Zero Signal

Conor Sherman

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out

  1. 2d ago

    Daniel Bardenstein: Why Third-Party Risk Is Broken

    Welcome back to Zero Signal! In this episode, hosts Conor Sherman and Stuart Mitchell sit down with Daniel Bardenstein, founder and CEO of Manifest Cyber, former Chief of Technology Strategy at CISA, and former cybersecurity lead for Operation Warp Speed. With open-weight models like GLM 5.2 rapidly challenging proprietary AI providers like ChatGPT and Claude on performance while offering up to 5x to 6x cost savings, Daniel unpacks why basic arithmetic is driving an enterprise shift back toward open-weight models. He breaks down the complex supply chain dynamics behind AI datasets, fine-tuning, and model dependencies, highlighting how untracked data inputs can quietly introduce massive legal, compliance, and security liabilities. The conversation addresses the ongoing breakdown of traditional Third-Party Risk Management (TPRM). Daniel explains why relying on static paper questionnaires, SOC 2 reports, and superficial web scans fails to capture non-deterministic AI risks or the hidden fourth- and fifth-party software dependencies lurking inside modern vendor products. To solve this, he advocates for treating AI as a subset of software and leveraging machine-readable AI Bills of Materials (AI BOMs) to automate inventory management, streamline license compliance, and protect pipelines against shadow AI created by developers using tools like Claude Code. Daniel Bardenstein is the founder and CEO of Manifest Cyber. He previously served as the Chief of Technology Strategy at the Cybersecurity and Infrastructure Security Agency (CISA), led cybersecurity for Operation Warp Speed, and helped architect national-level cross-sector Security Performance Goals. CISA Cross-Sector Cybersecurity Performance Goals: https://cisa.gov/cpgs CycloneDX SBOM/AIBOM Standard Specification: https://cyclonedx.org SPDX Software & AI Bill of Materials Standard: https://spdx.dev NIST Software Supply Chain Security Guidance: https://nist.gov/software-supply-chain OWASP Top 10 for Large Language Model Applications: https://owasp.org/www-project-top-10-for-large-language-model-applications LAION-5B Dataset Research Analysis (Stanford University): https://cyber.fsi.stanford.edu 00:00 Open-Weight Models & The Economics of GLM 5.2 04:15 The Shift from Proprietary APIs to Open-Weight Models 08:50 Mapping Supply Chain Risks in Datasets and Fine-Tuning 12:20 Software Supply Chain Models Applied to AI Inventory 18:10 Navigating Complex AI Model Licensing & Compliance 24:00 Shadow AI, Local Models, and "Vibe Coding" Developer Risks 33:00 The Failure of Traditional Third-Party Risk Management (TPRM) 40:30 Operationalizing AI Bills of Materials (AI BOMs) for Automation Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the GuestContinued Reading & ResourcesKey Topics & TimestampsMeet our Sponsors

  2. Jul 17

    Josh Woodruff: The Agentic Trust Framework

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Josh Woodruff, creator of the Agentic Trust Framework, co-chair of the CSA Zero Trust Working Group, and co-author of Agentic AI + Zero Trust. Josh wrote this definitive guide alongside John Kindervag, the industry pioneer who originally coined the term Zero Trust itself. Together, they bridge original Zero Trust fundamentals with the unpredictable nature of today's stochastic, probabilistic AI agents. Josh outlines an actionable operating model that treats AI agents as "digital colleagues," graduating their access through strict autonomy progression levels from Intern to Principal. Instead of getting stuck in pilot purgatory, Josh introduces five core questions—identity, behavior, segmentation, data governance, and rapid kill switches—to help security leaders build protective "roll cages" around their agentic systems, safely accelerating business transformation without sacrificing defense. Josh Woodruff is the creator of the Agentic Trust Framework, co-chair of the Cloud Security Alliance Zero Trust Working Group, and the founding chair of the CSAI Foundation. He is a prominent security strategist and co-author of Agentic AI + Zero Trust alongside John Kindervag. Agentic Trust Framework Official Site: https://agentictrustframework.ai Agentic Trust Framework (Open Spec, GitHub): https://github.com/massivescale-ai/agentic-trust-framework Agentic Trust Framework: Zero Trust for AI Agents (CSA Blog): https://cloudsecurityalliance.org/blog/agentic-trust-framework Agentic AI + Zero Trust: A Guide for Business Leaders: https://aws.amazon.com/blogs/enterprise-strategy/agentic-ai-zero-trust Zero Trust for AI Agents (Anthropic): https://anthropic.com/news/zero-trust-for-ai-agents A Look Back at Zero Trust (John Kindervag): https://forrester.com/blogs/zero-trust-never-trust-always-verify Securing the Agentic Control Plane (CSAI Foundation): https://csai.foundation/securing-the-agentic-control-plane 00:00 Grounding Zero Trust for Probabilistic AI Agents 04:15 The Stochastic Threat: Intent, Logic Loops, and Prompt Injection 07:55 The Framework Shift: Operational Models vs. Gated Threat Lists 10:15 Anchor Questions: Identity, Segmentation, Data, and Kill Switches 12:00 Autonomy Progressions: From Intern Status to Principal Control 14:30 Earning Privileges: The Five Dimensions of Agent Promotion 17:50 Intent-Based Leadership: Balancing Technical Competence with Autonomy 24:00 Constraints as Rocket Fuel: Tight Governance for Performing Agents 34:30 Pilot Purgatory & Lessons from a $300 Replicating Orchestrator Error Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal About the Guest:Continued Reading & Resources:Key Topics & Timestamps:Meet our Sponsors:

  3. Jul 10

    Andy Ellis: Why Cyber Vendors Pitch to the Wrong Person

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Andy Ellis, Akamai's first CISO, who led security operations there for more than 20 years while the platform grew to carry over 30% of global web traffic. A 2021 CISO Hall of Fame inductee and author of 1% Leadership, Andy draws from his decades of scale experience to explain how cybersecurity vendors can stop burning bridges with buyers and how security executives can thrive in a changing corporate landscape. In this conversation, Andy breaks down the core flaws of enterprise sales, revealing why most security vendors fail by treating every interaction as a transaction rather than practicing cultivation. He provides a tactical roadmap for how modern CISOs can become smarter buyers, protect their finite political capital, and transition from traditional control mentalities into strategic business drivers who privately collaborate with peers like the CMO and CRO to enable growth. Conor, Stu, and Andy also tackle the evolution of the executive role, detailing why the CISO function is splitting into two distinct paths: a sub-executive infrastructure position and a true chief technologist role. Andy shares his hard-earned wisdom on becoming a credible witness to corporate risk, managing the first 91 days in a new seat with intent, and building a professional environment modeled after a therapist's office to put stakeholders completely at ease. Continued Reading & Resources: How to CISO Framework & Content: https://howtociso.com Andy's First 91 Day Guide for CISOs: https://howtociso.com/91days 1% Leadership Official Page: https://1percentleadership.com Akamai Technical Scale Archives: https://akamai.com/blog/security/heartbleed-and-distributed-scale-defense DerbyCon Speaker Retrospectives: https://derbycon.com/talks/louisville-slugger-security-paradigms Gary Hayslip's Field CISO Guide: https://linkedin.com/in/garyhayslip/insights-on-the-field-ciso-shift About the Guest: Andy Ellis is an investor, advisor, 2021 CISO Hall of Fame inductee, and the former pioneering Chief Information Security Officer at Akamai Technologies, where he spent over two decades securing 30% of global web traffic. He is the author of 1% Leadership and the creator of the free industry resource How to CISO, which focuses on training the next generation of technological and operational business executives. Key Topics: 01:00 Cultivating Ripe Strawberries: Moving from Coercive Sales to Market Cultivation 05:30 The Vendor Rebuff Template: Protecting Entry-Level SDRs from Industry Abuse 09:55 The Field CISO Trap: Lending Your Gravitas to the Problem, Not a Sales Quota 14:45 The Pre-Pitch Mindset: Using Thought Leadership to Prime the Buyer's Mental Space 16:26 The Nine Buyer Beliefs: Market Urgency, Corporate Politics, and Platform Fit 19:25 Evolution of Seed to Series C Capital: Bespoke Sales vs. Scalable Rep Engines 22:15 The Duo Precedent: Using Cross-Vendor Endorsements to Gain True RSA Credibility 25:35 Stealing the Swag: Optimizing Steak Dinners for Existing Customer Retention 33:20 The CISO Therapist: Designing Your Physical and Remote Office Background to Lower Defenses 36:00 The Splitting Role: Differentiating Junior IT Directors from Strategic Chief Technologists 39:15 Private Boardroom Alignments: Educating the CMO and CRO Before Executive Staff Meetings 41:00 Vetoing a Billion-Dollar Launch: Transitioning from the Judge to a Faithful Witness of Risk Meet our Sponsors: Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  4. Jul 3

    [RE-RELEASE] Clint Gibler on AI Revolutionizing Cybersecurity

    Welcome back to Zero Signal! In this special re-release, Conor Sherman and Stuart Mitchell sit down with Clint Gibler—Head of Security Research at Semgrep, creator of the TLDRsec newsletter, and host of the Modern Security Podcast. Recorded live at Black Hat, Clint breaks down how artificial intelligence is rewriting the playbook for application security, vulnerability discovery, and developer workflows.AI is rapidly transforming cybersecurity, moving from a speculative future tech to an active force automating penetration testing and reshaping how security teams interact with codebases. In this conversation, Clint examines the practical implications, cost structures, and future prospects of deploying AI in security pipelines.More Conversations from Black Hat:The Zero Signal team will be in attendance on the ground again at Black Hat USA 2026, catching up with industry pioneers and capturing more amazing conversations on the cutting edge of cyber defense. Stay tuned for our upcoming on-site coverage!In the meantime, you can dive back into our full library of live event interviews by checking out the Full Black Hat 2025 Episode Playlist on YouTube: https://youtube.com/playlist?list=PLvtGUUDFmi-b-fELkdzirA9yYEcNVfVVJ&si=-6dc4A24dfJWyENpContinued Reading & Resources: TLDRsec Newsletter: https://tldrsec.comThe Modern Security Podcast: https://modernsecurity.ioSemgrep Code Analysis Platform: https://semgrep.devOWASP Top 10 for LLMs & Applications: https://owasp.orgGoogle Project Zero Vulnerability Research: https://googleprojectzero.blogspot.comDeepMind Camel Framework (Agent Separation): https://github.com/camel-ai/camelSocket Supply Chain Security Platform: https://socket.devHugging Face Model Repository: https://huggingface.coTrail of Bits Security Tools & Research: https://trailofbits.comBuilding Secure and Reliable Systems (Google Books): https://sre.google/books/building-secure-and-reliable-systemsComplianceAsCode GitHub Repository: https://github.com/ComplianceAsCode/content00:00 AI's Impact on Penetration Testing03:19 The Future of Junior Pen Testers05:42 Working with AI: A New Paradigm10:31 Trusting AI Outputs12:31 Shifting Down: A New Security Approach15:20 Making Security Invisible for Developers16:44 The Role of AI in Security and Development19:04 Integrating Security into Vibe Coding21:21 Human in the Loop: Balancing Automation and Oversight25:27 Emerging Security Risks in AI Infrastructure29:41 Understanding Prompt Injection Challenges31:05 Innovative Solutions in AI Security32:28 Risks of Model Integration and Code Execution34:14 Navigating AI Model Adoption in Organizations38:52 Career Pathways in CybersecurityAbout the Guest:Clint Gibler is the Head of Security Research at Semgrep, where he focuses on static analysis, developer enablement, and scaling AppSec programs. He is the creator of TLDRsec, a premier weekly newsletter providing deeply technical, actionable security summaries to thousands of industry professionals. Key Topics:Meet our Sponsors:Hampton North is the premier US-based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signalSysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  5. Jun 26

    Sean Catlett: Why Agent Trust Must Be Computed, Not Granted

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Sean Catlett, co-founder of Polymodal, founding CISO of Reddit, former Chief Security Officer at Slack, and the executive who pioneered combining security with trust and safety at Bumble. Sean leverages his history across massive technological waves—from the dot-com era to cloud and mobile transitions—to deliver a masterclass on how modern security leaders must adapt to drive enterprise AI adoption or face getting layered out of the room completely. In this deep dive into agentic autonomy, Sean details why the traditional CISO operating model of building walls and forcing technology choices is entirely broken. He introduces the critical concept of "computed trust"—the philosophy that autonomous systems must continuously earn their privileges through verifiable runtime evidence and contextual sensing rather than holding permanently granted access. The conversation unpacks the vital distinction between automating narrow workflows and managing a non-deterministic, long-running agent workforce. Conor, Stu, and Sean confront the upcoming realities of "computer use" execution contexts, the illusion that pure observability equals true legibility, and why co-locating risk directly with product owners is the only sustainable way to survive the logarithmic expansion of insider threats driven by rogue digital twins. Continued Reading & Resources: Polymodal Independent Research: https://polymodal.ai/executive-insights London Tech Week AI Enablement Panels: https://londontechweek.com/cyber-security-agentic-transformation Google NotebookLM Optimization Best Practices: https://notebooklm.google.com/enterprise-strategy ISO 27001 AI Risk Management Implementations: https://www.iso.org/standard/information-security-governance-frameworks Black Hat Europe GRC and EDR Projections: https://www.blackhat.com/eu/briefings/ciso-ai-enablement-trajectories About the Guest: Sean Catlett is the co-founder of Polymodal, an early-stage startup focused on AI embodiment, boundaries, and novel interaction environments. A veteran security executive, Sean served as the founding CISO of Reddit, the Chief Security Officer at Slack, and the head of security, trust, and safety at Bumble. Throughout his career, he has specialized in architecting engineering-led and threat-led security programs built to scale alongside massive business transformation. Key Topics: 01:11 The CISO Transformation: Turning Control Positions into AI Enablement Functions 04:14 Tech Wave Echoes: Applying Dot-Com, Cloud, and Mobile Paradigms to AI Transitions 06:43 Batting Averages in Risk: Why the Office of "No" Gets Layered Out by Boards 09:20 Engineering-Led vs. Threat-Led Security Models: Redefining Teams for the AI Era 12:54 The Errors and Omissions Insurance Trap: Why Delegating Judgment Is Uncovered 17:10 Defining the Agent Primitive: Workflow Automation vs. Bounded Digital Twins 20:20 The Logarithmic Insider Threat: Differentiating Human Actions From Agent Malfunction 26:15 Observability Is Not Legibility: The Failure of Legacy EDR Knowledge in AI Sessions 28:31 Higher Execution Contexts: How Agents Navigate Guardrails via Windows Subsystems 31:00 Computing Trust: Educating Agents at Runtime on Second and Third-Order Effects 38:15 The GRC Shift: Why Future Security Operations Teams Will Deploy Code Directly 45:13 The Bumble Paradigm: Unifying Classical Cyber Defenses with Trust and Safety Meet our Sponsors: Hampton North is the premier US based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal  Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  6. Jun 19

    Ilya Kabanov: "It's Not a Bug, It's a Feature"—Rogue AI Exposed

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Ilya Kabanov, the creator of "The Weather Report: Independent Dispatches on AI, Security, and Safety," which serves as a vital piece of public infrastructure read by CISOs, CEOs, and startup investors who want to stay grounded on what is actually going on in a market that sells noise. Ilya draws from his deep technical background running security engineering for Schneider Electric and leading AI protections at Google Cloud to give an honest, unvarnished look at the realities of modern enterprise defense. In this conversation, Ilya breaks down the stark reality of modern vulnerability management, where frontier models excel at discovering critical vulnerabilities but corporations are only successfully patching 14% of them. He unpacks how the changing economics of cybercrime—driven by cheap AI token customization—has completely compressed threat actor ROI, democratizing sophisticated cyber attacks and turning every organization into a financially viable target. Conor, Stu, and Ilya also explore why traditional AppSec isn't dying but rather facing massive coordination headwinds inside non-tech companies buried under legacy code and multi-vendor dependencies. The group dives into the dangerous illusion of prompt-level guardrails, the emergence of a cloud-style "shared responsibility model" forced by frontier labs, and why rogue agent behaviors like instrumental convergence are actually built-in features of advanced AI systems that security teams must learn to systematically design around. The Weather Report Project Page: https://theweatherreport.ai Ilya's LinkedIn Independent Briefings: https://linkedin.com/in/ilya-kabanov-ai-security Anthropic Aries Framework & Threat Report: https://anthropic.com/research/aries-defense-evasion-malware-analysis Verizon Data Breach Investigations Report: https://verizon.com/business/resources/reports/dbir-vulnerability-exploitation HackerOne Resolution Metrics & Bug Bounty Data: https://hackerone.com/resources/reporting/vulnerability-resolution-rates Mozilla AppSec Browser Remediation Studies: https://mozilla.org/security/blog/ai-mythos-patching-velocity Ilya Kabanov is the creator and principal architect of "The Weather Report," a weekly personalized briefing that filters noise to provide actionable data for C-suite executives and cloud architects. Before launching this independent nonprofit public infrastructure, Ilya accumulated extensive corporate leadership experience directing core security engineering operations at Schneider Electric and pioneering specialized enterprise AI protection frameworks for Google Cloud. 01:08 Filtering Market Noise to Provide Public Infrastructure for Decision Makers 06:00 The 14% Paradox: Finding Critical Vulnerabilities vs. Actual Corporate Patching Rates 07:22 The Economics of Cybercrime: How AI Compressed Threat Actor ROI Thresholds 11:11 Anthropic Metrics: Exposing the Strategic Use of AI for Defense Evasion and Malware 14:52 The Failure of Resolution Metrics: Why Corporations Can Only Patch 30% of Key Exploits 18:50 Coordination Headwinds: Why Non-Tech Organizations Stash Patches for Months 22:00 Designing Around Human Bottlenecks: Transitioning Toward Closed-Loop Remediation Stacks 27:12 The Kodak Trap: Why Legacy Defense Vendors Struggle to Overcome Core Cultures 44:24 Rogue Agents: Why Gemini 3 Pro Root Escalation is a Feature Not a Bug 48:40 The Cloud Deja Vu: Shifting to a Shared Responsibility Model for Frontier Models Hampton North is the premier US based cybersecurity search firm: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  7. Jun 12

    Cheryl Martin: The CISO Who Says No Is "Toast"

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Cheryl Martin, cybersecurity executive at C86 and former Vice President and Head of Cybersecurity at Capgemini in the UK, where she led over 350 cyber specialists across regulated sectors. Cheryl is a recognized voice on cyber leadership and was named in the 2026 most inspiring women in cyber awards. In this deep dive into modern risk operating models, Cheryl reveals how security leaders can safely navigate massive technological transformation without becoming the corporate bottleneck. Drawing from her extensive background—including her time as the global head of IT risk at HSBC managing 45 distinct global business lines—she unpacks her famous "yellow duck" analogy for scaling risk management, breaking down how to build an approval framework that turns shadow adoption into governed enablement. Conor, Stu, and Cheryl also challenge the outdated stereotype of the CISO who simply says no, tracing the critical shift toward becoming a business evangelist who establishes proactive guardrails. The conversation covers the rise of unstructured "cottage industries" of shadow AI among employees, the threat landscape shifts bringing exploitation windows down to mere seconds, and why executive humility—including the power of black box thinking and reverse mentoring from younger engineers—is a CISO's ultimate weapon for surviving the ongoing AI revolution. C86 Cybersecurity Executive Insights: https://c86.com/cyber-executive-intelligence International Cyber Expo Leadership Panel: https://www.internationalcyberexpo.com/cyber-leadership-technical-environments NIST Artificial Intelligence Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework UK Cyber Resiliency Bill Overview: https://www.gov.uk/government/collections/cyber-resiliency-digital-working-legislation Cloud Security Alliance Open-Source Playbooks: https://cloudsecurityalliance.org/research/artifacts/open-source-frameworks-mythos-response Cheryl Martin is a cybersecurity executive at C86 and a highly accomplished cyber transformation leader. She previously served as the Vice President and Head of Cybersecurity at Capgemini in the UK, managing a team of over 350 cyber specialists across heavily regulated sectors. Prior to that, Cheryl was the global head of IT risk at HSBC, directing risk postures across 45 global business entities. She is a recurring speaker at the International Cyber Expo and a recipient of the 2026 Most Inspiring Women in Cyber Award. 01:11 Navigating AI Transformation Without Becoming the Bottleneck 02:48 The Yellow Duck Analogy: Scaling Risk Postures Across 45 Global Businesses 05:47 The Threat of Shadow AI and Employee "Cottage Industries" 09:53 Flipping the Model: From "CISO Says No" to Governed Guardrails 11:11 The Sysdig Vibe Coding Stat: Why You Can't Put Brakes on Devs 17:39 The 5 Major AI Risk Vectors: Data, Models, Security, Supply Chain, and Regulation 21:48 Exploits in 27 Seconds: Tracking Mean Time to Adapt Over Mean Time to Detect 23:15 The Chameleon CISO: Shifting From Infrastructure Defense to Thought Leadership 26:43 Black Box Thinking: Adopting Aviation Industry Models for Cybersecurity Near Misses 28:31 Rising Personal Liability Under NIST2, DORA, and the SEC 31:43 Balancing Soft Skills and Team Burnout Against Complex AI Trajectories 42:41 The Power of Reverse Mentoring: Learning AI Red Teaming From Your Own Engineers Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal

  8. Jun 5

    Ayoub Fandi: Why Your Audit Program is Lying to You

    Welcome back to Zero Signal! In this episode, Conor Sherman and Stuart Mitchell sit down with Ayoub Fandi, the creator of the GRC Engineering Movement and author of the GRC Engineering Newsletter, read by thousands of security and compliance practitioners. Ayoub drops a truth bomb on the industry, exposing how typical SOC 2 audits rely on antiquated methodologies that sample a measly 25 pull requests out of thousands, slapping a 100% coverage certification on what amounts to 0.07% of actual infrastructure. He breaks down how this "abusal of trust signals" leaves organizations blind to systemic risk at a time when automated threat actors are moving faster than ever. The conversation dives deep into why 86% of GRC teams are still stuck relying on spreadsheets, how to weaponize compliance rules to win security infrastructure battles against development teams, and why the next generation of GRC platforms won't be SaaS tools but foundational AI models with real-time data wrappers. Finally, Ayoub outlines the future of Third-Party Risk Management (TPRM) through his open-source project, Corsair, moving the industry away from static PDFs and toward cryptographic, automated continuous assurance. The GRC Engineering Newsletter: https://grcengineering.com/newsletter Corsair Open-Source Trust Infrastructure: https://github.com/grcengineering/corsair Ayoub's State of the GRC 2026 Report: https://grcengineering.com/state-of-grc-2026/ Death By Claude Tracker: https://deathbyclaude.com/ Ayoub Fandi is the founder and principal pioneer of the GRC Engineering Movement. A former leading GRC engineer at GitLab, where he built custom cloud compliance infrastructure from scratch, Ayoub specializes in treating compliance and risk modeling as data engineering problems. He is an international speaker who recently presented his findings at RSA Conference 2026. 01:08 Transforming GRC from an Audit Prep Machine into an Engineering Program 01:54 The 25 PR Fallacy: Why Your SOC 2 Audit is Lying to You 02:23 Financial Auditing Legacies: Copy-Pasting Methods from the Enron Era 04:14 The Abuse of Trust Signals in Third-Party Risk Management 06:33 CISOs as Cynics: GRC Relegated to a Sales Enablement Tool 08:32 Compliance is Latin for Cash: Procurement vs. Real Security 09:16 CYA Mode: Why Standard Questionnaires Provide Zero Vendor Assurance 11:00 Building Corsair: Leveraging Open Protocols for Continuous Assurance Data 13:40 The Critical Sweet Spot: Auditing High-Risk, Low-Headcount AI Vendors 16:13 Replacing the GRC Acronym with a Trust and Assurance Framework 20:05 Deterministic Checkboxes vs. Probabilistic Risk Postures 21:08 Turning Compliance into Real-Time Observability Engine Metrics 22:56 The 2026 Survey: Why 86% of Security Programs Are Trapped in Excel 24:32 Relational Spreadsheets vs. Unified Graph Data Models 27:51 Excel Pivot Tables vs. Modern Prompt Engineering Roles 31:00 Node Hallucinations: What Happens When AI Drafts and Reviews Audit PDFs 35:28 The Notion and Cloudcore Shift: The Next GRC Platform is a Foundation Model 37:10 Leveraging Model Context Protocol (MCP) to Connect Direct Sources of Truth 41:42 The Lagging Indicator: Why Fortune 500s are Hiring Technical GRC Engineers 45:44 Parkinson’s Law: How Audit Calendars Expand to Destroy Security Innovation 47:34 Weaponizing Standards: Using Compliance to Win Hardening Battles with Devs 49:15 Control Planes and Telemetry: Who Will Own Future Assurance Programs? Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North: https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending: https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal Continued Reading & Resources:About the Guest:Key Topics:Meet our Sponsors:

5
out of 5
4 Ratings

About

Zero Signal is a podcast for CISOs and senior security leaders who are expected to have answers about AI risk before the industry has standards. We go after the strategic questions that don't yet have clean answers — the ones your board is asking and the industry is still debating. Each episode is an honest conversation with someone navigating that pressure — not with perfect answers but with principles, frameworks, and lived experience. We host guests who've had to make real calls under uncertainty and are willing to talk about what worked, what didn't, and what they're still figuring out