# SOC 2, Vibes, and the Audit Arms Race Page: https://stenobird.com/podcast/grc-uncensored-7039393/soc-2-vibes-and-the-audit-arms-race Text version: https://stenobird.com/podcast/grc-uncensored-7039393/soc-2-vibes-and-the-audit-arms-race.md Podcast: [GRC Uncensored](https://stenobird.com/podcast/grc-uncensored-7039393) Published: 2025-10-22T21:14:26+00:00 Episode link: https://shows.acast.com/grc-uncensored/episodes/68f94798237885ef40ec4eff Audio file: https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/68f94798237885ef40ec4eff/media.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/soc-2-vibes-and-the-audit-arms-race Duration seconds: 2819 ## Resource This episode dives deep into the messy, absurd, and sometimes hilarious world of SOC 2 audits and compliance frameworks. Wiz CISO Expert Zlatko Unger joins the crew to talk about the expanding “acronym soup” of frameworks, the blurred lines between automation and assurance, and why finding an auditor who vibes with your team might matter more than the name on the certificate. The crew also debates the future of SOC 2 — from fast-track “15-hour audits” to the rise of AI-generated reports — and whether the entire model needs a ground-up rebuild. Guest: Zlatko Unger, CISO Expert at Wiz Hosts: Troy Fine, Kendra Cooley, Elliot Volkman 00:03 — Framework overload 00:07 — Auditor “vibe check” 00:11 — SOC 2’s fall from grace 00:16 — TPRM and audit fatigue 00:25 — SOC 2 for robots 00:36 — Reform or rebuild? Hosted on Acast. See acast.com/privacy for more information. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/soc-2-vibes-and-the-audit-arms-race/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/grc-uncensored-7039393/soc-2-vibes-and-the-audit-arms-race.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.