Discover why compliance is now a boardroom priority, not just an IT task. In this episode, Todd Coshow and Adam Goslin reveal how outdated practices put organizations at risk. Learn about the shift towards real-time breach detection and the importance of translating risks into business impacts. Perfect for leaders eager to transform compliance into a strategic advantage. Tune in to stay ahead and secure your organization's future.


Episode Transcript:

Adam, I have to ask: is compliance still an operational function, or has it officially become a boardroom issue?

Adam Goslin:
Well, it’s a good question. Definitely not optional.

The interesting part about this particular question, one of the things that would drive me absolutely bonkers, as long ago, somebody that was the last one to sit down when the music stopped in IT, either that or some poor project manager or something, they just nominate somebody to have to go through it.

Meanwhile, the folks at the top of the food chain would look at it as an IT problem, and it’s been one of the biggest hurdles to overcome.

Your question is, is this an operational function, or is this elevated to boardroom level? The reality is it’s both, and quite frankly, the people at the top of the food chain, I’ve harped on this for a couple of decades at this point in the game, need to take this shit seriously, period.

It was always perplexing to me. It was almost like the people at the top of the food chain had a greater level of concern for numerous things and did not have their eyeball on probably the things that could most dramatically impact the organization, like a breach, like their security.

They’re more worried about whether or not they made their fire insurance payment than they were about whether or not—it’s like, okay, for all these businesses that had such hyper-effing focus on their freaking fire insurance, how many of them burned to the ground? Meanwhile, how many organizations have had their name in lights over the last couple of decades?

Todd Coshow:
More and more every month, sir.

Adam Goslin:
It’s absolutely unbelievable.

You and I were just chatting not too long ago. I just happened to be perusing the list of recent breaches. Holy shit, man. There are an absolute ton of companies that have gotten hammered just since January.

I think we’ll preserve that. Maybe we’ll do another “shame the folks out there that managed to land with their name in lights” type of deal. We’ll do that another time.

Going back to the topic at hand, the reality is that as regulations are coming in, compliance and the problems that arise out of not taking your security and compliance seriously have the potential to impact the reputation of the organization, dramatically open up legal exposure for the company, and directly hit revenue and profits.

It’s not easy these days to be running a company, period, let alone, through negligence, allowing something to occur at the organization that’s going to make it a thousand times more difficult.

Boards are starting to move from a question like, “Are we compliant?” and starting to move in the direction of looking at their level of risk, how it could possibly affect the business, etc.

The good news is that more and more light bulbs are going on at the upper levels of organizations. I’m sitting over here thinking to myself, man, it is about effing time that these people are taking this crap seriously.

Todd Coshow:
Sure. Your company, TCT, does business across the world, and we’ve seen this uptick in regulation across the globe, for lack of a better term.

What do you think is driving the explosion in global regulations right now?

Adam Goslin:
There’s a couple of things going on.

We’ve got more and more increasing cyber threats and the level of risk that those pose.

If you think about it, we’ve got governments looking at cybersecurity and data governance as economic stability issues, not just an IT thing. So that’s a good sign.

Podden och tillhörande omslagsbild på den här sidan tillhör Total Compliance Tracking. Innehållet i podden är skapat av Total Compliance Tracking och inte av, eller tillsammans med, Poddtoppen.