#AuditTuesday GRC Podcast
Every Tuesday we're sharing valuable content for you with the leading authorities in GRC, Compliance and Identity Security.
The Shadow NHI Problem: What’s Hiding in Your Identity Environment?
Everybody is talking about governing AI agents. But before you can govern agents, you have to find the non-human identities already hiding in your environment.
Join Dave Ackley and Andrew Berkuta of the Goliath Cyber Security Group, for a practical discussion on the growing Shadow NHI problem.
Service accounts, workload identities, automation accounts, applications, and AI agents are accessing enterprise systems and data—often without the same visibility and governance applied to human users.
We'll explore:
How do you discover Shadow NHIs?Who owns them?What privileges and access do they have?Wh...Building a World-Class GRC Program - Lessons from Jennifer Felix-Shannon
What separates a world-class Governance, Risk, and Compliance (GRC) program from one that simply checks compliance boxes?
Join Jennifer Felix-Shannon, Director of IT Security GRC & Privacy, as she shares practical lessons learned from more than two decades leading enterprise GRC, cybersecurity governance, privacy, and audit programs. We'll explore what it takes to build and mature a successful GRC organization, align security with business objectives, work effectively with auditors and executive leadership, navigate today's evolving regulatory landscape, and create a culture where governance enables the business rather than slows it down.
Whether you're building a new...
The CFO’s Role in Cybersecurity & Compliance, w/ Steve Shaw, Fractional CFO - #AuditTuesday GRC Podcast
The CFO's Role in Cybersecurity & Compliance
Cybersecurity and compliance are no longer just IT responsibilities—they're business priorities that increasingly land on the CFO's desk.
From financial audits and regulatory compliance to cybersecurity investments, board reporting, AI governance, and mergers & acquisitions, today's finance leaders play a critical role in managing organizational risk.
Join Steve Shaw, Founder of Shaw Financial Growth and experienced Fractional CFO, together with Garret Grajek, CEO of YouAttest, as they discuss how finance and security leaders can work together to build stronger, more resilient organizations.
We'll discuss:
Why...Designing the Secure Data Center: Identity Governance and Zero Trust by Design
#AuditTuesday Presents: Designing the Secure Data Center: Identity Governance and Zero Trust by Design
Join #AuditTuesday hosts and experts from EdgeRealm.ai and YouAttest for an executive-level discussion on how modern infrastructure teams are rethinking data center security from the ground up.
What’s on the Agenda?
Identity-First Infrastructure Security:
Learn why Identity Governance is becoming a core design requirement for modern data centers, hybrid cloud environments, and AI-driven infrastructure.
Zero Trust by Design:
Discover how Zero Trust principles help reduce risk, limit lateral movement, and strengthen operational security acro...
Designing the Secure Data Center: Identity Governance and Zero Trust by Design
Join #AuditTuesday hosts and experts from EdgeRealm.ai and YouAttest for an executive-level discussion on how modern infrastructure teams are rethinking data center security from the ground up.
What’s on the Agenda?
Identity-First Infrastructure Security:
Learn why Identity Governance is becoming a core design requirement for modern data centers, hybrid cloud environments, and AI-driven infrastructure.
Zero Trust by Design:
Discover how Zero Trust principles help reduce risk, limit lateral movement, and strengthen operational security across distributed environments.
Building for Compliance and Resilience:
Explore strategies for designing infrastructure that...
Turning Identity Data Into Cyber Risk Intelligence - RKON + YouAttest, #AuditTuesday
Identity data is everywhere — but turning it into actionable cyber risk insight?
That’s where most organizations struggle.
IAMs get deployed, 2FA turned on, Access reviews get completed. But the real question remains:
👉 What is your identity risk right now?
After a year in the making, RKON has developed the IAM Maturity Intelligence Center — a cyber risk portal designed to transform identity activity into real-time, measurable risk.
In this live session, RKON and YouAttest will walk through how organizations can move beyond static governance and into continuous identity risk intelligence.
🔍...
From SBOM to Access Governance: Closing the Supply Chain Gap
Software supply chain risk is exploding — but most organizations still treat it as a code problem, not a control problem.
