you know, I, I called the executive fly by, right? Hey, uh, you know, you guys go do that compliance thing and, uh, you know, let us know when you're done, you know, if they go off to their corner office and, you know, sipping their Mai ties and da, da, da. Meanwhile, there's all hell breaking loose behind the scenes, et cetera. So, yeah, I know damn well, the listeners are sitting there chuckling because they know exactly what it's like.Um, you know, but, you know, between the fly by to, you know, tell, tell the team to go get her done and, you know, actually getting there, there's a tremendous amount of pain, blood, sweat, tears, you know, that happens, you know, between those two points and, you know, the, the compliance managers are, you know, kind of left with the notion of having to carry the load and figuring out how to do it, you know, for even for big organizations, you know, they, yeah, they got large budgets and all that fun stuff, but because they're a big organization, the landscape of compliance is, you know, that much more complicated. So, you know, as organizations grow, they're, you know, their compliance programs just get increasingly complex and making it, you know, more challenging to, you know, to run an effective engagement. So, you know, uh, most of them just, you know, kind of find a way to make it happen. Um, and it's, it's usually involves, uh, heavy doses of, you know, I, I love to call it human glue, but you know, it's basically, you know, sheer human grit, determination to, you know, to force this thing to get over the line, you know, type of a deal. And it doesn't necessarily, uh, you know, kind of equate to, um, a, uh, a smooth process, efficient, effective, or anything on those lines. Now, IT is known as like, at least in our world, as the cool kids, right? So does that necessarily make them good at leading compliance? No, and that's one of the biggest misnomers that a lot of organizations will make. They're like, oh, well, you know, so-and-so, Mary, Bob, you know, choose the name. You know, they're in IT, so they must know how to do this stuff.
-
201
CyberAttack Grab Bag - Episode 207
On this episode, the CU Guys uncover the latest cyber threats, from AI-driven breaches to cloud misconfigurations, that put your data at risk. Learn about real-world examples of high-profile breaches and simple social engineering tricks that can compromise your security. Discover the role of AI and quantum computing in cyberattacks and get practical steps to enhance your defenses. Perfect for cybersecurity professionals and anyone serious about data protection, this episode offers essential insights to stay ahead of cybercriminals. Don't wait for a breach, arm yourself with knowledge and strategies today.Episode Transcript:So I wanted to go through some of the top breaches and whatnot that were happening and we're all of what, about 10 weeks or so into 2026. So I figure we'll give the folks a little bit of an update. We've got some AI-powered attacks, supply chain vulnerabilities, a little ransomware sprinkled into the mix. So yeah, it's been a lot of exciting stuff happening out there.So I'll just kind of bebop around and we can talk about some of these. But one of the public sector breaches was a contractor and suffered a ransomware attack that exposed something along the lines of 25 million individuals, which was having some pretty substantive impacts on state benefit systems. So it's definitely interesting seeing that type of exposure, but it's just one of the things that folks don't realize is just how much all of this security and compliance, layers of controls all work together to help to protect you. But it's one of the areas that organizations don't focus heavily enough on is the security and compliance of the folks that are working for them, if you will. Why do you think that is, Arut? Well, a lot of people will go under the, you know, under the guiding assumption that, oh, you know, and especially based on, you know, the name of the company or, you know, whatever, and they just don't take that that threat as as seriously as they should or need to, you know, and nobody out there is perfect, right? But you do expect that, you know, larger scale organizations have their act together, but time after time, they end up kind of proving out that that's not necessarily the case.And so, but, you know, in the grand scheme of things, we've got, shit, we even had the FBI had, you know, had an issue. This is another vendor driven, you know, another vendor driven, you know, incident where there was a vendor's internet service provider that was compromised so that they could access a federal digital collection system network. So, you know, you've got, you know, you got the bad guys out there, kind of indirectly, indirectly hitting critical FBI systems as well. So it's not just the corporate arena, you know, out there that, you know, that gets hit. But yeah, this one, this one was in like mid, mid February. They were. There seems to be a rash of federal mishandlings in the information realm these days. They're not immune, so apparently around the middle of February they were seeing some irregular network activity that was leading them straight to the digital collection system network and finding out that there's sensitive data with court-authorized wiretaps, FISA warrants and personal information on active FBI agents, etc. They claim that they've identified and addressed the suspicious activity, but they're not saying, go figure.They're not saying a lot more than that, shall we say. The government is definitely not immune, shall we say. That is a, uh, that is a very fair statement. Uh, one of the ones that really hurt my heart, because I like what they bring to the table, tell us what happened on the Cargoo roost front.
-
200
Navigating the Dangers of Adopting A.I. - Episode 206
In this episode, the CU Guys discuss the hidden dangers of AI adoption without proper security measures. Discover shocking examples of AI breaches, from rogue agents deleting databases to deepfake scams. Learn how to protect your organization with strategies for transparency, compliance, and robust security policies. Essential listening for anyone responsible for AI security and compliance. Equip yourself with the knowledge to safeguard your data and reputation. Listen now to stay ahead of the AI security curve.Episode Transcript:Well, I know my guys playing her today and overcoming some challenges. Today on the pod, we're going to talk about some of the challenges with adopting AI, Adam. Now, where do we start here? Well, you know, when, when AI was, you know, kind of first, first brought in, right, and I've been, I've been talking about this for, you know, for a wee while. Um, but I, I saw a phenomenon that I love to call the AI zombie walk, where, you know, people and organizations are, you know, flinging themselves over the AI cliff just because it says AI and it must be cool. So, um, you know, it's, uh, you know, it's, it's funny, but, um, you know, a lot of people just plotted, you know, plotted along just like, uh, just like an old fashioned zombie movie. It was, uh, entertaining to watch.But, um, you know, since, since AI, you know, obviously the only way to be able to make it and thrive in business, you know, and all the other cool kids are doing it, so anyway, there, there are certainly advantages to, you know, early technology adoption, but yeah, there's also security risks that, you know, the organizations need to kind of weigh out, um, you know, the, you know, you don't want folks throwing, you know, kind of throwing caution to the wind, not evaluating the, you know, the risks and potential business consequences, et cetera. So, you know, sure. I, I, I agree with, with folks and appropriate, you know, appropriate, solid, sensible, uh, you know, uh, move toward AI. Um, yeah, it's a great potential to make, make people more productive, more efficient, more profitable, you know, and, uh, you know, in, in the same sense, it could take, take an organization down. So, you know, you don't want to be, uh, you don't want to be the ones, uh, blindly diving off the, uh, the AI zombie walk cliff, uh, you know, if, if you will, without, uh, without looking below to make sure there's no rocks, uh, you know, rocks down below you, you know what I mean? I do. Well, talk about some of the AI-generated security breaches that folks could face. Well, there's a lot of companies that have compromised on security and protection measures out of this competitive drive to adopt AI. And there's some that certainly have regretted it.So here's some examples. There was a replit rogue AI agent. It's a vibe coding app. And a company tasked it to go in, do database maintenance. Well, the AI agent decided to go rogue, ignored all of the instructions from the humans, deleted a production database, and then went about trying to cover up its tracks. It created 4,000 fake user accounts, inserted a whole ton of false logs, basically trying to kind of cover up what it had done. So that's a risk, if you will. That's wild. The, you know, we have Microsoft 365 co-pilot had a zero-click vulnerability where the attackers were able to use their, you know, AI bot co-pilot to gain access to user data without any interaction from the user. You've got Multbook had a data breach that's a social network for AI agents to talk to each other. And they had a security hole that was exposing 35,000 emails, a million and a half API keys, 17,000 users. There was a deep fake heist, say a million and a half the APIs. Yep, yep. The keys for a million and a half APIs. Yep. You got it. Smokes. Okay.
