Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: Regulatory Explosion & Board-Level Accountability
Quick Take
Discover why compliance is now a boardroom priority, not just an IT task. In this episode, Todd Coshow and Adam Goslin reveal how outdated practices put organizations at risk.
Learn about the shift towards real-time breach detection and the importance of translating risks into business impacts. Perfect for leaders eager to transform compliance into a strategic advantage.
Tune in to stay ahead and secure your organization’s future.
Read The Transcript
Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the red and white patterned tablecloth to your compliance picnic, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I’m doing good today, Todd. How about yourself?
Todd Coshow:
I cannot complain.
We’re going to talk about something interesting today, sir. We’re going to talk a little bit about regulatory explosion and the board-level accountability that goes along with that.
But before we do, as always, we want to take an opportunity to thank the listeners of this podcast and invite you to share your thoughts or your ideas.
Get in touch with us at [email protected].
Adam, I have to ask: is compliance still an operational function, or has it officially become a boardroom issue?
Adam Goslin:
Well, it’s a good question. Definitely not optional.
The interesting part about this particular question, one of the things that would drive me absolutely bonkers, as long ago, somebody that was the last one to sit down when the music stopped in IT, either that or some poor project manager or something, they just nominate somebody to have to go through it.
Meanwhile, the folks at the top of the food chain would look at it as an IT problem, and it’s been one of the biggest hurdles to overcome.
Your question is, is this an operational function, or is this elevated to boardroom level? The reality is it’s both, and quite frankly, the people at the top of the food chain, I’ve harped on this for a couple of decades at this point in the game, need to take this shit seriously, period.
It was always perplexing to me. It was almost like the people at the top of the food chain had a greater level of concern for numerous things and did not have their eyeball on probably the things that could most dramatically impact the organization, like a breach, like their security.
They’re more worried about whether or not they made their fire insurance payment than they were about whether or not—it’s like, okay, for all these businesses that had such hyper-effing focus on their freaking fire insurance, how many of them burned to the ground? Meanwhile, how many organizations have had their name in lights over the last couple of decades?
Todd Coshow:
More and more every month, sir.
Adam Goslin:
It’s absolutely unbelievable.
You and I were just chatting not too long ago. I just happened to be perusing the list of recent breaches. Holy shit, man. There are an absolute ton of companies that have gotten hammered just since January.
I think we’ll preserve that. Maybe we’ll do another “shame the folks out there that managed to land with their name in lights” type of deal. We’ll do that another time.
Going back to the topic at hand, the reality is that as regulations are coming in, compliance and the problems that arise out of not taking your security and compliance seriously have the potential to impact the reputation of the organization, dramatically open up legal exposure for the company, and directly hit revenue and profits.
It’s not easy these days to be running a company, period, let alone, through negligence, allowing something to occur at the organization that’s going to make it a thousand times more difficult.
Boards are starting to move from a question like, “Are we compliant?” and starting to move in the direction of looking at their level of risk, how it could possibly affect the business, etc.
The good news is that more and more light bulbs are going on at the upper levels of organizations. I’m sitting over here thinking to myself, man, it is about effing time that these people are taking this crap seriously.
Todd Coshow:
Sure. Your company, TCT, does business across the world, and we’ve seen this uptick in regulation across the globe, for lack of a better term.
What do you think is driving the explosion in global regulations right now?
Adam Goslin:
There’s a couple of things going on.
We’ve got more and more increasing cyber threats and the level of risk that those pose.
If you think about it, we’ve got governments looking at cybersecurity and data governance as economic stability issues, not just an IT thing. So that’s a good sign.
We’re seeing new regulations and frameworks rolling out, the NIS2 Directive, the EU AI Act, all pushing to enforce accountability up through those highest levels.
The interesting part about all of this is that as this has been going, seeing the companies starting to take things more seriously, there’s also, I’m going to call it, a shortened time span between the analytical and detection tools available, the speed of that data’s availability, and visibility into it.
That’s kind of a double-edged sword right now. For the organizations that have access to this information for their own company, great. They can see what’s going on. They’ve got the capability to take steps in the right direction to thwart risks that are being posed to the organization.
