{"version":"1.0","type":"rich","provider_name":"Acast","provider_url":"https://acast.com","height":250,"width":700,"html":"<iframe src=\"https://embed.acast.com/$/6702dcb9c88f09c3e0b9a10a/695525f45f9b0b61aaaba4f2?\" frameBorder=\"0\" width=\"700\" height=\"250\"></iframe>","title":"AMA: GRC, SOC 2, and the State of Audits","description":"<p>It’s the last day of 2025, which means it’s time to wrap season one. When Troy and I piloted this series, we didn’t expect thousands of you to tune in, and certainly didn’t expect to pickup the wonderfully smart Kendra to join our crew.</p><p><br></p><p>With that, we want to thank you for encouraging us to keep this series going. We’ll be back for season 2 soon, and are taking in new pitches for episodes now. To wrap the year, we conducted a AMA on the current state of GRC. We pulled questions from <a href=\"https://old.reddit.com/r/cybersecurity/comments/1ppqcwg/ama_about_the_current_state_of_grc_conversation/\" rel=\"noopener noreferrer\" target=\"_blank\">Reddit</a> and <a href=\"https://www.linkedin.com/posts/elliotv_join-troy-fine-and-kendra-cooley-of-grc-uncensored-activity-7407434398687703041-xrHw?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAJkq7oB5vp964tKu45smLzBSwV9ZnBhRPA\" rel=\"noopener noreferrer\" target=\"_blank\">LinkedIn</a> and tackled them live in conversation.</p><p><br></p><h3>What we covered</h3><p><strong>Are we “anti–GRC automation tools”?</strong></p><p>Short answer: no. Long answer: automation isn’t the problem. It’s misuse, blind trust, and compromised audit integrity are.</p><p><br></p><p><strong>Cheap SOC 2s and bundled audits</strong></p><p>Why budget startups often <em>don’t</em> have a real incentive to avoid low-cost, bundled auditors, and what you give up when you go that route.</p><p><br></p><p><strong>SOC 2 pentesting vs PCI DSS</strong></p><p>Why SOC 2 allows weak or missing pentests, why PCI doesn’t, and how automated scans differ from real manual testing.</p><p><br></p><p><strong>Conflicts of interest in the GRC ecosystem</strong></p><p>Platforms, auditors, and vCISOs all partner, so where does objectivity break down, and is it even possible to keep it clean?</p><p><br></p><p><strong>Who’s really at fault: tools or auditors?</strong></p><p>A blunt discussion on incentives, accountability, and why low-quality audits keep winning.</p><p><br></p><p><strong>Offshoring and the race to the bottom</strong></p><p>When cost-cutting leads to offshoring, what should clients actually be worried about and what’s just noise.</p><p><br></p><p><strong>The future of audits and AI</strong></p><p>Will AI replace auditors? Where automation helps, where humans still matter, and what happens if we stop caring about independent assurance altogether.</p>","author_name":"Chaos"}