The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls can pass every audit yet still fail to stop modern attacks, and why continuous validation is replacing point-in-time evidence. Discover how organizations should test resilience through penetration testing, red teaming, tabletop exercises, backup recovery, and control effectiveness—not just documentation. If you think "audit passed" equals "risk reduced," this episode will change the way you measure security forever.


Episode Transcript:

Today’s topic, Adam, is one that I feel like too many folks are familiar with, and that is the company still got breached despite all of your controls working.

So what happens when every box is checked, every control passes the audit, and the attacker still gets in?

Adam Goslin:
Controls can operate as designed, but still end up failing to protect the organization.

Compliance is measuring whether or not a control exists and if that control was executed. Security measures whether that control actually reduced the risk.

One of the earlier euphemisms that you would hear a lot is compliance doesn’t equal security.

What those people were getting at is that just because I have checked this box that says this thing’s in place doesn’t mean I’m actually secure.

The control working doesn’t necessarily mean the organization’s protected.

We need to make a shift from control execution to control effectiveness so that we can gain risk mitigation.

There’s also the possibility, and this happens to fewer of those organizations, but there’s a possibility that you’ve got a zero day out there.

But even in the case of a zero day, you’ve got a myriad of other controls that ought to be effective, where those detection mechanisms still have the ability to identify, “Hey, Houston, you got a problem.”

Whether it’s identifying control bypass through monitoring of central logging, unusual user activity with behavioral analytics, file integrity monitoring if you’re seeing files changing within the environment, failed attempts from inside the network as attackers are trying this, trying that, and trying the other thing.

There’s a reason why, even with zero days, it ends up seeing the light of day.

It’s about mitigating the amount of time between, “Houston, we got a problem,” and knowing that you have a problem.

Todd Coshow:
What’s the difference between a control operating as designed and a control actually being effective?

Adam Goslin:
When it’s operating, you’re checking the box. This thing happened.

But when a control is effective, it means that the risk was meaningfully reduced.

You can have every single person in your organization going and attending security awareness training and seeing their quarterly security reminders and the piece of paper that’s taped up on the inside of the bathroom door, and yet employees still fall for phishing attempts.

Maybe you’ve got a situation where an organization went in, ran their vuln scans, but they left vulnerabilities unpatched for a period of time.

There’s gonna be some period of time between recognition that I have a vulnerability and getting it cured, and depending on how long of a span that is.

It doesn’t necessarily have to be just critical vulnerability. A lot of people will obviously focus in on critical vulnerabilities.

But what they seem to miss in their vulnerability management is that oftentimes I can take two or three medium-level vulnerabilities and conjoin them to create something that’s far more impactful.


Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(234)

The Day Your Compliance Champion Leaves - Episode 234

The Day Your Compliance Champion Leaves - Episode 234

What happens when your compliance champion suddenly disappears? Todd Coshow and Adam Goslin explore the hidden risks of building a compliance program around one go-to person. From tribal knowledge and...

24 Sep 30min

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Aug 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Aug 33min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Jul 21min

Populært innen Teknologi

teknisk-sett
tomprat-med-gunnar-tjomlid
lydartikler-fra-aftenposten
energi-og-klima
elektropodden
rss-ki-praten
hans-petter-og-co
nasjonal-sikkerhetsmyndighet-nsm
shifter
smart-forklart
rss-alt-som-gar-pa-strom
rss-ai-forklart
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
fornybaren
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis