Compliance Unfiltered With Adam Goslin

Total Compliance Tracking

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

  1. Jul 16

    Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225

    On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status. Episode Tracking: Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet. That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say. Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it? Adam Goslin:If we’re talking about my engagement, how long would it take? Seconds. But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit. This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet. I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.” All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch. “Hold on a second. I think it’s over here.” They go and look over there. “Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.” No, it’s not there either. “You know what? Evan knows exactly where it’s at. Give me one second.” Ring, ring, ring, ring. His phone went to voicemail. “Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?” It was an effing nightmare. A lot of people think that they know where things are until they’re under the gun and have to prove it. If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game. It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it. It really degrades their sense that the people they’re talking to actually have their act together. Todd Coshow:I can definitely appreciate that. Spreadsheets are still everywhere in compliance, but why are they such a problem? Adam Goslin:Spreadsheets weren’t designed to manage living, breathing systems. We’ve talked before about the levels of complexity that exist within these things. A spreadsheet is static, and compliance isn’t. There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against. You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states. If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane. The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.

  2. Jul 9

    Q3 Security Insights 2026 - Episode 224

    In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions. The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds. If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you. Episode Transcript: It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026. As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy. As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly. Also, feel free to reach out to us at complianceunfiltered@totalcompliancetracking.com. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us. Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more. Adam Goslin:In the grand scheme of things, it is a capability that some organizations struggle with. Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no? When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request. There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof. This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy. It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly. Certainly, safeguarding internal reports is one arena we’re going to get into. As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports. There’s a myriad of information within them that external entities don’t have any right or reason to see. In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution. The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those. Only issuing your externally appropriate summary of your security posture to third parties is appropriate. The next arena I want to touch on is a centralized distribution channel. One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.

  3. Jul 2

    Building AI Agents Securely - Episode 223

    AI agents are driving efficiency, but also introducing serious, often unseen security risks. As adoption accelerates, unvetted access, prompt injection, and poorly controlled environments can expose sensitive data and disrupt operations. This episode of Compliance Unfiltered breaks down the key threats and shows how to mitigate them using proven principles like least privilege, input validation, and isolated execution. Learn how to secure AI deployments and turn a growing risk into a resilient advantage. Episode Transcript: You’ve been talking about the AI zombie walk for some period of time now. What perils are folks walking into with AI agents? Adam Goslin:We’ve got the democratization of agentic AI on the march. Anybody can get the latest tools and create these incredible AI agents that can do almost anything you can imagine. It’s part of the main reason why the agentic AI move can be a substantive risk for the organization as well. One of the big problems they’re having right now is that, while security and compliance folks understand the risks of AI, there are a ton of frontline users that are just clicking buttons and building tools and making things automated and better. There isn’t, in a lot of cases, any thought to the security implications of what they’re in the process of doing. Thinking about security isn’t an element of day-by-day workflow, and that’s where this notion of agentic AI comes in riskiest, if you will. Leveraging platforms for building these AI agents without a security background, I’d liken it to giving a three-year-old an arc welder. It might be able to figure out how to turn it on, but can you imagine the untold damage that they could do with it? You put a powerful AI tool in the hands of people that don’t know about protecting data, layers of security, and how to appropriately restrict access. They’re not going to know how to use it safely. There are a lot of considerations when it comes down to building AI agents in a secure fashion. But most of it honestly comes down to security principles. It’s possible for employees to build those safely, but there needs to be that marrying of the security and compliance-style mindset in conjunction with what’s going on. Todd Coshow:What type of efficiency risks are folks running into? Adam Goslin:AI agents are often used for personal efficiency and internal workplace functions. To give some examples: consolidating, summarizing, and filtering across multiple email accounts; automated execution of auto-replies; analyzing workflows and calendars for identifying efficiencies; gathering up data; and preparing written summaries of client projects. These things may seem harmless, but just consider the risk of letting the AI agent loose on your calendar. How much data did you just expose as a result of clicking, “Sure, you’re going to have full access to my calendar”? The agent has access to your client lists, client contacts, emails, signatures, phone numbers, and cell phone numbers. All of that starts to come into play as you’re granting blind access to Office 365, as an example. Maybe that extends to OneDrive and SharePoint. Maybe, depending on the user and their access levels, they could be granting a ton of access. Even things that seem innocent, such as tracking birthdays or anniversaries, could similarly produce greater levels of exposure than you were even considering. The company needs to consider what is the data and information that’s exposed to the AI engine, how do we want to use it, and whether or not that data is secluded from other things. If you’re moving from a free version to a paid version of AI, your users may still be jammed into some gigantic public pool of data storage. Even when the AI vendors are claiming, “We don’t hand your data over to public AI models,” you need to look closely at what they are doing, such as utilizing the information that’s gleaned from the individual users when it comes to training their engines.

