Podlipodcast player Webplayer

The Security Strategist

The Security Strategist

Preemptive by Design: Is GRC the New Front Line for Security?

The Security Strategist · Sep 22, 2026 · 20:55

0:0020:55

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

Every CISO’s inbox is hot with this email at least once a year: the audit is four months away, and it's time to stop everything.

As a result, progress comes to a halt, and a person then spends two weeks logging into 30 different consoles, taking screenshots in order to show that MFA has been turned on. After the audit is over, the evidence becomes invalid, and exactly twelve months later the same frantic situation begins all over again.

That is precisely the kind of situation that Jonathan Schipp, Senior Director of Product Management at Rapid7, aims to end, and it is the focus of the most recent episode of The Security Strategist podcast.

In this episode, host Richard Stiennon, Chief Research Analyst at IT-Harvest, is joined by Schipp to talk about the reason why governance, risk and compliance (GRC) is moving from being a yearly rush to becoming a continuous, API-driven element of security operations. They also address why AI is causing this change to happen more quickly than most GRC teams can keep up with.

“Compliance turns into something you have to put everything else aside for,” Schipp tells Stiennon. “When an enterprise carries out its SOC 2 audit, most of them are not well prepared; it disrupts the business flow.”

Key Takeaways

Rapid7 launched CyberGRC to connect live security telemetry to compliance evidence

Continuous monitoring replaces manual screenshot evidence with API-based checks

SOC 2 and ISO 27001 still require annual audits; continuous monitoring closes the gaps between them

Roughly 1% of discovered vulnerabilities are actually exploitable, per Schipp

AI models are finding more vulnerabilities mainly by scanning source code faster

Automated exploitation attempts generate high log volume, making them detectable

Rapid7's GRC platform supports ISO/IEC 42001 and the NIST AI RMF

Rapid7 serves roughly 11,000 customers, many now requesting AI-specific controls

GRC's role is to move the business through AI risk, not block AI adoption

Boards typically have audit and risk committees but no dedicated security committee

Vulnerability risk should be classified by business impact, not treated as uniform

Basic controls — MFA, asset inventory, patching exploitable exposures — stop most attacks, AI-driven or not

Chapters

00:00 Introduction and guest overview

02:07 Incentives for security maturity

03:06 European and US regulatory developments

03:50 Connecting security telemetry with GRC

04:16 Continuous compliance and audit cycles

05:16 The importance of continuous control monitoring

06:20 Using APIs for evidence collection

07:16 Managing vulnerabilities and exceptions

08:18 Classifying vulnerabilities and risk

09:15 AI in security and human accountability

09:53 The reality of AI discovering vulnerabilities

11:08 Managing noise and false positives in AI detection

12:10 Integrating AI systems for proactive security

13:26 Preemptive security and threat intelligence

14:17 Risks of AI in attack scenarios

15:16 AI misuse and governance challenges

16:23 Balancing AI adoption with controls

17:22 The importance of basic security controls

18:22 Key takeaways for CISOs and security leaders

20:19 Closing remarks and next steps

For further information, visit rapid7.com and em360tech.com.

Episodes: The Security Strategist

PodliGet the free Podli app
↓ App