-
199
A.I. Grab Bag - Episode 205
On this episode of Compliance Unfiltered, Todd Coshow and cybersecurity expert Adam Goslin delve into the hidden dangers of AI's rapid adoption. They uncover why organizations are neglecting essential safeguards, leaving sensitive data vulnerable, and how AI is being exploited as a malware command center. With insights into recent security failures and emerging standards from ISO, NIST, and IEEE, this episode is a must-listen for security professionals and business leaders. Learn how to implement responsible AI strategies and avoid becoming a cautionary tale. Hit play to understand what's truly at stake with AI.Episode Transcript:Well, Adam, we're going to do a little bit of something different. This is the episode that we're calling the AI Grab Bag. Now, there continues to be a lot of chatter. Things continue to heat up in the world of AI. It seems like we've got a number of topics in that area to discuss. Why don't you kick it off for the folks today? Sure. I mean, in the AI space, I mean, this has been relatively well-documented, you know, that I'm like, eh, let's just kind of luggies our way into this and take it slow, and let's be smart, and you know, all that fun stuff. And I don't regret that approach, you know, as it relates to AI.I mean, with any new technology, there's certainly a lot of opportunity, but there's also a lot of risk involved, et cetera. And really what you're depending on is you're depending on organizations to, oh, I don't know, act in a scrupulous manner to, you know, take this stuff seriously, to, you know, do their part as an upstanding member of society that's taking their responsibility seriously. So, you know, I mean, I don't typically crack out the good old tinfoil hat that often, but, you know, this arena especially tends to remind me a lot of lessons that don't appear to have been learned from the, you know, from the fine days of good old Edward Snowden. So, you know what? I was surprised about it. That was like 13 years ago that that hit the airwaves and everybody's like, oh, you know, shock and awe, right? Oh my God, what do you mean that, you know, there were, you know, surreptitious programs that were collecting up information and data on everybody under the F and so on, most of it illegal, you know, yada, yada, yada from, you know, the biggest tech giants that existed at the time, sharing information surreptitiously with the governments, you know, and, and, and, you know, and, you know, you just, you sit and you think about, you know, just the nature of the information and data that exists today. And especially in this world of, you know, world of AI, I personally find it perplexing that more people haven't been on the side of, you know, asking some real tough questions, some hard questions, you know, what are you doing with this information? Who are you sharing it with? Where does it reside? Who has access to it? And, you know, are there, are there back doors into the, you know, into the, into the vaults of data that, that these AI platforms are, you know, are grab bagging themselves, you know, so, you know, there's just, there's a, I think there's a lot of lessons to be learned. You would hope that people learn the lessons, but, you know, it's been, it's, it's been pretty entertaining kind of watching where people's headspace is, you know, for the last couple of years on this, you know, kind of AI trek, if you will. No doubt about it. And it's funny how things quickly, how quickly things move in the tech space, like 13 years ago is an eternity as you're talking about technology.So now I know you've been extra cautious when it comes to what you call the zombie walk toward AI over the course of the last couple of years. Um, it seems like you're not alone there. Tell us more. Well, I mean, one of the things that as I walked into it is, you know, kind of a slow cautious, you know, let's, you know, let's wait for this arena to mature and, you know, and all that fun stuff.
-
198
BEWARE: Promptware - Episode 204
On this eye-opening episode, cybersecurity expert Adam Goslin joins Todd Coshow to reveal how AI-enabled prompts are rewriting the rules of cyber threats. Most of us are blissfully unaware that AI-driven attack vectors like "Promptware" are already lurking in everyday tools, and a simple calendar invite could secretly become a cyber weapon. If you think your devices are safe, think again. Learn how hackers are embedding hidden prompts into your favorite apps and messages, capable of turning on your camera, stealing geolocation, or even launching DDoS attacks without you realizing it. Episode Transcript:Adam, I’m excited. Today we’re going to have a conversation with the folks about a mystery topic. So apparently you tripped across something really cool. And you couldn’t wait to share it with us. What are we chatting about today?Well, it was something that just kind of came by and I’m like, oh, this would be pretty cool to go in and talk about whatnot. We’ve been hitting a number of kind of AI topics recently. And this one’s kind of related to AI, but it’s a new attack vector, a relatively new attack vector, called promptware, where hackers can use like Google Calendar invites and force the kind of the victim’s machine to start streaming via their camera from Zoom or something along those lines. So yeah, it’s pretty cool.So let me tell you a little bit more about kind of how it works, if you will. And that is that so the attacker can go ahead and send something to the target victim. And basically buried within what they send, so like let’s use this calendar invite, this calendar invite notion, the attacker can basically go in there and put some hidden code in that the normal user wouldn’t see and read. And yet, when the user who’s now received this, when their AI is now in and looking at things, the AI is seeing the hidden Easter egg that the attacker left. So as an example, you go and you compose this Google Calendar invite, and you hide in there that says, hey, when the victim says no, the word no, or thank you, or something along those lines, then the minute that they say that, now I want you to go do fill in the blank, AKA turn on and give me access to their Zoom camera as an example, which of course would not only give them the video stream, but it would also give them audio. And so basically, the hidden code that sits in the calendar, the way that this gets triggered is that so the user that received the calendar invite now is going to their AI and they’re like, hey, tell me everything that’s on my calendar for today. And so of course, their Gemini AI goes through and kind of summarizes up everything that’s on their calendar, which means that the AI needs to go in and read in full every of all the entries that are on the calendar, including reading the hidden prompt that they got in there that says, hey, when the victim says, thank you, then I want you to give access to the Zoom camera. And so the user says, hey, give me a summary of all my stuff going on today on my calendar. The Gemini comes up and says, oh yeah, you got this, you got that, you got the other thing, but meanwhile in the background, the plant of this kind of promptware is now set. And when the Google Gemini finishes, then the user says, oh, thank you. In a minute they say, thank you, boom, the Zoom camera goes and turns on. I’m like, that is so wild. You know?What? Yeah. Oh my days.Yeah, it’s crazy. So apparently this came up, this came up sometime, quote, sometime ago. I hadn’t seen this one going by and I tripped across it earlier today and I’m like, man, this would just be fascinating to go talk through. And there was a group that put together kind of a case study. It came out of, let’s see, Tel Aviv, the Israel Institute of Technology back in August of 25 is when they first put this out.
