Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: Q3 Security Insights 2026
Quick Take
In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions.
The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds.
If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you.
Read The Transcript
So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.
Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.
Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the pinwheel to your compliance Fourth of July parade, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I am doing fantabulous, Todd. How about yourself?
Todd Coshow:
Can’t complain.
It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026.
As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy.
As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly.
Also, feel free to reach out to us at [email protected]. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us.
Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more.
Adam Goslin:
In the grand scheme of things, it is a capability that some organizations struggle with.
Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no?
When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request.
There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof.
This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy.
It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly.
Certainly, safeguarding internal reports is one arena we’re going to get into.
As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports.
There’s a myriad of information within them that external entities don’t have any right or reason to see.
In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution.
The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those.
Only issuing your externally appropriate summary of your security posture to third parties is appropriate.
The next arena I want to touch on is a centralized distribution channel.
One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.
This was a topic that came up with an organization I was talking to just a couple of days ago.
The sales and marketing team was getting direct inquiries from prospects, and meanwhile, they were busily trying to answer the questions themselves.
“We’ve seen the security team respond to this previously, so we won’t bother them. We’re just going to go ahead and wing it.”
No, not today.
But it makes sense. The sales and marketing crew are just trying to knock down barriers, solve problems, land deals quickly, not bother the people that are really busy, etc.
Because they’re focused on closing that contract, they could inadvertently hand out stuff that they shouldn’t be handing out.
Instead, get a centralized system so that all your requests go to the same spot.
It doesn’t matter whether it’s coming from a brand-new prospect, an existing client, etc. It all goes to the same spot.
That way, the centralization gives you granular control over what leaves the building, what left the building, who sent it to whom, when, etc.
Knowing exactly what you sent out is important. When did you send it? Who at the organization got it? Which organization was it?
The interesting part is that maintaining that tracking and management system is a good reference point. It can serve a number of purposes, but it also directly supports a multitude of different security and compliance standards.
When your assessor is coming to you and saying, “How are you handling responses to clients when they’re trying to validate your compliance?” guess what? Now I’ve got a piece of evidence I can go ahead and share internally with my assessor.
Keeping in mind, you could be getting inquiries through sales and marketing, customer support, contact-us forms on your website, or direct calls going into account managers.
There’s a ton of different ways that this stuff comes in. Regardless of the entry path, go through the same process.
If you can establish a ticketing system where you can track them through tickets, cool. If you need to track them manually, then go ahead and track them manually.
What I would suggest is putting together some form of a distribution list that will send to the right people, and everybody knows where to send those requests.
Call it [email protected]. Create the distribution list. That’ll send it to the right people, but everybody in the company knows this is where we need to send these inquiries.
That makes it nice, easy, and consistent for them.
Another thing that folks need to learn is considering putting together an MNDA for prospects.
For your active clients, where you’ve got an MSA with confidentiality language, etc., that’s going to cover all this stuff, no problem.
But for prospects, if they’re starting to get past the high-level questions, that’s really where you want to put an MNDA in place with the organization.
Todd Coshow:
I couldn’t agree more with that.
Especially when you’re having conversations about proprietary things that they may have access to as clients, it almost shows the prospect the respect that you have for your own product by requiring an MNDA to move forward.
Adam Goslin:
Not only that, but if you’re actually taking this stuff seriously, then your prospect also has the notion that you’re actually taking this stuff seriously.
They have a much better feel for the security and compliance stance of the organization they’re talking to as a result.
Very few organizations that I’ve seen push back.
I had one organization quite a while ago. This dude obviously had gotten burned by somebody before, and he wanted to make sure that he had his MNDA in place.
It had these provisions in there: “If you break any piece of this MNDA, you’re going to send me X millions of dollars,” and blah, blah, blah.
I’m like, “It’s just not that important. Let’s not make it complicated.”
Just a no-frills, no-funny-business: I’m not going to share your stuff. You’re not going to share my stuff.
It goes a long way toward smoothing the waters, but yet putting appropriate paperwork in place.
Standard, high-level sales presentations and pre-approved marketing materials, no, you don’t need MNDAs for all that.
But when they start asking specifics about your systems, where they’re hosted, or how you’re handling encryption at rest, transmission, etc., that’s where we need to get the MNDA in place and have a chitchat.
Onto the topic du jour of learning to say no.
Prospects, customers, all of the above, are going to ask for all sorts of internal security documents. It happens all the time.
The top priority for your organization should be protecting your sensitive data.
Get comfortable with respectfully telling people no when they’re requesting internal documents.
Earlier this week, I think you were on a call with me, and we were talking to, we’ll call it, a large, multi-billion-dollar company.
They were coming in and going, “Give us your vulnerability scans, the results of your last one, your penetration test, and all the ad nauseam details about findings, what you did, how you fixed it, and when did you fix it?”
No.
That’s why we go through a third-party assessment, where they’ll go in and we can show them all of that detailed information, and they can confirm that we’re doing things appropriately.
