Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: AI-Powered Attacks: Is Your Compliance Program Already Obsolete?
Quick Take
In an era of evolving AI-driven cyberattacks, traditional compliance programs are falling dangerously behind. Static controls create a false sense of security while attackers leverage AI to move faster, exploit vulnerabilities, and bypass defenses.
On this week’s Compliance Unfiltered, Todd Coshow and compliance expert Adam Goslin explore how AI is reshaping threats, why checkbox compliance is obsolete, and how organizations must shift to continuous, real-time assurance to stay resilient, protect data, and keep pace with modern adversaries.
Read The Transcript
So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.
Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.
Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the fresh set of tires for your compliance race car, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I’m doing good, Todd. How about you?
Todd Coshow:
I cannot complain.
Today, we’re going to talk about the nefarious. That’s right, the artificially nefarious. In fact, AI-powered attacks. Is your compliance program already obsolete?
But before we do so, Adam, as always, we want to say a special thank you to listeners of this podcast. Tell your compliance friends, if they’re not listening to us already, let them know that it’s something that you enjoy doing, and they might as well.
Also, if you have any questions, topics, or general compliments you want to send our way, please do so at [email protected].
As I mentioned, Adam, AI-powered attacks are something that’s on everybody’s mind these days. I guess the question is: if AI is fundamentally changing how attacks are executed—faster, smarter, more adaptive—are most compliance programs already outdated?
Adam Goslin:
In a lot of cases, yeah. It’s not because of some type of poor design, but a lot of the programs that exist now were founded in advance of the advent of AI, built in a different time, if you will.
A lot of the compliance programs have certain assumptions baked in: stability, known systems, predictive behavior, human-driven threats. AI is really putting a gaping hole in that assumption, if you will.
You’ve got attacks these days that can adapt midstream. They can mimic a legitimate user and scale with a speed that wasn’t possible before.
Compliance is still, in many cases, measuring control effectiveness and measuring controls being in place at fixed points in time. It isn’t necessarily that the compliance is wrong, but it’s operating on a timeline that’s not matching up to today’s newfangled AI-world reality.
Todd Coshow:
Fair enough. Where do you see the biggest disconnect today between what compliance frameworks validate and what’s actually happening inside an environment?
Adam Goslin:
One of the biggest gaps is between existence and effectiveness.
Frameworks are good at confirming controls exist. There is a policy. Here it is. There’s a process, and there’s evidence. But they’re not consistently validating that the control is working under real-world conditions, and quite frankly, the real world is changing under our feet, if you will, especially when it comes to these AI-driven attacks.
You’ve got organizations that hold up their piece of paper and say, “Hey, big green checkbox, we’re compliant.” But the controls, in some cases, are bypassed shortly after the validation that, at that point in time, they were working.
In many cases, the controls aren’t getting tested against how attack patterns are really behaving in the real world these days.
Todd Coshow:
You’ve talked about organizations having a false sense of their own state of compliance. How does AI make that problem even worse?
Adam Goslin:
AI accelerates the drift and buries it, if you will.
Controls have a tendency to degrade over time. Access reviews get stale. Monitoring gets noisy and ignored. That type of stuff was already happening. But AI allows for the exploit of those gaps faster than many organizations are set up to detect them.
Now you’re sitting here with a situation where, on the one side, I’m technically compliant because of my last audit. But operationally, I’m not compliant because the environment has modified or changed, and the attackers are jumping on those gaps immediately.
We’ve seen for a long time where vulnerabilities will get known within the space. The identification of the new vulnerability to that vulnerability or that attack pattern being leveraged has been a thing for many years. But now we’re in a situation where exploiting a particular approach or attack pattern can happen very quickly.
Many organizations were operating under a security-by-obscurity-style approach where, “We’re too small,” or, “It’s going to take the bad guys a while to find us.” People have got to wake up. The landscape is changing fast. You can’t just kick back and rest on that notion.
It’s what’s making organizations have that false sense of security. Especially at the upper levels of the organization, they feel like, “We have our piece of paper with our big green checkbox, so we’re cool, and we’ll go back to compliance next year.”
Unfortunately, with the speed that things are moving right now, the organization isn’t seeing the failure until it’s too late at this point in the game. It makes it a challenging chicken-and-egg problem, if you will.
Todd Coshow:
That leads to the following. What if we pressure-tested a typical compliance program today? What type of AI-driven attack scenarios are most likely to expose weaknesses?
Adam Goslin:
Anywhere where we’ve got a trust assumption in place.
For example, AI-driven phishing, where somebody’s credentials get compromised. Back in the day, it was somebody trying to masquerade as a particular user, but it’s broken English and grammar that’s not accurate, and things along those lines.
