# The Commoditization of Compliance and SOC 2 Page: https://stenobird.com/podcast/grc-uncensored-7039393/the-commoditization-of-compliance-and-soc-2 Text version: https://stenobird.com/podcast/grc-uncensored-7039393/the-commoditization-of-compliance-and-soc-2.md Podcast: [GRC Uncensored](https://stenobird.com/podcast/grc-uncensored-7039393) Published: 2024-10-10T10:00:45+00:00 Episode link: https://grcpod.substack.com/p/the-commoditization-of-compliance Audio file: https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67051e89ed8ff5205ed9d4a5/media.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/the-commoditization-of-compliance-and-soc-2 Duration seconds: 2419 ## Resource In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time. The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards. 00:00 Welcome to GRC Uncensored 01:34 Introducing Kendra Cooley 02:05 Love-Hate Relationship with GRC 03:16 The SOC 2 Debate 04:33 Challenges with SOC 2 Audits 09:10 The Value of SOC 2 in the Industry 12:04 The Evolution of Compliance Frameworks 20:39 False Sense of Security in Compliance 24:46 The Buzz Around AI and Quantum 25:10 Staying Updated as a Security Professional 26:45 Challenges in Penetration Testing and Vendor Assessments 27:37 Compliance and Its Impact on Security 30:10 Government Regulations and Their Effectiveness 32:23 The Complexity of Privacy Laws 38:29 The Role of GRC Teams in Risk Management 42:30 Concluding Thoughts and Future Episodes Hosted on Acast. See acast.com/privacy for more information. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/the-commoditization-of-compliance-and-soc-2/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/grc-uncensored-7039393/the-commoditization-of-compliance-and-soc-2.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.