But the other side of that coin is that the bad guys are also getting a never-ending continuous feed of, “Hey, guess what? We just found this vulnerability or that vulnerability.”
They’ve got not only the things that they’ve developed as processes for their attack vectors, but they also have a continuous inbound stream feed from innumerable sources of new vulnerabilities that have been identified.
It’s definitely a problem that’s far from going away. I think, in many ways, we’re in the early stages of it really hitting a crescendo at this point in the game. But we can’t do anything if the light bulbs aren’t twinkling.
Todd Coshow:
Sure. Trying to get a better understanding of whether or not this is actually hyperbole or truly a risk: are executives truly at risk personally, or is that overstated?
Adam Goslin:
Historically, they’ve run under this notion that, “It’s not my job. It’s somebody else eight steps down the food chain.”
No offense to the uppity-ups at the various companies, but I think, in many ways, for a long time, it was one of those, “I’m going to close my eyes, plug my ears, repeat the words la, la, la, la, la, and pretend like I’m not ultimately responsible for making sure that we’re taking this shit seriously.”
The reality is that more and more executive-level and board-level people are starting to get themselves in the crosshairs of regulators.
SEC cybersecurity disclosure rules require leadership to certify disclosures, demonstrate oversight, and create a realm of personal liability if something goes wrong.
The notion that the people at the top of the food chain can just plead ignorance or, “It’s not my job,” no. You’re personally responsible for the people whose job it is.
Trying to plead the Fifth or plead ignorance, those days are going to continue to evaporate.
For the folks that are at the top end of the food chain, they really have a decision to make. Are they really willing to walk this tightrope of hoping that they don’t get their foot caught in the mousetrap, or are they going to throw caution to the wind, or take it seriously?
I think it’s long overdue that the folks at the top of the food chain started to actually be held accountable because their inaction to date, and in general, has been absolutely absurd.
Todd Coshow:
Yeah, I agree. The days of feigning ignorance are quickly evaporating, as you mentioned.
How is this shift toward faster breach reporting changing the game?
Adam Goslin:
It just compresses everything.
Organizations used to have a certain period of time. Some organizations didn’t have to do reporting for, in some cases, north of a year. It used to be weeks to months. Now the pressure’s on so that they have days to go through and respond to these breaches.
What it means is that they’re going to need real-time visibility into what’s going on, incidents, escalation paths, and the ability to communicate risk quickly throughout the organizations.
If your organization cannot explain what happened quickly, then you’re already behind the eight ball.
The pressure is going to continue to escalate toward communication of breaches in a shorter and shorter period of time.
I’m seeing a lot of pressure even in the legal agreements that we sign off on with organizations. I have seen a tremendous amount of increased pressure for shortened reporting timelines because organizations are tired of only finding out there was a problem way too late in the game, after a ton of damage has already been done.
It’s inappropriate.
Todd Coshow:
Why is translating technical risk into business risk becoming so critical?
Adam Goslin:
Boards don’t operate with technical language.
Generally speaking, not saying this is the case with all board members, because certainly there are some technical board members, but the vast majority of them aren’t.
Telling them, “We have a vulnerability,” isn’t going to hit home. They can’t relate to what that means in language that makes sense to them.
But if you’re coming to them and saying, “Hey, just a heads up, this particular issue could shut down our operations instantly and cost us approximately $10 million,” then—
Todd Coshow:
That’s going to move the needle.
Adam Goslin:
Yeah. At the end of the day, money talks and something walks.
It’s about getting the light bulb to twinkle at that level. You’ve got to be able to translate it into a way or a method or an approach that connects with them.
I would throw down the gauntlet to those leaders within both compliance and IT that that is a skill.
That’s a skill that, for a long time, has been difficult for the folks in compliance and IT to bridge, but that’s certainly, in my mind’s eye, an area of growth for those technical leaders within the organization.
It’s one thing to be sitting there and saying, “The uppity-ups didn’t do anything.”
If I were to walk into my executive team or my board meeting, let’s pretend for the sake of this discussion that none of them speak Japanese, and I deliver my state of the state in compliance and IT address only in Japanese, what are they going to do with that? They don’t understand what the hell I’m talking about.