Beyond that, I usually will put together some wording along the lines of:
“We are happy to provide appropriate evidence to prove our security posture. However, the requested information is internal documentation proprietary to our organization and never shared with third parties.
“To ensure we’re protecting all of our customers, you included, we do not distribute our internal documentation externally.
“You’re welcome to review our publicly available compliance assets, such as our AOC, and we would be happy to schedule a call with our security and compliance team to answer any additional technical follow-up questions you may have.”
You have to look at it from your company’s perspective. Look at it from the perspective of being a good steward of security.
Even organizations asking for raw pen-testing documentation, vulnerability scans, etc., and the vendor actually coughs this stuff up, there is little on this planet that will be a bigger blaring, flashing red siren and light going in a circle than when I see some vendor that spits this stuff out.
If they’re not going to protect their own highly sensitive security data, what the hell are they going to do with your information?
You need to draw a hard line at a centralized level to help protect your organization.
It proves to clients that you have a practice where you’re taking security seriously. They’ll actually respect it more than they’ll be offended by it.
Obviously, everything’s in the delivery. If you just responded, “Oh, hell no,” then they’re probably not going to take that as well as the description that I went over a minute ago.
But in general, folks need to get comfortable with the capability to tell customers no.
Todd Coshow:
Quick tip: don’t sort of use the TCT Portal.
Adam Goslin:
What do you mean?
Todd Coshow:
Oh, boy.
Adam Goslin:
One of the biggest challenges on these security and compliance engagements is simply being able to manage the sheer number of things that you need to manage.
You’ve got a ton of different people, places, locations, teams, applications, hosted environments, and it’s a crapload of compliance data that’s flowing across a wide variety of communication channels on the atypical engagement.
You’ve got emails coming in. You see somebody at a meeting and they tell you something pertinent about the engagement and expect you to remember.
They’re sending you text messages, chatting you in Teams, sending you Slack messages, dumping evidence to you through email.
They’ll print it out. They’ll put it on your desk. They put it on SharePoint, a file server, typically in the wrong place, leaving your voicemails, etc.
The folks that are listening to this that are intimately familiar with this pain are chuckling to themselves.
But that’s the crux of the problem when you get onto these engagements.
Coming full circle to the topic at hand, do yourself a gigantic favor. You’ve got the TCT Portal for a reason. Use it for everything.
Your engagement is still going to be complex, but solving the problem of the herding of the compliance cats is simple.
You have compliance management software, so use it. Use the TCT Portal.
Just because you have a license for the portal doesn’t mean that the people are faithfully using it as intended.
One of the big time-savers for a streamlined compliance engagement is to train the people to put things into the portal and then actually enforce it.
If you need confirmation that you’re pulling the right evidence, put it in the portal and send it up for review.
If you have a question, put it in the portal.
If you have an additional explanation about evidence you provided, put it in the portal.
If you need to reference vendor documentation for a particular item, guess what you do, Todd?
Todd Coshow:
Put it in the portal.
Adam Goslin:
You’re a winner.
The bottom line is, it sounds simple, but human nature always wants to take over.
People want answers now, so they’re sending text messages or asking people pertinent stuff in the hallways.
Do yourself a favor. It’s painful at first, but eventually everybody gets the memo, which is, “Thank you so much for that explanation. Please put it in the portal.”
Only process items you receive through the portal.
I’ve had folks go to status meetings and be like, “Mary, I’m still waiting on the information for yada, yada, yada.”
“Oh, I told you that at the meeting last Tuesday.”
“And I told you to put it in the portal. It’s not in there. Let’s go.”
You gain greater efficiency out of it.
When you’re done with your engagement, you have a rock-solid artifact of everything that happened.
Who did it? When did they do it? What did they provide?
This is gold for year two plus, in your future years.
You can use that prior information to guide the next compliance cycle and save even more time than you did on the first one.
Your training costs are going down. Speed of acquisition for control owners’ inputs goes way up because they can refer to it.
If you have new members coming in, guess what?
“I’m taking over for Mary at this point in the game. What did Mary do last time?”
All I’ve got to do is go look it up in the portal.
I know exactly who to assign the replacement items to. The new person has a direct reference to exactly what Mary provided the last go-around.
They don’t need to be asking questions. They don’t wait until the next meeting with the compliance team. They can just go into the portal and look it up.
Staging and setting up for your future engagements is made easier because all the right people are assigned to all the right things that we already went through all the 18 dimensions of hell figuring out on the last engagement.
Now, when we go and swing up our next-year engagement, we just mirror the assignments.
The organizations that do this appropriately are a lot happier with their compliance engagements than the ones that don’t.
Companies that don’t use the portal consistently are expressing frustration about not being able to determine status, wondering if so-and-so completed a task, or asking, “What did I give you last year?”
Just use the system.
The system’s up, running, and available 24/7/365. It’s available to everybody on your team, geographically, wherever they are.
You’re going to gain an absolute ton of efficiencies by using the tool that you’ve got in your hands.
Todd Coshow:
What’s new in the news?