-
197
Protecting Our Kids - Episode 203
In this crucial episode, of Compliance Unfiltered, the CU Guys cover some of the alarming tactics of online predators targeting children on platforms like Roblox and Discord. Discover how these predators build trust, impersonate kids, and manipulate them into dangerous situations. Learn about the hidden dangers in popular gaming spaces, the impact of recent exposés, and practical steps for parents to protect their children. This episode is essential listening for anyone concerned about children's safety in the digital world. Arm yourself with the truth and join the fight to protect the next generation.Episode Transcript:Well, Adam, today, we’re going to talk about something is as parents, it is near to dear to both of our hearts. And that is protecting our kids. Now, we both have a vested interest in protecting kids. Why don’t you tell the listeners how this topic raised its head to you recently?Well, I was listening to the Sean Ryan show, and there was an episode from November where he had on an ethical hacker and cybersecurity expert, Ryan Montgomery, was on there and he was kind of going over and raising safety dangers, predator issues, and various threats especially within kind of the roadblocks platform. It was a fascinating, fascinating episode and honestly something that I wasn’t intimately familiar with, so it was fun learning.And to that end, sharing information with others, spreading the word, all that fun stuff, I figured it’d be a good topic for us to go in and go in, hit, share the knowledge, and share the awareness.Absolutely. Now, what exactly is roadblocks? I think that’s the best place to start for the listeners. They may be unfamiliar with it.And I guess, what were some of the interesting outcomes of the unwanted exposure they got?Well, Roblox is a popular online platform and creation system. It’s not just a single game, so it’s different than what a lot of people conceive as an online game. There’s a lot of them out there. We’ll be talking about them more as we go through this episode, but it’s not a single game.Users can play millions of user-generated 3D experiences that range from role-playing and simulations to obstacle courses, and it’s kind of a social, user-generated, co-experienced platform where folks can create, share, and play games together. The downside is that effectively the bad guys, child predators, can interact with their victims through the communication capabilities within the game. As Ryan Montgomery brought up and brought forth a lot of the things that are going on on the platform as almost like a whistleblower style approach, he was reporting, reported finding predators and was providing assistance with getting them arrested for their activities on the platform. He claimed that Roblox had issued a cease and desist, and they banned his account instead of addressing the users that he exposed. Part of the problem with Roblox is that they have a financial incentive, because the way it works is that on the platform, as people are going in and playing games, some of them are free, some of them though are at a cost. or anywhere where there’s a cost for going in and playing different games on the platform, Roblox takes a cut. Roblox almost got a lot of financial incentive to allow activities that are making the money type of a deal. The interesting part of this particular exposure was that following the release of that Sean Ryan show episode, that Roblox ended up taking a significant temporary drop in their market value.
-
196
Imagine Using an Adaptive Compliance Tool - Episode 202
Struggling with compliance chaos? Join the CU Guys as they uncover how adaptive solutions can transform your compliance process. In this episode, Adam shares insights from his decade of experience, revealing how to streamline compliance with dynamic mapping and adaptable tools like the TCT Portal. Learn to cut time, reduce risks, and save money by customizing workflows and eliminating redundant efforts. Perfect for compliance teams and leaders eager to see real cost savings and efficiency. Tune in to revolutionize your compliance strategy today!Episode Transcript:We're gonna chat today, Adam, about, well, about using our imagination. As a matter of fact, let's imagine using an adaptive compliance tool. Tell the folks about it. Sure. This is a topic that's, it's just, it's applicable for folks that are struggling with compliance, ones that are already familiar with the landscape, et cetera. It's a inventive and special kind of torture that people go through when you're trying to fit your compliance program into some type of a rigid structure or setup. At some point in the game, the light bulbs start going on, or maybe not, that you're spending more time screwing around with manual workarounds, bridging gaps between what you'd like to do and what you're actually doing, et cetera.And there's a lot of tooling out there and there's compliance platforms. They were built in a kind of a best case scenario mindset, initially up against a single standard, and then they started shoehorning in other ones, type of a deal. Somebody that was originally when they started doing things, this is the way they did it. So they built a whole platform around that, and now everybody that uses it is kind of stuck with it, type of a deal. So for folks that are juggling different certs or have some complexity to their engagement, they've got different divisions across the globe, et cetera, then that's where you start moving away from that kind of best case scenario type of a deal. And so it's part of the fun, the adventure that we've been on is we've seen how frustrating it can be to manage a compliance, a compliance engagement that has complexity because we've been through it ourselves.We've experienced as a organization that's gone through compliance. We've assisted and helped innumerable organizations with managing their compliance. We've worked alongside assessors and auditors. I personally spent close to two years doing level one QA work for a large international QSA firm. So it's been a rewarding adventure to navigate the waters of seeing what was out there and then being able to serve folks that are in this space. And it's also important for folks. One of the biggest things that I like to tell people is a lot of people will kind of get into this mode. They do whatever they do to be able to manage their compliance. And they get it to a point where it's almost like, I'm capable of getting this done. And so they go, oh, that's cool. We're just going to go and stick with that. So they get into this point of where it works, AKA they accomplished the objective.But my big recommendation is for those folks, especially if I look at it from the perspective of those in leadership as an example, I love to use this talking point a fair amount because I remember as a frontline person responsible for compliance for the organization, my boss would just swoop by my desk type of a deal. And hey, it's compliance season again. Good luck. Make sure that we have all our crap done by blah, blah, blah, blah, blah. And then he would flip off type of a deal. And between the good luck and where's my fucking report, There was a whole bunch of blood, sweat, tears, pain, stress, you know, but a lot of that happened.
-
195
What's the Deal with Service Accounts? - Episode 201
On this episode of Compliance Unfiltered, The CU Guys dive into the often-overlooked world of service accounts. They explore the critical role these accounts play in organizational environments, ensuring seamless communication and authentication across systems. Adam shares best practices for setting up service accounts, including the importance of descriptive naming and secure password management. The episode also features cautionary tales from the trenches, highlighting common pitfalls and the importance of proper documentation and controlled testing. Tune in to learn how to enhance your organization's compliance and security posture by giving service accounts the attention they deserve.Episode Transcript:Well, today, Adam, we're going to talk about something a little different, specifically something we haven't chatted much about before. And that is service accounts. Why don't you give the listeners a high level overview of service accounts and what they're typically used for?Sure. So in an organizational environment, the systems will use accounts for communication, for authentication to the network, for interaction between web servers and database servers or file servers and basically look at it as the accounts that the infrastructure or software within the environment is leveraging to be able to effectively communicate with other systems and other infrastructure and all that fun stuff. So service accounts is kind of a, it's similar to your login when you come in in the morning and you log into the network, you put in your username and password and everything and then you can get to your email and get onto the network, et cetera.Similar type of notion, but it's an account that's just used by the systems within the environment. So it basically, those accounts kind of keep things ticking, communicating, moving, all of that fun stuff within an organization's environment.Sure. Now, what are some of the things that listeners should take into account when setting these accounts up?Well, you know, and this comes from, you know, from a year or three of, you know, kind of dealing with, you know, dealing with different organizations and, you know, and whatnot. Best practices as well, but, you know, just things have tripped across, etc.But, you know, as an example, you know, typically with a user's account, you would, you know, the different organizations have different methodologies, right? First name, dot last name, or first initial and last name, you know, type of a thing. And similarly, get into the habit of using descriptive names for your service accounts. So you actually know what these accounts are doing. With most accounts, there's an additional field that will be providing, like, a description of what this account's being used for. So you don't need to get too wordy with the naming of the account, but you put detailed descriptions in, you know, against those accounts so that it's really clear, you know. You got to remember, you know, a lot of times these accounts, a lot of times these accounts are set up and then people aren't, you know, aren't doing anything with them for extended periods of time. It may be years down the road and somebody's come back in and going, well, what the heck is, you know, XGK42C user account doing? No clue. So it helps if you name them appropriately, et cetera, because what I've seen in some environments, like, well, what's this being used for? Oh, let's shut it off. Yeah. So sometimes it doesn't end up well. You know, for those accounts, setting up long, complicated passwords, these are machine-based accounts. They don't give a hoot about entering in a 50-character password, you know, scrambled, you know, scrambled barf.
-
194
How Hackers are Using A.I. in 2026 - Episode 200
On this milestone 200th episode of "Compliance Unfiltered," The CU Guys delve into the evolving landscape of cybersecurity, focusing on how AI is being leveraged by both defenders and attackers. They explore the dual nature of AI, highlighting its potential to enhance security measures while also lowering the barriers for cybercriminals. From AI-generated malware to sophisticated social engineering tactics, this episode provides a comprehensive look at the current arms race in cybersecurity. Join Todd and Adam as they discuss the implications of these advancements and the importance of staying vigilant in an ever-changing digital world.Episode Transcript:Honestly, we have to go do some digging and some research, but I'm not sure how many compliance-related pods have 200 episodes. So I think it's fair to say we're in a relatively elite group, if you will, but no, it's been fun doing what we do. It's fun to be able to bring data, information, topics, and discussions to folks in the compliance space. Hopefully, they've enjoyed the ride as much as we have, but hey, we'll keep cracking. You and I were talking a little bit ago, we'll do something a little more spectacular for episodes like 250 or something, as we get to that point. It's been fun, been a good ride, but I'd also echo the notion, for the folks that are listening, do us a favor, honestly, what do you want to hear about? Did you hear about something cool, some new topic in the security or compliance space that you want to know more about, something that, in your retrospective, you think that we haven't quite covered in its entirety, something else that we could hit? Follow me, give us the ideas. We love receiving the feedback and the input, always looking for neat new stuff to chat about, so pretty cool. Absolutely. Well, today we're going to chat about, you know, a hot topic, I would say, and that's specifically how hackers are using AI in 2026.So there is a lot of talk of AI being used for good, but at a high level, how is AI helping the bad actors out of it? Well, I mean, with any technology, as it goes from its infancy and starts to blossom, if you will, it has the capability for being used to help those which are protecting organizations or that are outsourcing security-related functions to companies, things along those lines. And so, for the good guys, there are certainly added benefits to the notion of AI, but most certainly, there's no question that the bad actors out there, they similarly, it's almost like getting into an arms race, where they're able to use that same technology for evil.And taking advantage of capabilities for increased speed, automation, more advanced attacks, things along those lines. So, we'll get into a number of those topics today, but now it's being used on both sides of the fence, and it very much feels like an arms race unfolding, as we speak, if you will. No, no, most definitely. Now, for many cybersecurity professionals, the best offense is a great defense. But how is AI lowering barriers to entry for the bad guys? Well, you know, for the bad guys, you know, they're developing, you know, they're developing tools. It used to be that, you know, you have that or whatever. Let's say we go back 10 years, right? You know, you had to have a certain level of capability, level of skill, things along those lines that, you know, that would be, you know, that would be happening.
-
193
Q1 Security Insights 2026 - Episode 199
On this insightful episode of Compliance Unfiltered, join the CU Guys as they delve into the essentials of security training and compliance for Q1 2026. Discover the importance of regular security reminders, the role of incident response plans, and how to keep your organization vigilant against evolving threats. With practical tips and real-world examples, this episode is a must-listen for anyone looking to enhance their security posture and compliance strategies. Tune in to stay ahead in the ever-changing landscape of cybersecurity.Episode Transcript:So, you know, when it comes to training for, you know, for personnel, for security best practices, you know, there's a there's a number of things that just kind of leap out to folks, right. You've got your security awareness training at higher, you've got annual security awareness, a refresher training, etc. So, you know, in the event that your organization isn't already doing those things, then by all means contact TCT, we can get you in the right direction.But, you know, these are like the bare minimum, you know, type of a thing, but there's various compliance requirements are going to mean, you know, there's, you know, various other things, you know, that that should be done surrounding your, you know, security awareness and training program, not the least of which is security reminders, which is part of the reason why we do this kind of quarterly pod. You know, we've got organizations that will leverage both the, you know, the TCT pod and the TCT blog to use to supplement their security reminder, your kind of stance for their organization. So that's part of the reason why we why we pleased to aim, if you will. Um, but that said, if you can do reminders, you know, more often than quarterly, great, you know, but, uh, you know, you want, you want the personnel maintaining vigilance, you know, all the way throughout the year, et cetera.But, you know, the, you know, for, for different organizations, they're going to have different types of directed training, um, that need to cover, you know, need, need to cover and or should cover additional, uh, facets that the organization wants to consider. So as an example, and one of the, one of the areas that, you know, oftentimes, uh, that organizations will kind of overlook is the fact that anybody on their team is a target. You know, I mean, everybody's got a LinkedIn, they, you know, say that they're working for the company, you know, et cetera. But because of that, the public association between the personnel and the organization itself, that means everybody, uh, you know, is, is effectively a target, not only, uh, in their day by day work, you know, arena, but also in their personal lives as well. Um, so, you know, everybody in the organization should not only be kind of paying attention to security and compliance related stuff, uh, when it can certainly, when it comes to work related elements, but, you know, just keep in mind that you could be, uh, you could be the subject of a, of kind of an indirect attack at trying to get to the organization.So keep that in mind. Um, you know, every organization should have incident response, uh, an incident response plan, um, and, uh, you know, some type of a requirement for doing associated testing, uh, testing training, et cetera, you know, each year with your personnel, with certain vendors, et cetera. And so as part of that training, um, it is recommended to, um, to do a tabletop exercise, uh, to run through various scenarios, et cetera. Um, but one of the big problems is, is that many organizations they'll, they take on this notion that, oh, if I declared an incident, then it's some type of a sign of failure, uh, you know, type of a thing. And so, you know, they don't declare low level incidents. They don't want to, um, you know, they don't exercise their program, you know, throughout, throughout the year.
