#44 - Karen Laughton on FedRAMP 20X, AI, and the Future of Compliance

EPISODE · Aug 12, 2025 · 51 MIN

#44 - Karen Laughton on FedRAMP 20X, AI, and the Future of Compliance

from The Paramify Podcast · host Paramify

In this episode of the Paramify Podcast, Karen Laughton, EVP of Advisory at Coalfire, joins Kenny Scott (CEO of Paramify) and Mike Schreiner to unpack the future of government cybersecurity and compliance modernization. From the hard realities of FedRAMP 20X to lessons learned from the early days of FSMA and CMMC confusion, this conversation pulls no punches. Karen shares how she broke into cybersecurity via HR (and a saltine-fueled CISSP exam), why automation without strategy won’t scale, and what it's going to take to make 20X work at moderate and high baselines. If you're curious where compliance, automation, AI, and public sector modernization are headed—you’ll want to tune in. ⏱️ Timestamps: 00:00 – "Dang, we need to modernize our government" — Karen's IRS nightmare becomes a metaphor for digital transformation. 02:44 – Meet Karen Laughton: Coalfire EVP, community leader, and accidental cyber exec. 03:35 – Saltines, pregnancy, and passing the CISSP: Karen’s origin story in cyber. 08:01 – AC-7 and the mouse jiggler: when coarse-grained controls meet real-world demos. 10:03 – FedRAMP in the early days: the “marathon in flip-flops” era of inconsistent TR feedback. 13:01 – The worst documentation nitpicks Karen’s ever seen (IP addresses and diagram chaos). 14:46 – FedRAMP then vs. now: why decentralization could hurt even as risk-focus improves. 17:28 – What scaling 20X to moderate and high will actually require. 20:03 – Are we solving the right problem with KSIs? Recapping Coalfire's “automation of arrested development” blog. 23:08 – Why automation isn’t a silver bullet (and why it still needs humans). 24:57 – 3PAOs aren't going anywhere — and that’s not just job security talk. 26:15 – Andrej Karpathy, robot soccer, and the early innings of AI assurance. 29:30 – Why agencies aren’t lining up to sponsor FedRAMP 20X. 31:08 – How Coalfire responded to 20X: culture, planning, and Compliance Essentials. 33:41 – Leveraging Paramify to accelerate automation where it makes sense. 36:42 – Politics, acquisitions, and why automation hits limits in complex orgs. 37:27 – DoD, CMMC, and 20X: where things stand and why there’s still confusion. 41:01 – The case for CMMC enclaves (and why most orgs want to isolate the mess). 42:00 – Mentorship, career pivots, and embracing “knowing nothing” as a superpower. 47:58 – Why questions make you smarter — and why cybersecurity people love answering them. 50:00 – Why cybersecurity never gets boring (and feels like a family reunion at every conference). 50:59 – Wrap-up & future part two tease. Learn more about Coalfire: https://coalfire.com/ Learn more about Karen Laughton: https://www.linkedin.com/in/karen-laughton-6484115/ Learn more about Paramify: https://www.paramify.com/ Learn more about Kenny: https://www.linkedin.com/in/kenny-g-scott/ Learn more about Mike: https://www.linkedin.com/in/mikecschreiner/

NOW PLAYING

#44 - Karen Laughton on FedRAMP 20X, AI, and the Future of Compliance

0:00 51:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

MG Show MG Show The MG Show, hosted by Jeffrey Pedersen and Shannon Townsend, is a leading alternative media platform dedicated to uncovering the truth behind today’s most pressing political issues. Launched in 2019, the show has grown exponentially, offering unfiltered insights, comprehensive research, and real-time analysis. With a commitment to independent journalism and factual integrity, the MG Show empowers its audience with knowledge and encourages active participation in the political discourse. The Game Radio Popolare Soldi, lavoro, avidità, disoccupazioni: il grande gioco dell’economia smontato ogni giorno da Raffaele Liguori. Photo Breakdown Scott Wyden Kivowitz Photo Breakdown is a podcast in which we explore the world of photography with a trusted guide, host Scott Wyden Kivowitz. His expertise and passion bring the industry to life as we explore the stories, trends, and ideas shaping it today. Join us as we dissect everything from incredible photographs and creative techniques to the latest gear releases and hot topics in the photography community.In each episode, we break down what’s happening behind the scenes - whether it’s making a powerful image, a candid discussion on industry trends, or a reflection on the tools and technology changing how we make photographs. You’ll get insights, expert opinions, and a fresh perspective on what’s top of mind for photographers right now.Anticipate short, engaging episodes brimming with ideas and inspiration. Be part of the conversation by sharing your thoughts, voice notes, and comments. Your participation is what makes our community vibrant and dynamic.It’s more than just photography - everyth The Last Outlaws Impact Studios at UTS In a History Lab season like no other, we're pulling on the threads of one of Australia's great misunderstood histories, moving beyond the myths to learn what the Aboriginal brothers Jimmy and Joe Governor faced in both life and death.Australia's budding Federation is the background setting to this remarkable story, that sees the Governor brothers tied to the inauguration of a 'new' nation and Australia's dark history of frontier violence, racial injustice and the global trade and defilement of Aboriginal ancestral remains. This Impact Studios production is a collaboration with the Governor family, UTS Faculty of Law and Jumbunna Institute for Indigenous Education and Research.The Last Outlaws teamKatherine Biber - UTS Law Professor and Chief InvestigatorAunty Loretta Parsley - Great-granddaughter of Jimmy Governor and the Governor Family Historian Leroy Parsons - Governor descendant, Narrator and Co-WriterKaitlyn Sawrey - Host, Writer and Senior ProducerFrank Lopez - Writer,
URL copied to clipboard!