Showing 2 episodes for Cloud Compliance
#273
April 20, 2026
EP273 From CISA to Cloud: AI Assurance, Concentration Risk, and the New Regulatory Frontier
Topics covered:
- How does "outsourcing" security to the cloud change the intensity of the security vs. privacy struggle for a CISO?
- Does the centralization of cloud make it a bigger target for regulators, or is there a dimension we’re missing?
- Does the Shared Responsibility Model actually survive contact with regulators, and how does AI complicate that boundary?
- Can AI actually automate the translation of fragmented rules into evidence, or are we just dreaming?
- How do we navigate the collision between transparency (logging everything) and privacy (recording nothing)?
- What is your one piece of practical advice for leaders helping their teams adopt AI?
#161
February 26, 2024
EP161 Cloud Compliance: A Lawyer - Turned Technologist! - Perspective on Navigating the Cloud
Topics covered:
- You work with technical folks at the intersection of compliance, security, and cloud. So what do you do, and where do you find the biggest challenges in communicating across those boundaries?
- How does cloud make compliance easier? Does it ever make compliance harder?
- What is your best advice to organizations that approach cloud compliance as they did for the 1990s data centers and classic IT?
- What has been the most surprising compliance challenge you’ve helped teams debug in your time here?
- You also work on standards development –can you tell us about how you got into that and what’s been surprising in that for you?
- We often say on this show that an organization’s ability to threat model is only as good as their team’s perspectives are diverse: how has your background shaped your work here?