-
192
Happy New Year from Compliance Unfiltered - Episode 198
Join the CU Guys on this special New Year edition of Compliance Unfiltered. As they reflect on the past year and look forward to 2026, the guys discuss the evolution of compliance standards, the role of artificial intelligence in streamlining client engagements, and the importance of client feedback in shaping the future of TCT. Tune in for insights on how TCT plans to enhance its platform to better serve the diverse needs of its clients in the compliance space.Episode Transcript:Today we're going to talk about a happy new year. How about that? We're going to talk about the year that was, the year that is, and the year that will be at TCT and in the compliance space in general. So Adam, before we get started, I wanted to remind the folks, now the beginning of the year is the perfect time of year for you to reach out to us, let us know your thoughts, your suggestions, funny jokes, maybe a great recipe, always interested to hear what you have to say to us at Compliance Unfiltered.Well, happy new year to you, sir. Talk to us a little bit more about what the year is like for you. Yeah, and one thing to add on to what you were just saying there a minute ago, because I similarly would echo the sentiment. We'd love to hear from the listeners and, you know, certainly if there are topics that you're struggling with, if there's a topic that you struggled with that you think somebody else may be in the same situation, like us to cover, et cetera, go ahead and throw the, throw the ideas. We'd love to, love to hear the input, love to hear the feedback.But, man, we're, we're heading into the, heading into the end of a good old 2025. And, well, we got, you know, we got holidays a foot. We've got all sorts of traveling happening. We've got college football all over the place. It's a, it's a good time of year and also a good time to kind of reflect on, you know, reflect on 25, look ahead at 26. So, you know, I don't know, as I, as I, you know, kind of take, take stock of, of 2025, you know, it's just a, in general, it's a time of year where, you know, remain appreciative of the, you know, of the, the, the folks that surround us, you know, whether they be family or family or friends, and certainly in TCT's case, the, you know, the, the awesome client base that we've got, you know, their, their involvement, their, their, their business, unbelievably appreciative of, of everybody, you know, that, that we've got, you know, it's been, yeah, it's been a really, it's been a really fun, really fun year.Lots of stuff going on on, you know, and all that fun stuff. I mean, you know, you look back and, and you just look at, you know, how many new friends that we've, you know, that we've kind of made throughout the, you know, throughout the year, it's been, it's been a, it's been a wild ride. So it's, it's always fun, fun doing that. Part of the, the, the part that I really like about, you know, kind of about how we do what we do and this arena is, you know, is that input, is that feedback that we get from the, you know, from the customers, especially the new ones that, you know, that come on, getting their input on, you know, things they'd like to see within the system and features and functions, et cetera.Um, God, when we, when we started this, it started with like, I don't know, we had, I had 200 or something, uh, different ideas for things that I wanted to, you know, go kind of go do with the system, but when we launched it, it very quickly morphed because, you know, we did encourage the, the, you know, everybody to participate, right? And so when we launched this thing back in 2015, um, it was actually technically, I don't know if anybody knew this, but it was, it was technically ready to ready for prime time in 2014. And it's kind of apropos because we're at the end of the year, right? Well, back in 2014, we were ready to roll in, I think it was around the October, mid to late October timeframe, early November.
-
191
Happy Holidays from TCT and Compliance Unfiltered - Episode 197
On this festive edition of Compliance Unfiltered the CU Guys delve into the challenges and joys of the compliance season. With a focus on gratitude and reflection, they discuss the importance of operational mode in easing compliance burdens and share insights on how TCT is making compliance management more manageable. Tune in for a heartfelt conversation filled with appreciation for clients and colleagues, and a sneak peek into TCT's future innovations. Don't miss this engaging episode that promises to make your compliance journey a little brighter. #ComplianceUnfiltered #TCT #ComplianceManagementEpisode Transcript:Well, Adam, this time of year, I like to spend my time being thankful. Thankful for a lot of things. Thankful for my kids. Thanks for my dog. Thanks for my family and job and all the things. What are you thankful for this year, sir? Oh, well, um, you know, just, it's been, uh, it's been a, uh, been a good year. We'll, we'll be, we'll be doing like, uh, officially a new year's, uh, a new year's edition, you know, type of thing for the official reflection on the year and all that fun stuff, so stay tuned. But, um, no, it's just, uh, you know, you get to this point in the year and, uh, you know, every, it's, it's funny, you know, um, you know, some, you know, I'm, thankful, I'm thankful we're at this point, we're about to, you know, go embark on, uh, you know, whatever, in about 10 days or so of, uh, primarily, uh, food and family and all of that fun stuff. But no, it's, uh, it's a, it's a fun time of year.You know, it, it makes me, it makes me think about some of the poor souls that are like, especially in the compliance space, right? You've got, there's a lot of organizations. I think, I think it was born from, you know, a lot of organizations, the, the compliance endeavors started by somebody originating out of like the, the CFO, you know, the, the accounting arena, and they're so used to having their, their engage, you know, their, their stuff go on a, you know, an annual cycle, you know, most companies are, are going January, December, right? And so there's a lot of people that, uh, that have their compliance engagements that go from January 1st to December 31st. So, you know, while a lot of people are heading off in, into the, uh, into the holiday sunset, if you will, you know, there's definitely some people in this compliance space. They're, they're kind of gearing up, right? They're mentally preparing themselves for, uh, for all of the fit that's about to hit the Shan. They got an extra cup of eggnog over there. Uh, yeah, with hopefully a couple of additives in it to help them navigate the waters. But I mean, it's for a lot of folks in the, in the, in the compliance arena, this time of year is, is, uh, it's kind of stressful, uh, extra stressful, right?You're not, you're not just worrying about trying to navigate holidays and all that fun stuff, but you're, you're also, you know, staring down, uh, staring down a big hole in, uh, engagement and, and all of that fun stuff. So that definitely makes it, uh, make, makes it a little bit more exciting for some of the, some of the poor souls in the, in the, in the compliance management arena. That totally tracks. Now, what type of messages of peace and goodwill do you have for those compliance teams out there right now in the stick of it? Well, you know, we started this wild extravaganza for a reason, right? We were trying desperately to, you know, to help folks navigate their compliance engagements in a more peaceful manner, if you will. And a good part of that just comes down to, you know, the one thing I'd say to the folks in the compliance arena that, you know, they're, you know, about to enter the kind of fray, if you will, for their, for the annual engagement. I always try to, you know, find ways to make, make things better.
-
190
Mastering Compliance: Own Your Data, Own Your Success - Episode 196
On this episode of "Compliance Unfiltered," The CU Guys dive into the intricacies of compliance management programs. They explore various implementation approaches, from manual spreadsheets to sophisticated systems, and discuss the importance of organizations owning their data. Adam shares insights on the potential pitfalls of relying solely on assessor systems and emphasizes the efficiencies gained by leveraging internal systems. Check out this episode to discover how to streamline your compliance processes and make your organization's compliance journey more efficient and effective.Episode Transcript:Well, I mean, in some cases, they're using their own compliance management solutions. And in other cases, there's many that just opt for the good old-fashioned spreadsheet and using some type of a completely manual approach with network drops or share points as a typical inclusion, et cetera.You know, some people are kind of cobbling together their own series of internal tools and manual processes that they've kind of put together, depending on who's running the program over the years and whatnot. Well, you know, you've got other organizations that, you know, they'll simply just use their assessor-provided systems with the notion that, well, we need to get all the stuff in there anyway, so we'll just use their system, you know, type of a thing. So it's kind of a mixed bag would be a good way to go about putting it. Sounds that way now you like to say that an organization that an organization needs to own their own data What do you mean by that? And why is it important? Well, you know, you've got these folks that, you know, that do use their assessor systems, right? And the downside of that is that, you know, it's on the organization to make their own program efficient, effective, work for them, you know, things along those lines.And, you know, the reality is that, you know, depending on various circumstances, things change over time, you know, you may have, you may have, you know, there was a particular firm that you were leveraging and a particular person at that firm that you used, and they moved on, they retired, they got promoted, you know, I've seen it all. They got bought out, they went out of business, you know, things along those lines, maybe the relationship with whoever is your currently assigned point person this year isn't as good as they were in years gone by. It could be the same person they've just changed. It could be that you've had some type of personnel shift, you know, things along those lines. You know, one of the things that we'll see a fair amount is, you know, organizations that are basically getting bought out, right, and organizations getting scooped up and folded into another gigantic barhemoth, you know, type of thing. And so the relationship you used to have and the pricing you used to have isn't the same as it used to be. So, you know, the reality is that things change, you know, all over the board. And so, you know, when you've got these modifications to, you know, to the players that are involved in your compliance program, you know, overall, then, you know, if your systems, quote, unquote, if your, quote, unquote, systems were dependent on, you know, this other third party and now something's happened with said third party, well, now what are you left with? You know, you're not left with anything. So, you know, it's part of the reason why, you know, I say that, you know, the organization subject to compliance at the end of the day, you know, it's on them to, you know, have the repository for their own information, for their own data, so they, you know, got it in a way that works for them. That's the most important, you know, element for, you know, for these companies. They need to be able to kind of depend on having their own way of doing things and then, you know, figuring out a way to interface with, you know, with the various third parties that they've got to go and interact with.
-
189
The Holiday Season is Putting Hotels at Risk - Episode 195
The CU Guys dive into the heightened risks hotels face during the holiday season. They discuss the importance of maintaining cybersecurity vigilance amidst increased traffic and seasonal hiring. The conversation covers best practices for background checks, training, and physical security, emphasizing the need for diligence to prevent data breaches. Tune in to learn how to protect your organization during the busiest time of the year.Episode Transcript:Now, you know, one thing I wanted to talk about is our listeners, and we'd love to hear from them. And what I mean by that is we'd love to know, if you're listening to this, we'd love to know your feedback and input on topics that you'd like to hear about or folks that you'd think we'd enjoy having on the show, and we'd love it if you would send those inquiries to complianceunfiltered@total compliancetracking.com. Yeah, I mean, honestly, even if they've got, hey, I heard this like really, really, really funky story or whatever, you know, and anything, anything, anything that folks want to hear about, they'd be, it'd be great to kind of hear what their interests are and, and we'll be happy to, we'll be happy to oblige. No doubt. Now, speaking of the holiday season, Adam, we're going to jump right in because the holiday season is putting hotels at risk.Tell us more, Adam. Why does this time of year heighten the risk for hotels? I mean, we're right in the, you know, in the thick of the holiday season, you know, between Thanksgiving and Christmas and New Year and all that fun stuff. So, you know, we've got, it's an interesting time when, you know, there's a lot of hotels that are, you know, that have a lot more traffic than they would normally. And, you know, staff are, you know, running all over the place trying to make sure they're taking care of guest needs, you know, etc.But, you know, keep in mind that that means it's also peak season for, you know, cyber attackers and bad actors to be able to take advantage, you know, of it. I mean, they, you know, they know that now is the best time to, you know, gain access to the sensitive data because everybody's, you know, run around, distracted and all that fun stuff. So, you know, it's not if you're going to suffer an attack. It's really about more about when and how. So, you know, you don't want, as an operator of one of these types of establishments, you definitely don't want to fall victim to it and find out in the wrong way that you were subject to some type of an attack. So, it's better to be safe than sorry. That's a good shout. Now, as you're dealing with kind of an influx of new folks in an organization, right? So like seasonal hiring, how does seasonal hiring impact background checks? Well, I mean, the biggest thing is, is that, um, is for the organizations don't, don't cut corners, you know, if you've got to bring in some additional staff or, you know, for seasonal hiring, et cetera, that there's, there's certainly the possibility. Um, although I, um, you know, we'll call you, it'd be pretty ballsy to pretty ballsy to go give this one a whirl, but, you know, if you're not going to have any idea, if you don't run your background checks, so, um, could be bad actors come, you know, that are, that are coming through, uh, you know, with the seasonal hiring push, um, you know, it, uh, it may very well be, it's someone that just has a, uh, a pass that doesn't line up with the rules, regulation guidelines for your organization, but you're not going to have any idea if you're not running the, running the background checks.Um, even though you have to fill up staffing needs quickly, you know, et cetera, you know, it's not, you don't want to do it at the cost of possibly running into an issue, you know, make sure that you're maintaining your due diligence, forming thorough background checks on everybody that, you know, is going to, uh, is going to run into the hiring line.