  4. Jun 25

    AI-Powered Attacks: Is Your Compliance Program Already Obsolete? - Episode 222

    In an era of evolving AI-driven cyberattacks, traditional compliance programs are falling dangerously behind. Static controls create a false sense of security while attackers leverage AI to move faster, exploit vulnerabilities, and bypass defenses. On this week's Compliance Unfiltered, Todd Coshow and compliance expert Adam Goslin explore how AI is reshaping threats, why checkbox compliance is obsolete, and how organizations must shift to continuous, real-time assurance to stay resilient, protect data, and keep pace with modern adversaries. Episode Transcript: Today, we’re going to talk about the nefarious. That’s right, the artificially nefarious. In fact, AI-powered attacks. Is your compliance program already obsolete? But before we do so, Adam, as always, we want to say a special thank you to listeners of this podcast. Tell your compliance friends, if they’re not listening to us already, let them know that it’s something that you enjoy doing, and they might as well. Also, if you have any questions, topics, or general compliments you want to send our way, please do so at ComplianceUnfiltered@TotalComplianceTracking.com. As I mentioned, Adam, AI-powered attacks are something that’s on everybody’s mind these days. I guess the question is: if AI is fundamentally changing how attacks are executed—faster, smarter, more adaptive—are most compliance programs already outdated? Adam Goslin:In a lot of cases, yeah. It’s not because of some type of poor design, but a lot of the programs that exist now were founded in advance of the advent of AI, built in a different time, if you will. A lot of the compliance programs have certain assumptions baked in: stability, known systems, predictive behavior, human-driven threats. AI is really putting a gaping hole in that assumption, if you will. You’ve got attacks these days that can adapt midstream. They can mimic a legitimate user and scale with a speed that wasn’t possible before. Compliance is still, in many cases, measuring control effectiveness and measuring controls being in place at fixed points in time. It isn’t necessarily that the compliance is wrong, but it’s operating on a timeline that’s not matching up to today’s newfangled AI-world reality. Todd Coshow:Fair enough. Where do you see the biggest disconnect today between what compliance frameworks validate and what’s actually happening inside an environment? Adam Goslin:One of the biggest gaps is between existence and effectiveness. Frameworks are good at confirming controls exist. There is a policy. Here it is. There’s a process, and there’s evidence. But they’re not consistently validating that the control is working under real-world conditions, and quite frankly, the real world is changing under our feet, if you will, especially when it comes to these AI-driven attacks. You’ve got organizations that hold up their piece of paper and say, “Hey, big green checkbox, we’re compliant.” But the controls, in some cases, are bypassed shortly after the validation that, at that point in time, they were working. In many cases, the controls aren’t getting tested against how attack patterns are really behaving in the real world these days. Todd Coshow:You’ve talked about organizations having a false sense of their own state of compliance. How does AI make that problem even worse? Adam Goslin:AI accelerates the drift and buries it, if you will. Controls have a tendency to degrade over time. Access reviews get stale. Monitoring gets noisy and ignored. That type of stuff was already happening. But AI allows for the exploit of those gaps faster than many organizations are set up to detect them. Now you’re sitting here with a situation where, on the one side, I’m technically compliant because of my last audit. But operationally, I’m not compliant because the environment has modified or changed, and the attackers are jumping on those gaps immediately.

  5. Jun 18

    Compliance Theater: Are You Actually Secure or Just Checking Boxes? - Episode 221