You’ve got to, as a leader within the compliance and IT space, translate your speak into their speak, keying in on things that are financial in nature, legal impacts, operations impacts, etc.
It’s important as a leader within the IT or technical space to be able to do that.
Todd Coshow:
Absolutely. What separates organizations that are adapting well from those that aren’t?
Adam Goslin:
Long story short is the good old-fashioned definition of insanity: doing the same thing and expecting a different result.
If you’re going to continue doing nothing, not taking it seriously, or not upping your game as an organization, then you are not adapting to everything changing around you right now.
You can’t just go and pick out a nice park bench. It doesn’t work that way.
The ones that are doing it are those that have moved into a continuous compliance mode or real-time finger on the pulse of what’s going on.
To put this in perspective, when I initially—and this actually predates TCT—was spending time with organizations doing security and compliance consulting, one of the things that I saw as one of the biggest shortcomings during that period of time was that you’ve got these organizations.
Number one, I was running into some companies, we call it checklist compliance. All I’m trying to do is check the boxes.
“I just want to check these boxes, and as long as I have done the bare minimum to be able to purport that I’ve checked the box, good enough, let’s keep it moving.”
It’s like these organizations—and it’s probably one of the biggest misses for the leadership of the organization—what they don’t understand is frameworks like the Payment Card Industry Data Security Standard, which I’ve used for a very long time because it’s an extremely prescriptive standard.
It all depends on what scope you decide to point that at. In the case of its original writing, it was written for credit cards. But I could take all of those fundamentals and apply them generically to the organization and just call it sensitive data.
If it’s good enough to protect credit cards, I’m sure it’s good enough to be able to protect the other sensitive data within the company.
It all depends on the approach.
Back when I was doing the security compliance consulting, you’d see organizations doing checkbox compliance. You’d see the annual scramble to get compliance.
The companies that end up without their name in lights are either, one, astronomically lucky and the chicken timer’s just ticking down until they do, or otherwise they actually took this shit seriously.
I called it operational compliance way back in the day. In fact, as soon as I made TCT, it was one of the first things that we built into the platform once it went live.
I think I did this over a decade ago, enabled an operational compliance mode within the TCT Portal so that organizations could not have the annual compliance scramble, but instead spread their stuff out all year long, gaining better visibility throughout the year.
It really helped those organizations with integrating security and compliance into the DNA of the company.
It also helped a lot with increasing the visibility to the upper levels of those organizations, to where their leadership groups started to get on the same page about the importance of the security and compliance activities that were going on within the company.
It really helped a lot.
It’s the organizations that are actually taking it seriously that fall into that good adoption.
Todd Coshow:
Yep, it’s all about creating that culture of compliance.
Parting shots and thoughts for the folks this week. Got them?
Adam Goslin:
If I haven’t harped on it enough, for every single person that’s at an upper level within a freaking organization, take this shit seriously.
Stop brushing it under the rug. Stop saying that it’s somebody else’s responsibility. Stop saying that it’s five levels below me and that’s their job. Take this stuff seriously.
The more that you, as a leader within the organization, embrace this notion of, “We are going to take our security and compliance seriously,” the more you do that as a leader, the more finely tuned your entire program will become.
The more that your personnel, vendors, etc., will realize, “Hey, this company is really taking this stuff seriously.”
The more you do, the more your people that are frontline defense for the security and compliance of your organization will feel supported.
The more you do, the more you will be able to have conversations with those folks to make sure that they’re being properly supported and that your program is set up for success.
The partnership that happens, it’s magic, man.
When you can watch an organization where everybody is on the same page, they’re all taking it seriously, they understand the importance, it is awesome to watch that unfold because you watch all of these layers and layers of their security and compliance program working harmoniously to help protect the company.
I’ve said it before. I think we had this conversation on one of the pods about whether I would rather pay my cyber liability insurance bill or have a strong security and compliance program.
I said I’ll light the cybersecurity policy on fire before I would let my security and compliance program get shortchanged.
It’s that damn important.
We need more of the folks at the top end of the food chain to see the light.
Todd Coshow:
And that right there, that’s the good stuff.