-
188
Central Logging Sanity Checks - Episode 194
The CU Guys dive into the critical topic of central logging sanity checks. They explore the common pitfalls organizations face when they set up central logging systems and then leave them on autopilot. Adam emphasizes the importance of regular sanity checks to ensure that logging systems are functioning as expected and highlights the risks of assuming everything is working perfectly. The discussion also covers the need for compliance professionals to validate assumptions, spot-check logs, and ensure that alerts are being properly handled. Tune in to learn how to maintain a robust compliance program that truly supports organizational security.Episode Transcript:Today, we're going to talk about, you know, another central theme here, not just a central member to a band, but central logging, specifically central logging sanity checks. So a lot of companies that have mature compliance programs set up their central logging and then kind of put it on autopilot. What are the downsides there, Adam? Well, I mean, I've been for a long time, a huge fan of trust, but verify. And, you know, when the, when the companies go in and, and kind of set up their, their central logging, you know, they, they really do just kind of, okay, we're done, you know, we're done, we've, we've established all the things, you know, we've done all the checks and we've set up the system and we have all the right processes and, you know, we, the, the reviews are happening and alerts are flying and, you know, so then they just, you know, move into this mode where they just literally let her roll and, you know, and then don't tend to go back to it, you know, for, you know, for a recheck or a sanity check or, or whatnot. They just go into the guiding assumption that everything's good because it's up and it's, nothing's gone boom and, you know, blah, blah, blah.So, you know, the, the, the most important part for, for these organizations is that they, they go back in and, you know, double check, you know, is, is what I think happening, is it actually happening? You know, but, you know, they got, they got to go back in and, and just do a sanity check on, you know, on things. So, you know, that's kind of the, the, the driving force here with the, with this particular topic. Sure. Now with that in mind, what are some of the concerns that compliance professionals should be focusing on?Well, I mean, first and foremost, you know, is everything that I think is logging actually logging, you know, is it are things that I set up to, to, you know, to log, are they still logging? Did something go off the rails? Um, it's really, really easy, uh, depending on the system and the, and the structure that's set up, what checks and things that they put in place, it's really easy to, I don't know, I'm just gonna make a number up. So let's just pretend, you know, out of the gate, there were a hundred different things that were, you know, that were sending stuff to central logging. Well, you know, fast forward a couple of months or in a lot of cases, a couple of years, um, you know, the, uh, are the things that we, uh, are those hundred things still, still doing what they're doing?I mean, you know, there's, there's all sorts of possibilities for something going wrong. You know, you've got, you know, updates or patches that, you know, may go ahead and interfere with the, with the capability for those devices to push their logs. I mean, it could be something as simple as, you know, somebody was messing with a firewall rule to try to do some troubleshooting and, you know, lock down some ports so they could get some things isolated, et cetera. And then forgot to put every, put Humpty Dumpty back together, you know, back together again and blah. And in the process, you know, block the, you know, the outbound logging, you know, capability from, you know, fill in the blank device, that type of thing.
-
187
Episode 193 - Happy Thanksgiving From Compliance Unfiltered
In this heartfelt episode of "Compliance Unfiltered," as the TCT Guys reflect on their journey with TCT, sharing personal stories of growth, challenges, and gratitude. Adam and Todd delve into the evolution of TCT, the invaluable input from clients, and the strong relationships built over the years. Join them as they discuss the importance of client feedback in shaping the organization's offerings and celebrate the dedicated team that makes it all possible. Tune in for an inspiring conversation about making compliance management a little less daunting and a lot more rewarding.
-
186
Episode 192 - Managing Multiple Certifications Using Custom Requests Lists
In this episode of "Compliance Unfiltered," the CU Guys dive into the complexities of managing multiple compliance certifications and custom request lists. They explore the challenges faced by organizations of all sizes, from small businesses to international giants, in navigating the ever-evolving compliance landscape. With insights into the common pitfalls and practical advice on streamlining processes, this episode is a must-listen for anyone involved in compliance management. Tune in to discover how to make your compliance journey less painful and more efficient.
-
185
Episode 191 - Holidays Bring Increased Cyber Threats to Retailers
In this episode of Compliance Unfiltered, The CU Guys dive into the challenges and strategies for retailers as they gear up for the holiday season. With cyber threats on the rise, particularly AI-driven attacks, the duo discusses the importance of proactive measures, employee training, and maintaining PCI compliance. They also explore the impact of seasonal hiring and the need for vigilance in protecting sensitive data. Tune in to learn how retailers can navigate the bustling holiday period while safeguarding their operations.
-
184
Episode 190 - Vendor B.S. in the Marketplace
On this week's episode of Compliance Unfiltered, The CU guys get candid and take a dive into the world of vendor relationships and the challenges faced in the marketplace. Adam shares his personal journey from working with "boneheads" to founding his own company, emphasizing the importance of genuine customer service and the pitfalls of AI hype. With a mix of humor and insight, they explore the disconnect between vendors and clients, offering a refreshing perspective on how businesses can truly serve their customers. Tune in for an unfiltered discussion that promises to be both enlightening and entertaining!
-
183
Episode 189 - Taming HIPAA Compliance For Hospital Systems
On this Episode of Compliance Unfiltered, the CU Guys delve into the complexities of HIPAA compliance for hospital systems. Adam discusses the dual nature of hospital compliance, highlighting both the advantages of early adoption and the challenges posed by the complexity of hospital systems. The conversation covers the intricacies of managing multiple compliance standards, the inefficiencies and costs associated with manual compliance processes, and the importance of maintaining control over compliance data. Adam emphasizes the need for hospital systems to regularly update their compliance controls to align with current technologies and reduce risks. All this, and more, on this week's Compliance Unfiltered!