A lot of those telltale signs from a phishing perspective are going by the wayside at this stage of the game because I can use AI to compose something that sounds completely legitimate.
In the event of a credential compromise, you pair that up, and now you’ve got a situation where realistic messaging is coming across the bow and it’s coming from a known user, a known source.
The attacker is able to behave much more like a real user than they could before.
You get into deepfake-based social engineering. You’ve got your processes followed exactly, but the input’s fraudulent.
Automated exploitation, where AI is finding and abusing misconfigurations faster than controls have the capability to detect or respond.
I go back to the early days. I had an experience where we were watching and monitoring a group that was executing an attack. They were very quickly morphing because they had everything scripted.
They’d go in and do one round to say, “Is this box alive?” Then that would go away. All of a sudden, another one would say, “What type of a box is it?”
They were doing various tests along those lines. Every single time they went through these waves, it was coming out of a different group of IP addresses.
That alone made it extremely difficult. I could go in and blacklist the IP addresses, but they kept morphing and changing the IPs.
The entire structure that these guys had set up—and keeping in mind, this was two decades ago—that group was fairly advanced at the time.
You take that scenario, which these guys had basically scripted to go from one group of IPs to another, to another, with different tests, slowly escalating and elevating their attack approach or process to dial in on what the heck do we have here.
You take that same type of notion that was capable two decades ago, and now you layer on AI. The bad guys are having an effing field day right now because they can use automation and intelligence to modify and morph their approaches.
In all the cases that I was mentioning, it’s not necessarily that the controls fail in terms of the design, but it’s more a failure of speed, context, and adaptability. That’s the biggest problem, if you will.
Todd Coshow:
When you look at that reality, what fundamentally needs to change in how organizations approach compliance?
Adam Goslin:
They need to move from static validation to continuous assurance.
Fifteen or 20 years ago, when I was doing security and compliance engagements and helping people shepherd their programs, it was one of the biggest things that I saw.
When we initially launched the TCT Portal back in 2015, I think it was within a year that we had what we call operational compliance bolted into the TCT Portal because it was one of the problems.
You only go in and look at this stuff once a year, and it becomes an issue if somebody wasn’t doing one of the periodic checks that they need to do throughout the program.
In operational compliance mode, at least we have far earlier detection capability.
Now we move toward things like continuous assurance—literally continuous assurance, not periodic assurance throughout the compliance cycle.
The more adept the organization can get at that automation, the better off they’re going to be and the faster they’re going to be able to respond.
A lot of the programs today are built around proving something out at that moment in time, but organizations need to do more. They need to move into that continuous evaluation mode.
They need to make sure that they can put their fingers on their evidence and have it at hand at all times, real-time visibility into their compliance posture.
It’s not as much about the need for additional controls, but more about ensuring that those controls the organization has are actually functioning as intended consistently, not just occasionally.
Todd Coshow:
Looking ahead, Adam, what does the future of compliance look like in a world where AI is embedded in both attacks and operations? I feel like this has the potential to be a war front that we’re not ready for.
Adam Goslin:
Is this where I cough and say Skynet?
Todd Coshow:
Yes.
Adam Goslin:
Compliance needs to become more integrated, more automated, more operational.
We’re going to see shifts where compliance isn’t this separate function that prepares for audits, but is really integrated into the day-by-day DNA of the organization.
There’ll be a much higher focus on continuous monitoring, real-time validation, and being able to clearly demonstrate control effectiveness.
Regulators are going to start expecting that. They’re not going to just come in and say, “Do you have this control? Can you prove it out once?”
They’re going to be asking more questions about, “How are you able to ensure that the control’s effectiveness is operating all the time?”
The organizations that have the capability to answer that question more confidently will be in a far stronger position.
The ones that can’t are going to be the ones struggling to keep up with the Joneses, if you will.
Todd Coshow:
Parting shots and thoughts for the folks this week, Adam.
Adam Goslin:
For a very long time, I’ve been pushing organizations to take their program seriously, to not leverage checkbox compliance, moving past the notion of the annual compliance scramble, and really making the security and compliance posture of the organization more of a day-by-day activity throughout the compliance cycle, instead of just this moment in time when it becomes audit season.
The move in this direction to AI being leveraged by both the good guys and the bad guys is going to bring that notion of real-world, real-time analysis, evaluation, protection, etc., to the forefront.
The one thing that I would strongly encourage organizations to do is they have to start moving in this direction of making the security and compliance posture of the organization a day-by-day thing, not a once-a-year or seasonal thing, if you will.
Todd Coshow:
And that right there, that’s the good stuff.
That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.
Adam Goslin:
And I’m Adam Goslin.
Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.