In this live session, Interlynk and YouAttest connect the dots between software composition risk and identity governance — showing how SBOM insights must tie back to who can access, build, and ship software.
🔍 What you’ll learn:
- How SBOMs expose hidden risk in your software supply chain
- How identity governance applies to developers, pipelines, and build systems
- How to connect SBOM findings to access reviews and least privilege enforcement
- How YouAtte...
Who Has Access to Your Systems? Featuring Dino Price of AgileGRC
Identity is still the #1 control auditors and attackers look at first —
but most small and mid-sized organizations are still struggling to answer:
Who has access to what… and is it a risk?
Join us for a live conversation with Dino Price (AgileGRC) as we break down how identity directly impacts:
- SOC 2, HITRUST, and CMMC readiness
- Day-to-day security operations
- Real-world risk (not just audit checkboxes)
No theory. No enterprise fluff. Just what actually works.
What we’ll cover (more practical framing)
✅ What an Identity Risk Asses...
Let's talk to The GRC Recruiter - #AuditTuesday w/ Pete Strouse
Thinking about a career in GRC—or trying to hire the right talent?
Join us for this live #AuditTuesday session featuring Pete Strouse, “The GRC Recruiter”, CEO & Founder of InfoSec Connect. Pete brings deep, real-world insight from the front lines of GRC hiring—and will share what he’s seeing across the market today.
This isn’t just theory—Pete will break down what actually works, what employers are looking for, and where opportunities are emerging. Plus, he’ll be taking your live questions during the session.
In this episode, we’ll cover:
The most in-dema...Time for an Identity Risk Assessment w/ Neil Chapman, Ph.D., and IntraSystems
Identity has become the control plane for modern security — yet most organizations still don’t have a clear answer to one critical question:
Who has access to what… and should they?
Join us for a live conversation with Neil Chapman, PhD (IntraSystems) as we explore why identity is now at the center of cyber security.
In this session, we’ll break down:
✅ What an Identity Risk Assessment is — and why it’s overdue
✅ How to uncover orphaned, stale, and over-privileged accounts
✅ Why service accounts and key roles create hidden exposure
✅ What...
2026 DORA Audits: What Regulators Will Expect with Ralf Menegatti
DORA is no longer theoretical. The EU’s Digital Operational Resilience Act (Regulation (EU) 2022/2554) is in force.
Financial institutions and the organizations that support them must now demonstrate measurable digital operational resilience. Regulators will expect clear evidence of ICT risk management, incident response readiness, third-party oversight, and governance accountability.
More importantly — what will regulators expect to see when they examine your identity and access governance controls?
Identity is at the center of DORA compliance:
Access governance and least privilegeControl over privileged accountsThird-party and vendor access oversightEvidence of monitoring, review, and remediationTo h...
#AuditTuesday - AI Governance in 2026 w Reliath AI
AI adoption is accelerating — but governance, risk, and regulatory readiness are still lagging behind.
As organizations move toward 2026, leaders must cut through the hype and understand what AI governance actually means, what regulations truly require, and how to operationalize governance across the enterprise.
Join us live as we discuss:
✅ What AI governance really means in 2026
✅ What regulations require vs. what frameworks recommend
✅ How organizations can prepare for AI risk, audits, and oversight
✅ How Reliath AI and YouAttest help address AI governance in practice
🎙 Featuring:
Herb Roitblat — Chief AI Officer & CTO, R...Finding (and Auditing) Those Microsoft Share Files w/ Alan Sugano
Shared Microsoft files are everywhere — but do you actually know who has access, what’s still exposed, and which links never expire?
Join us for a live discussion where we break down:
✅ What Microsoft files are being shared across your enterprise
✅ How to actually discover shared access in OneDrive, Teams, and SharePoint
✅ Why expired (or never-expiring) links are a hidden risk
✅ What identity + GRC teams should be doing right now to reduce exposure
🎙 Featuring:
Alan Sugano – Cyber Expert, ADS Consulting Group
If you care about identity governance, audit readiness, and Mi...
#AuditTuesday - Executing SCuBA Compliance, featuring Jason Dunn-Potter (CW5-R) and Allgress
Join us for this #AuditTuesday LinkedIn Live as we break down CISA’s Secure Cloud Business Applications (SCuBA) framework and what it really takes to execute on SCuBA compliance in real-world environments.
As organizations increasingly rely on Microsoft 365 and Google Workspace, securing identities and cloud configurations has become a top audit and risk priority. In this live session, we’ll cut through the noise and focus on what auditors, GRC professionals, security leaders, and MSPs need to know now.
YouAttest’s Garret Grajek will be joined by Jason Dunn-Potter(CW5-R), ex-Whitehouse Chief Warrant Officer...
Auditing Microsoft Active Directory for Compliance & Zero Trust Security
Active Directory remains the backbone of enterprise identity — and one of the largest sources of audit findings, security gaps, and insider risk.
Yet many organizations still rely on manual reviews, spreadsheets, and outdated processes to prove compliance.
In this #AuditTuesday LinkedIn Live, we’ll break down why Active Directory auditing is more critical than ever — especially for SOX compliance, access governance, and Zero Trust identity security.
You’ll learn:
Why AD continues to be a top risk area for SOX, auditors, and security teamsHow manual access reviews fail — and where auditors focus firstHow YouAttest a...After the BRICKSTORM Hack: An Identity-First Security Strategy for 2026
A critical discussion on cybersecurity in the wake of the BRICKSTORM attack—a sophisticated Chinese APT campaign targeting critical infrastructure. This live session will explore how organizations can pivot to identity-first security strategies to defend against nation-state threats.
What is Covered:
- Understanding the Threat
- What was the BRICKSTORM hack?
- Who was targeted and how did the attack unfold?
- The broader implications for critical infrastructure security
- Building Defense Through Identity
How to construct an identity-first architecture
T
Who Should Watch:
- CISOs and se...
Zero Day + Sloppy IAM = Catastrophe: Lessons from 2025’s Biggest Breaches w/ Darrick Richardson
Discussion on how sloppy identity practices made 2025 breaches worse
2025 delivered zero-day nightmares: SharePoint RCE, Oracle EBS privilege escalation, VMware vCenter remote code execution — all exploited in the wild.
But the real catastrophe? Sloppy IAM. Overprivileged accounts, ghost users, and orphan access turned surgical strikes into enterprise-wide meltdowns. One compromised admin in VMware? Full domain takeover. One stale Oracle account? Financial data exfiltrated.
Join Garret Grajek (CEO, YouAttest) and Darrick Richardson (IAM & Cloud Security Architect) for a no-BS breakdown of 2025’s worst breaches — and how automated user access reviews stop the bleeding.
🔍 We’ll cov...
#AuditTuesday - SOX IT Audit Prep w/ Paul Feather and Craig Guinasso
Are you an IT leader, auditor, or professional navigating the complexities of Sarbanes-Oxley (SOX) compliance? Join our upcoming webinar, "SOX Preparation: Mastering IT Controls for Seamless Compliance," where we'll dive deep into the IT-specific aspects of SOX to help you build robust systems and avoid costly pitfalls.
What You'll Learn:
Key IT General Controls (ITGC): From access management and change controls to data integrity and cybersecurity measures essential for SOX Section 404 compliance.Audit-Ready Strategies: Practical tips on documenting processes, implementing automated controls, and preparing for IT audits without disrupting operations.Common IT Challenges & Solutions: Real-world examples...#AuditTuesday GRC Podcast - America's First AI Transparency Law, CA SB 53 w/ Karina Klever
Join us for an engaging #AuditTuesday session on California’s CA SB 53 - America’s First AI Transparency Law.
CS SB 53 was signed into law on September 29, 2025. Hosted by Karlina Klever, GRC Expert from Klever Compliance, and featuring Garrett Grajek, CEO of YouAttest and Multi-Patented AI & Identity Innovator, this event promises valuable insights.
This is a pioneering law targeting frontier AI models with over 10^26 FLOPs. It mandates that large developers (over $500 million revenue) disclose safety protocols to mitigate catastrophic risks like bioweapons or cyberattacks, and it sets up public incident reporting channels. Effective January 1, 2026 - it’s...
#AuditTuesday GRC Podcast - After the Hack - Keep SharePoint Secure w/ Greg Kutzbach
In this dynamic #AuditTuesday webinar, cybersecurity expert Greg Kutzbach, Cybersecurity Expert, will dive into the critical topic of keeping SharePoint secure after recent hacks.
He will be joined by Garret Grajek, CEO of YouAttest, to discuss robust identity security strategies. The session will explore real-world threats and actionable solutions to protect your SharePoint environment.
Key Discussion Points:
- Why SharePoint Matters: Understand the importance of SharePoint in your organization and the risks it faces.
- Identity Security in SharePoint: Learn why identity security is crucial to safeguarding SharePoint data.
- Knowing Your Perm...
#AuditTuesday GRC PodCast - AI Hacking featuring Alan Sugano and Shannon Noonan
In this dynamic #AuditTuesday webinar, cyber security expert Alan Sugano, President of ADS Consulting Group, we’ll dive into the escalating threat of AI-powered cyberattacks. He will be joined w/ Garret Grajek, CEO of YouAttest on how robust access governance can protect your business and Shannon Noonan, GRC and Cyber Expert.
The session explores real-world tactics like AI-driven credential cracking, deepfake scams, and invisible malware, offering actionable strategies to counter them.
Key Discussion Points:
Master PCI DSS 4.0 Compliance w/ Truvantis and YouAttest
Tune in for an engaging #AuditTuesday GRC podcast focused on mastering the complexities of PCI DSS 4.0. This live session, hosted by YouAttest, a premier identity governance solution, will feature Truvantis, a leading GRC consulting firm, sharing expert insights to guide you toward confident compliance.
In this session, we’ll cover:
Key PCI DSS 4.0 Updates: Understand critical changes and how they impact your organization.Streamlined Compliance Strategies: Learn how Truvantis’ expert GRC services simplify risk management and compliance processes.Identity Governance Simplified: See how YouAttest’s automated user access reviews strengthen security and ensure PCI DSS compliance.Who...
AI Governance - Ignorance is Not Bliss w/ Ashley Robinson and Allgress
Join us for an engaging #AuditTuesday webinar featuring renowned AI governance expert Ashley Robinson, hosted by YouAttest. This session will explore the critical elements of AI governance, addressing the risks, standards/frameworks/guidances, and actionable steps needed for responsible AI adoption.
Many organizations overlook the importance of education and governance awareness in AI use—leaving leaders and staff unprepared! This session will highlight the need for practical policies and training to build public trust.
Ashley will share insights on translating frameworks like NIST AI RMF and ISO/IEC 42001 into actionable classroom and workforce policies, while Yo...
#AuditTuesday - Who’s Really Inside Your System? w/ #ThatAuditGuy RobertBerry
Join us for an engaging #AuditTuesday webinar featuring renowned auditor Robert Berry, #ThatAuditGuy, hosted by YouAttest. This session will explore the critical elements of conducting effective t user access reviews for identity security vulnerabilities and meeting compliance regulations SOX, GLBA, HIPAA, PCI-DSS, NYRR 500, CCPR/CCPA.
Many organizations fall short by relying on the identity managers to conduct the reviews - without consulting the business and application owners! This practice violates audit guidelines!
Robert will inform you how audits are done the right way! And YouAttest will discuss/demo how to ensure access to sensitive data and a...
CISO’s: Strengthening Supply Chain Security with Identity Governance and InvisiRisk
#AuditTuesday Presents: The CISO’s Playbook: Strengthening Security with Identity and Supply Chain Governance
CISOs need robust strategies to secure their ecosystems and the supply chain and identities that make these supply chains secure - are core to a secure enterprise. Join our #AuditTuesday GRC Podcast, where YouAttest’s Garret Grajek and InvisiRisk experts explore how user access reviews and GRC platforms fortify security across identity and software development lifecycles.
What’s on the Agenda?
Real-World Security Lessons: Learn from the experts on real world use cases where faulty supply chain security and identity securi...Starting An AI Project? Where Does GRC Fit In? With MyTech.Network's Robert Hilliker
As AI transforms industries, ensuring robust governance, risk, and compliance (GRC) is critical to building secure and ethical AI systems. In this dynamic #AuditTuesday GRC Podcast,welcomes Robert Hilliker, an AI project leader, to explore how GRC integrates into AI development.