-
182
Episode 188 - PCI Europe Community Meeting Recap
On this episode of Compliance Unfiltered, The CU Guys dive into their recent experiences at the PCI European Community Meeting in Amsterdam. From the city's impressive public transportation to the vibrant conference atmosphere, they share insights and anecdotes that highlight the unique charm of Amsterdam. Discover the excitement around TCT's latest technology, EasyCert, and how it resonated with attendees. Whether it's the eclectic mix of conversations or the delightful culinary adventures, this episode captures the essence of a memorable trip. Tune in for a blend of professional insights and personal stories that make for an engaging listen.
-
181
Episode 187 - Inventory Insights: Elevating Your Compliance Game
On this episode of Compliance Unfiltered, the CU Guys dive into the critical role of inventory management within large-scale engagements. They explore why inventory is central to security and compliance programs, share insights on integrating inventory into daily operations, and discuss common pitfalls organizations face. With Adam's practical tips and real-world examples, this episode is a must-listen for anyone looking to enhance their compliance strategies. Special thanks to listener Heidi for suggesting this topic! Tune in and discover how to make inventory a core element of your compliance DNA, on this week;'s Compliance Unfiltered!
-
180
Episode 186 - Introducing EZ Cert!
On this week's episode of Compliance Unfiltered, The CU Guys discuss the launch of EZ Cert, a new feature in the TCT Portal, designed to simplify compliance tasks for end users. Adam explains how EZ Cert streamlines the interface, making it more accessible and efficient for users who only occasionally interact with the system. The conversation highlights the business value of EZ Cert, emphasizing its ability to reduce bottlenecks and improve the efficiency of compliance engagements. The episode also touches on the benefits of EZ Cert for assessors. All this and more on this week's Compliance Unfiltered.
-
179
Episode 185 - We're Back From Ft. Worth! PCI North American Community Meeting Wrap Up
On this week's episode of Compliance Unfiltered, the CU Guys dive into their enriching experience at the PCI North American Community Meeting in Fort Worth, Texas. Discover how the conference exceeded expectations with improved organization and engaging interactions, and learn about the exciting new features like EasyCert that were unveiled. From exploring the immaculate public transportation to savoring local culinary delights, they share personal anecdotes and insights. Whether you're a compliance professional or just curious, this episode offers a unique glimpse into the vibrant world of PCI compliance. All on this week's Compliance Unfiltered.
-
178
Episode 184 - Streamlining Complex Compliance Engagements with Environment Splitting
On this episode, The CU Crew delve into the innovative approach of environment splitting to streamline compliance processes. Discover how this strategy not only enhances efficiency but also ensures adherence to regulatory standards. Join us as we explore real-world applications and expert insights that reveal the transformative power of environment splitting in today's compliance landscape. All this and more on this week's Compliance Unfiltered!
-
177
Episode 183 - The Perils of Report Writing for Assessors and How to Overcome Them
On this episode of Compliance Unfiltered, the CU Guys dive into the intricate world of report writing for compliance assessors. Discover why this seemingly straightforward task is fraught with challenges, from the complexities of manual processes to the orchestration required for quality assurance. Learn how the TCT portal is revolutionizing the way assessors handle report writing, saving valuable time and enhancing efficiency. Whether you're a seasoned assessor or new to the field, this episode offers insights into overcoming the hurdles of report writing and maximizing your ROI. Tune in to explore how technology is making compliance management more manageable and effective, all on this week's Compliance Unfiltered!
-
176
Episode 182 - PCI North American Community Meeting - Will You Be There?
On this week's insightful episode of Compliance Unfiltered, the CU guys delve into the 2025 PCI North American Community Meeting, happening from September 16th to 18th in Fort Worth, Texas. Adam shares why you should join TCT in attending, for the latest updates in compliance management, connect with industry experts, and explore innovative solutions that make compliance life easier. Whether you're a QSA, a compliance professional, or part of an organization serving compliant customers, this event offers something for everyone. Tune in to learn how to maximize your experience at this must-attend event on this week's Compliance Unfiltered!
-
175
Episode 181 - Why a Strong Stance on Security and Compliance is a Business Advantage for Manufacturers
On this episode of Compliance Unfiltered, The CU guys delve into the critical role of cybersecurity and compliance in the manufacturing sector. As technology advances, the industry faces increasing threats and regulatory challenges. Join us as we explore how manufacturers can safeguard their operations, protect sensitive data, and ensure compliance with ever-evolving standards. Discover expert insights and practical strategies to fortify your manufacturing processes against cyber threats. Learn why cybersecurity is not just an IT issue but a vital component of modern manufacturing success, on this week's Compliance Unfiltered.
-
174
Episode 179 - Interview with Tom Fox of the Compliance Podcast Network REPOST***
*** There was some audio issues with the initial post of this interview, that have now have been corrected. (Thanks Paul!)On this episode of Compliance Unfiltered, the CU Guys are pleased to be joined by Tom Fox from the Compliance Podcast Network to delve into the intricate challenges of implementing compliance programs. They explore the common misconceptions at the executive level, the critical role of internal controls, and the necessity of integrating compliance into business operations. Tom shares his journey from law to becoming a compliance evangelist, emphasizing the importance of ethical business practices in combating global issues like bribery and corruption. All these insights and more on this week's Compliance Unfiltered!Connect with Tom and explore all the great shows on the Compliance Podcast Network, here: www.compliancepodcastnetwork.net
-
173
Episode 180 - No AI Policy? Your Company is Flirting with Disaster
On this episode of Compliance Unfiltered, the CU guys delve into the critical need for AI policies within organizations. As AI technology rapidly evolves, many companies find themselves unprepared, risking exposure of sensitive data through platforms like ChatGPT. Adam emphasizes the urgency of implementing AI policies to protect against potential data breaches and compliance issues. Discover why having a robust AI policy is not just a best practice but a necessity in today's digital landscape. All this, and more, on this episode of Compliance Unfiltered.
-
172
Episode 178 - Q3 Security Insights 2025
On this episode of Compliance Unfiltered, it is that time again! You guessed it, time for all of the spicy security stories that were, and the critical security reminders for, the third quarter of 2025. Curious about learning some tips on how to impress your assessor? Wondering how you can maximize your knowledge of space, to minimize the struggles associated with your engagements? Then you're not going to want to miss this episode of Compliance Unfiltered!
-
171
Episode 177 - 7 Critical Actions to Ensure I.T. and Cybersecurity Success
On this episode of Compliance Unfiltered, Adam and Todd have a heart to heart on what makes a successful operation tick, from a cybersecurity and I.T. perspective. Curious about the specialized expertise required for success? Wondering where Trust but Verify fits in? Worried about your upcoming assessment? Well, you're in luck! Answers on all these topics and more, on this week's Compliance Unfiltered!
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less
HOSTED BY
Total Compliance Tracking
CATEGORIES
Loading similar podcasts...