    Most organizations are just performing compliance – ticking boxes, not building real security. What happens when the curtain is pulled back on these check-the-box programs? You might be under the illusion of safety, but in reality, you're exposing your organization to serious risks.In this eye-opening episode, Todd Coshow and cybersecurity expert Adam Goslin reveal how many companies operate in “compliance theater,” creating an illusion of security to meet audit deadlines without safeguarding their environment. They unpack the stark difference between being audit-ready and genuinely secure, exposing how superficial policies, outdated evidence, and a mindset focused on passing assessments put your company at risk. Episode Transcript: The topic for today really boils down to whether or not folks out there are actually secure or if they’re just checking boxes. So let’s start with the tough one. Are organizations actually secure or just really good at checking the bare minimum boxes before the auditor shows up? Adam Goslin:If we’re being honest about it, most of them are performing. There are too many organizations out there to count that their view of navigating their security and compliance waters is doing the least preparation that’s humanly possible in advance of their audit or their assessment. They’re just trying to get through the process. In a lot of cases, it’s like a mantra: “We have to check. We’re being forced to do this, and we’re doing as little as we can just so that we can achieve the little piece of paper that says we’re secure.” They know what they need to show to the assessor, when to show it, and how to package it. But there’s a stark difference between organizations that are actually operationally secure, really taking this stuff seriously, etc. It also doesn’t provide any proof that everything’s going to be cooking with gas come some random Tuesday in March. Security isn’t a moment-in-time thing, where unfortunately most of the assessments and audits are. Todd Coshow:When we say compliance theater, what does that actually mean in practice? Where do you see organizations just going through the motions instead of building real security? Adam Goslin:Compliance theater is when your program’s built to prove something instead of actually demonstrating or doing something. That’s where you see compliance theater coming into play. Maybe it rears its head with screenshots that are cobbled together the day before the assessment. Maybe it’s policies that get refreshed once a year and, other than that, collect dust somewhere. It’s controls that exist but aren’t truly implemented or operationalized. Probably one of the biggest signs for an organization is when there’s this crescendo of compliance effort that happens with their annual assessment, and then all of a sudden, the second the auditor leaves, everybody’s wiping the sweat off their brow: “Thank God we made it through that one.” Everybody goes back to their day jobs and waits another nine or ten months before they have to prep for their next cycle. That’s the epitome of the compliance theater arena. Todd Coshow:Talking about the audit-versus-reality gap, how big is the gap between passing the audit, like PCI, SOC 2, ISO, and what’s actually happening on a day-to-day basis inside of an environment? Adam Goslin:There’s a bigger gap than folks want to admit. If you’re passing an audit or an assessment, that means that you’ve met the minimum bar at a specific point in time. But it doesn’t necessarily mean that the controls are being consistently applied across the environment throughout the compliance cycle. It doesn’t mean that you’re keeping your evidence fresh. It doesn’t mean that the team may even understand what they have or what they do. All I know is that for this particular requirement, I had to go into this interface, click these buttons, grab this information, this screenshot, and poof.

  6. Jun 11

    Audit Fatigue and How to Effectively Navigate It - Episode 220

    Caught in a cycle of audit requests, evidence chaos, and burnout? Discover a way out in this episode. Compliance Expert Adam Goslin joins Todd Coshow to reveal the hidden causes of audit fatigue and share strategies to lighten your load. Learn why audit fatigue is intensifying and how fragmented compliance efforts fuel chaos. Uncover tactics to centralize evidence, reduce duplication, and implement improvements. Tune in to reclaim control over your compliance universe. Episode Transcript: So today we’re going to talk about audit fatigue. But before we do, I want to, as always, thank all the fine listeners to this podcast. Let you know that we greatly appreciate your time and your input. With that in mind, if you have a topic, a comment, a favorite recipe, or something you want to share, please do reach out to us at complianceunfiltered@totalcompliancetracking.com. We’d love to hear what you have to say. Adam, audit fatigue. Talk to me about why it’s getting worse and what to do about it. Let’s be honest. Compliance teams of companies undergoing compliance everywhere are exhausted. Audit fatigue feels like it is at an all-time high right now. Why does it seem like this problem is getting worse year over year instead of better? Adam Goslin:It’s a real issue. One would think that with better tooling and a program going into its year two, year three, etc., things would start getting easier, but it almost feels like the opposite’s happening for a lot of organizations. Honestly, there’s been very few organizations that I’ve worked with over the years where everything just stayed static. You’ve got growing scope. You’ve got new requests for additional frameworks that need to get folded in. Expectations of assessors continue to go up, not down. So, in a lot of cases, instead of going through just one audit, there are teams that feel like they’re on this never-ending circular bicycle track, where it’s a continuous, never-ending cycle of audits, evidence requests, and follow-ups. You get done with one, another one pops up. I feel like we’re playing assessment whack-a-mole. That would be a good way to put it. Todd Coshow:That’s pretty fair. But the question is, what’s really driving that? Is it just more frameworks like PCI and SOC or ISO, or is there something deeper going on? Adam Goslin:That’s a big part of it. The bigger issue that underlies the real problem is fragmentation. You’ve got a lot of organizations that are managing compliance in silos. There’s different frameworks, different teams, different tools, and at the end of the day, all of that leads to duplicated effort. You’re proving out the same control in five different ways to five different audiences. You got spreadsheets. You got shared drives. You’ve got crap spread all over Hell’s Half Acre. I’ve talked about that ad nauseam in the past, where you’ve got stuff coming at you through email, text messages, meetings, hallway conversations, people swinging by your desk. For whatever reason, I had somebody back in the day printing their effing evidence out. They printed it out on the printer, walked by, and dropped it on my desk. You’ve got network drives. You’ve got SharePoints. You’ve got the assessor systems. It’s an effing nightmare. There are a lot of organizations that end up with different assessors through this process. Let’s say you got one organization. They start out and get somebody to evaluate them against HIPAA. Then all of a sudden, the business says, “Wait a second. We’ve got to throw PCI into the mix.” Now, when they have to go to PCI, they go back to their HIPAA assessor: “Do you guys do PCI?” Nope. Then we’ll go look and find a PCI assessor. So they throw a PCI assessor into the mix. Now I got two.

  7. Jun 4

    Identity is the New Perimeter (Zero Trust) - Episode 219

    On this week's Compliance Unfiltered, discover why identity is the new perimeter in cybersecurity. This episode reveals how zero trust principles can protect your systems by continuously verifying user identity and behavior. Learn about the risks of traditional defenses, the evolution of compliance standards, and practical tactics for implementing context-aware verification. Perfect for IT leaders and security professionals ready to strengthen defenses and build a trustworthy digital environment. Listen now to stay ahead of threats. Episode Transcript: Today, Adam, we are going to talk about identity as the new perimeter. That’s right, folks. Zero trust is the topic for today. Now, Adam, if someone logs into your system with the right username and password, do you automatically trust them? Adam Goslin:That’s the issue. Most organizations still do, but today, credentials are one of the easy things for attackers to steal or buy. Just having somebody with a valid login doesn’t necessarily mean that it’s a legitimate user. The bad guys are taking measures to gather up this information in detail, and they’re not necessarily hacking the system, but they’re just going ahead and logging in, if you will. Todd Coshow:Sure. We’ve heard for years that the network perimeter is dying. Now the real question is, is it officially dead? Adam Goslin:There’s a couple of different ways to look at it. In a practical sense, yeah. We’ve got cloud. We’ve got software as a service. We’ve got folks doing remote work. Not only just the general sense of remote work, but also, depending on the roles of the individuals involved, part of their job is literally being on the road all the time. There’s not a notion in particular of what is inside, just because users, devices, data are being interacted with across a broad scope of geographic spread and all that fun stuff. It’s certainly getting more exciting than getting less, if you will. Todd Coshow:Fair enough. I guess the next logical question then is: what replaces it? Adam Goslin:Identity is now the perimeter. If you can control and identify the identities properly, then you’ve got the capability for securing the access regardless where the user is. One of the big elements here is, for a lot of organizations, and the ones that are in the security and compliance space have been used to this for a longer period of time, but you see more and more organizations mandating, requiring multiple factors of connectivity. That certainly has gone a long way to being able to make improvements. But part of the issues come in when, let’s say that you’ve got a username and a password that’s now been breached or shared amongst bad actors, coupled with attacks on multi-factor organizations, etc., it becomes an issue, if you will. Todd Coshow:Absolutely. How big of a problem is credential abuse in modern— Adam Goslin:It’s one of the biggest elements because the attackers have a cottage industry of scraping data and information from a wide variety of various breaches. This could be phishing that they’re doing, or from prior breaches, data and information that they’re pooling up on the dark web. The problem is that the bad guys are sharing a lot of information amongst themselves, which makes it more and more difficult for organizations to have a substantial trust factor in the identities that they’re allowing through the door. It makes things monumentally more complicated. Think about it. When you’ve got attackers that attacked this site, that site, the other site, and they’re pooling all this information, each of your users, individually, has probably been scraped up into several different data sets from various data breaches from the various vendors that they even use individually. We’ve talked about this before when we were talking about good password hygiene.

Ratings & Reviews

5
out of 5
2 Ratings

About

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

You Might Also Like