What’s on the Agenda?
Real-World AI Insights: Robert Hilliker shares experiences from his diverse AI projects, highlighting challenges and successes.AI Governance Frameworks: Introduction to NIST AI Risk Management Framework (AI RMF) and ISO 42001, and the OWASP Guide on LLAM and Generative AI for responsible AI development.GRC Across the AI Lifecycle: Practical strategies for...#AuditTuesday: v-CISOs: Scaling Identity GRC for Security and Compliance w/ YouAttest and Allgress
With cyber threats escalating and compliance requirements tightening, organizations need flexible, expert-driven solutions to stay secure. Virtual CISOs (v-CISOs) are redefining governance, risk, and compliance (GRC) by delivering strategic expertise without the cost of a full-time CISO.
In this exciting edition of the #AuditTuesday GRC Podcast, Jerry Sisson, Founder/CEO of MyTechNetwork, moderates a compelling discussion with Jeff Kushner, a cybersecurity marketing and GRC expert, and Garret Grajek, CEO of YouAttest, a certified cybersecurity innovator (CEH, CISM, CGEIT, CISSP) with 10+ patents in identity security.
What’s on the agenda?
#AuditTuesday: Hey MSPs! Time to Get on Board w/ YouAttest Managed UARs!
MSPs – it's time to expand your security service offerings with a critical, high-demand compliance function: User Access Reviews (UARs).
In this special edition of the #AuditTuesday GRC Podcast, Garret Grajek, CEO of YouAttest, sits down with Joe Rojas, Co-Founder of Start Grow Manage, to discuss how MSPs can unlock new revenue and compliance value by partnering with YouAttest as their backend Managed Security Service Provider (MSSP) for UARs.
What’s on the agenda?
- What exactly is a User Access Review (UAR) and why is it foundational to any cybersecurity compliance framework?
- The in...
#AuditTuesday: CISO Reality Check — Identity Risk w/ Larry Whiteside
As identity risk rises across enterprises, CISOs are being called to lead the charge in governance and access oversight. But are they equipped for the challenge?
In this edition of the #AuditTuesday GRC podcast, we sit down with Larry Whiteside Jr., veteran CISO and Co-Founder of Confide—a peer-based leadership network for cybersecurity executives—for a frank discussion on how identity fits into modern risk strategy. Larry also brings his perspective as Co-Founder of the ICMCP, focused on advancing diversity in the cybersecurity space.
Key Topics:
Why identity governance is a CISO’s responsibility nowCom...#AuditTuesday - AI Governance and Model Risk Management w/ James Sayles
As artificial intelligence reshapes business, compliance, and security landscapes, organizations are under pressure to implement clear governance strategies. Yet, many lack a roadmap for ethical, secure, and compliant AI deployment.
In this special edition of the #AuditTuesday GRC podcast series, we welcome James Sayles, author of Principles of the Governance Model for Risk Management, to explore the critical issues surrounding AI governance. Sayles will share his expert perspective on where current governance frameworks fall short—and what enterprises, auditors, and boards must do to close the gap.
Key Points:
The current state of AI go...
MSPs and GRC (Governance Risk and Compliance) w/ Shannon Noonan and Daniel Morrison
Governance Risk and Compliance is a $45.6B market - a market the Managed Service Providers (MPSs) need to be in they want to grow.
But GRC, the concept of helping enterprises obtain not only compliance but be able to show proper governance is out of the comfort zone of many MSPs.
How to start? How do MSPs get into this much needed space that benefits both the MSP and their clients. That’s what we cover in this webinar.
Key Points:
How to get started w/ GRC?
What needs to be offere...Automating AWS Entitlement Reviews - with CloudArmee
AWS is the premier cloud vendor - AWS is the basis of most enterprises cloud strategy.
To help us understand the importance of AWS and AWS entitlements, YouAttest has partnered with CloudArmee, prominent AWS experts.
CloudArmee and YouAttest have partnered together to help enterprises determine what their access entitlements are for their AWS deployments.
E.G. for your AWS deployment: What roles have been created? Who has access? What is the identity security posture of the enterprise AWS server and services? This is not a question easily answered.
But it needs to...
EU's DORA and Identity Governance - with Ralph Menegatti from concedro
Huge regulatory changes face the EU nations and the companies that work w/ the EU: Digital Operational Resilience ACT (DORA).
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) solves an important problem in the EU financial regulation. DORA mandates that enterprises augment their protection, detection, containment, recovery and repair capabilities against ICT-related incidents.
But what does this mean for your enterprise - and what does this mean for your identity and identity governance efforts?
To answer these questions - YouAttest invites a foremost authority in EU regulations: Concedro, featuring CEO, Armin Binsteiner and compliance exp...
Reviewing Privileged Accounts - with Synoptek MSP
Privileged users are the source of most enterprise problems: from outsider attacks, insider threads and compliance - the focus usually involves admin accounts.
These accounts have to be reviewed - and on a regular basis. How?
And...
How do we even get started?To delve into this key security topic we had invited the security and managed service experts at Synoptek. They bring rea...
Shared Signals - What They Mean for Authorization
Shared Signals - for those in the identity know - it’s a subject that time has come.
Shared Signals refers to a standardized system where organizations can exchange real-time security information about users across different platforms.
What we cover, here:
To delve into this key security topic we have invited the security and identity experts. We will be joined by Craig Guiansso, cyber security expert at Alector and David Wor...
CMMC 2.0 Ruling - What Does this Mean? With ShortArm Solutions
The U.S. Department of Defense (DoD) on October 15th, 2024 published its long-anticipating first part of the final rule (32 CFR) for the Cybersecurity Maturity Model Certification (CMMC) program.
The program will require third-party verification for contractors working with controlled unclassified information (CUI) confirming that contractors are meeting existing DoD cybersecurity standards and a self-assessment by contractors that have Federal Contract Information (FCI) showing that they are in compliance with the 15 controls in Federal Acquisition Regulation (FAR) 52.204-21.
What does this mean? For Contractors? How do enterprise adhere to the new standards - and document their pr...
The Trump Administration and Cyber Regulations - Karen Klever, Mike Andrewes and Stacey Cameron
New administration - new attitude, regulations, priorities on cyber governance? No question.
But what will it be?
What about CISA?What about NIST?What about the SEC?What about CMMC?All of these and more will be discussed.
To answer these questions - YouAttest invites authorities in compliance and security matters, Stacey Cameron, CEO of Cycam Strategies, Karina Klever of Klever Compliance, and Mike Andrewes of Yastis
To learn more about YouAttest and how we can help secure your identities, contact us at info@youattest.com
Okta “No Password Flaw” - What Is It? How to Secure? - Featuring Greg Kutzbach
Okta announced that they had a flaw in their authentication - where under “specific circumstances” a user could gain access w/o inputting the password associated with the account.
How is this possible?
What does this mean?And most importantly…How to secureThat’s what will be discussed this very important #AuditTuesday w/ Greg Kutzbach, Cyber Security and Digital Forensic Expert of Exhib A Cyber.
To learn more about YouAttest and how we can help secure your identities, contact us at info@youattest.com
Mentoring the Next-Generation of Cyber Professionals - Featuring Ted Alben
You can’t talk about cyber security with a professional today without the conversation turning to the topic of the next generation.
Namely our youth - with questions coming up,
Are they ready for jobs in cyber security?
Are they capable of taking the reins of responsibility for cyber security?At what level?And what needs to be done to get them more ready.But how AI is created is not longer a science project - it’s a regulated business. Key aspects of the creation of the AI components must be govern, especi...
CMMC 2.0 Final Ruling - What Does This Mean? Featuring Michael Andrewes, Yastis
The U.S. Department of Defense (DoD) on October 15th, 2024 published its long-anticipating first part of the final rule (the Final Rule) for the Cybersecurity Maturity Model Ceritficat (CMMC) program.
The program will require third-party verification for contractors working with controlled unclassified information (CUI) confirming that contractors are meeting existing DoD cybersecurity standards and a self-assessment by contractors that have Federal Contract Information (FCI) showing that they are in compliance with the 15 controls in Federal Acquisition Regulation (FAR) 52.204-21.
What does this? For Contractors? How should this change this practices and documentation procedures?
To...