Listeners, as always, can access links to the various news stories by going to the TCT website at gettct.com. Click on Resources and click on Security Reminders.
Adam, what’s new in the news?
Adam Goslin:
We decided to throw a new portion in for the quarterly security reminder.
I don’t know why we didn’t do it before now, but I tripped across this and thought, “That’s a good idea.”
We hit a couple of highlights of breaches that happened in the prior quarter.
One in April of 2026 was Carnival. They had a social-engineering attack that ended with a ransomware payload and impacted almost six million customers for the cruise-ship business. That was a big one.
There was another one in May of 2026, which was New York City Health and Hospitals. About 1.8 million people were impacted by that breach.
Most significant was the theft of traditional PII and biometric identifiers.
It’s a problem when you can’t exactly change your palm print like you can change your passwords.
Todd Coshow:
Or your voice, for that matter.
Adam Goslin:
Exactly, depending on which biometric identifier they were taking.
It could have massive implications for those who were affected by the breach.
We’ll keep cherry-picking a couple of the big ones each quarter going forward.
Onto notable news stories.
The first of these, Fortified. This was a vulnerability targeting FortiGate firewalls.
There were about 110 million credentials harvested as part of this operation.
This was a really big credential compromise that exposed valid administrator and VPN credentials for 74,000 to 86,000 FortiGate firewalls worldwide.
This represents about half of the internet-facing Fortinet devices.
There were a slew of confirmed victims: Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, government entities, and even a Turkish NATO defense contractor.
Do yourself a favor. If you’ve got anything Fortinet or FortiGate, get up to speed on that one.
The next one was Canvas.
Canvas came back online after a major breach, but some of the California campuses were locked amid ongoing threats.
The Canvas LMS, a learning management system, had both a data breach and an outage.
It included user data, names, email, student ID numbers, and messages between users.
ShinyHunters was behind this particular attack, but it’s considered the biggest educational hack on record to date.
Over 8,800 learning institutions were impacted in some way, shape, or form.
Forty-one percent of U.S. higher-learning institutions use Canvas, and the attackers are claiming that they stole 3.65 terabytes of data.
That’s a pretty big one.
Moving on, there were some critical Ubiquiti vulnerabilities that landed in the attackers’ crosshairs.
There were some critical vulnerabilities that were being targeted by attackers.
If those were to be exploited, then remote, unauthorized attackers could make changes to vulnerable UniFi OS devices.
One vulnerability was a path-traversal defect. It would allow the attacker to access files on the underlying UniFi OS and access the underlying accounts.
Another was improper input validation, which allowed attackers to execute command-injection attacks.
The server OS version 5.0.8 was released with patches to those vulnerabilities.
If you’re not on that version and you own UniFi devices, then you’re exposed to these vulnerabilities, which are rated 10 out of 10.
Do yourself a favor. If you’ve got some Ubiquiti UniFi OS devices, go take a peek at that one.
The next security topic: security leaders are saying that the next couple of years are going to be, finger quotes, “insane.”
Security leaders were sitting down in a meeting with CyberScoop, saying that AI is finding security bugs faster than people can fix them.
This is leading to exploit development speeding up, and they’re anticipating that the next couple of years are going to be insane for organizations trying to balance the scales.
If they harness it properly, AI could be used to fight or combat the exploitations, but it’s being used faster and more effectively on the dark side of cybersecurity.
We’re getting to this point that they’re viewing as an inflection point for AI and traditional cybersecurity.
The last of the news stories, this one’s entertaining.
It’s about when the machine guesses.
There was an AI that deleted a database in nine seconds.
There was an AI agent that independently, all on its own, decided to delete an entire database at a small software company called Pocket OS.
The agent was running Cursor, which is an AI coding tool that uses Claude.
The AI agent hit a snag when it was doing its checks. Instead of stopping and raising an alert, it tried to be helpful.
What did it do? It tried to fix the issue all on its own.
It found an API token that was in an unrelated file.
That token had the capability to destroy data.
The agent called an older version of Pocket OS, skipped over a safety check, and went on and deleted the live database and wiped everything in production.
Guess where the backups lived, Todd?
Todd Coshow:
Where’s that?
Adam Goslin:
Right in the same damn spot.
They blasted the freaking backups while they were at it too.
Unsurprisingly, they did not have human beings in the loop to monitor and govern that particular AI travesty.
There we go.
Todd Coshow:
Parting shots and thoughts for the folks this week, Adam. Anything that we haven’t covered yet today?
Adam Goslin:
No. If I had to harken back to this last story, the AI thing, we’ve been doing a lot of AI content lately, things that you’re supposed to do with it, etc.
In that particular case, it underscores that you have to get your AI system, if you’re going to do these various things, to send it for real, live human-being approval before you decide to get helpful.
I think there’s going to be a lot. That is one in a myriad of tough stories that are going to continue to happen while we balance this path of AI zombie walk versus doing shit that’s smart.
It’s going to get entertaining.
Todd Coshow:
And that right there, that’s the good stuff.
That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.
Adam Goslin:
And I’m Adam Goslin.
Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.