#AuditTuesday GRC Podcast

YouAttest

95 episodes listed below

Listen to the show on

GRC risk, translated into operational reality.

The gist

#AuditTuesday GRC Podcast treats governance, risk, compliance, and identity security as operational work, not abstract policy language. Episodes move through hiring realities, access reviews, DORA preparation, AI governance, and Microsoft file exposure with guests.

PRESS PLAY

Find your next episode

All episodes

About #AuditTuesday GRC Podcast

#AuditTuesday GRC Podcast is a practical GRC and identity-security show centered on risk as it appears in daily operations. It is less interested in polished theory than in the work of proving, reviewing, hiring, and correcting. Recent conversations move across GRC careers, identity risk assessments, DORA audits, AI governance, and Microsoft file sharing. The throughline is access. Who has it, who should have it, how evidence is produced, and what happens when policy outruns the tools available to enforce it. Episodes often begin with a timely board-level or audit-level concern, then bring it down to the level of stale accounts, admin reviews, external file links, segregation of duties, and hiring-manager expectations. The show is brisk, technical, and usually interview-driven. It gives guests room to explain their background, but keeps returning to the operational question. What does the company need to know, document, monitor, or fix? The GRC recruiting episode with Pete Strauss looks past certification lists and toward experience, communication skills, and the problem of training entry-level talent. The identity-risk discussion with Neil Chapman, Ph.D., focuses on privilege creep, access reviews, and the danger of writing policies that the organization cannot actually execute. The DORA episode with Ralf Menegatti treats digital resilience as a broad control environment, where access evidence and regulatory scrutiny reach beyond IT administration. The AI governance panel frames regulation, readiness, compute, and risk management as audit and leadership concerns rather than hype-cycle talking points. The Microsoft file-sharing conversation with Alan Sugano is especially concrete, zeroing in on external links, anonymous access, and missing expiration dates across OneDrive, Teams, and SharePoint. The show can sound like a live industry session, complete with product mentions and contact details. Its value is in the working examples. For compliance professionals, security leaders, auditors, and GRC job seekers, it provides a clear view of the questions that come up before audits, after incidents, and during hiring conversations. It is practical, specific, and more useful when the listener wants the operational consequences than when the listener wants a formal lecture.

Made for: Built for GRC professionals, security leaders, auditors, compliance teams, and job seekers trying to understand how controls work in practice. It also suits executives who need plain explanations of audit exposure, identity risk, and regulatory readiness.

What sets it apart: The show stands out by tying governance topics to specific operating problems: access reviews, evidence requests, policy gaps, shared files, and hiring constraints. It keeps returning to the practical question of whether an organization can prove what its policies claim.

In their own words

Every Tuesday we're sharing valuable content for you with the leading authorities in GRC, Compliance and Identity Security.

As heard by us

Based on 4 episodes we listened to · September 2026

Detailed practitioner conversations reveal where identity controls, regulatory audits, and GRC hiring succeed or break down.

#AuditTuesday GRC Podcast keeps governance and compliance tied to decisions people have to make at work. In live, question-led conversations with practitioners, the host presses past broad requirements toward operational questions: who still has access, whether controls match…

Read our full review in PlayNext →

Why you'd press play

A policy promises monthly access reviews. The auditor asks for proof. Sound familiar?

Press play if you want

  • to close the gap between a written control and a review you can actually perform
  • to hear a GRC recruiter weigh experience and communication skills against an alphabet soup of certifications
Read the full recommendation in PlayNext →
identity risk assessmentsGRC hiring and certificationsaccess reviews and privilege creepDORA audit expectationsAI governance readinessMicrosoft file sharingpolicy versus control executionaudit evidence

Talks about

Best episodes of #AuditTuesday GRC Podcast

Short reviews from the PlayNext desk, based on the episodes we processed.

Let's talk to The GRC Recruiter - #AuditTuesday w/ Pete StrouseApr 7, 2026

A practical look at GRC hiring, where experience and communication carry the most weight.

This episode follows GRC careers and hiring through Pete Strauss, a GRC recruiter and founder of InfoSec Connect. It stays close to the practical side of the field, showing how people get in, how they move forward, and what hiring managers actually weigh when a role opens.

Time for an Identity Risk Assessment w/ Neil Chapman, Ph.D., and IntraSystemsMar 24, 2026

Identity risk comes down to whether access, policy, and daily controls line up.

Identity risk here is framed as a governance problem, not a slogan. The discussion keeps coming back to a simple test: who has access, and does that access still make sense?

2026 DORA Audits: What Regulators Will Expect with Ralf MenegattiMar 10, 2026

DORA is presented as a practical test of access, monitoring, and proof.

Audit Tuesday treats DORA as a live test of operational resilience, not a slogan. Ralph Minigotti moves through the questions auditors and regulators are likely to ask now that the framework is in force, and the strongest moments stay grounded in ordinary controls: who has…

Finding (and Auditing) Those Microsoft Share Files w/ Alan SuganoFeb 17, 2026

An auditor-minded look at Microsoft 365 sharing risk, from OneDrive and Teams to SharePoint.

This episode takes a clear-eyed look at a familiar Microsoft 365 exposure problem, with attention on shared files across OneDrive, Teams, and SharePoint and the way access can drift into risk.

Podcasts like #AuditTuesday GRC Podcast

Episodes

  1. 1

    Worried About Rogue AI? Start with Identity Governance - #AuditTuesday w/ Justin Roy and Jeff Kushner

    Sep 29, 2026·54m
  2. 2

    The Shadow NHI Problem: What’s Hiding in Your Identity Environment?

    Sep 15, 2026·52m
  3. 3

    Building a World-Class GRC Program - Lessons from Jennifer Felix-Shannon

    Aug 18, 2026·40m
  4. 4

    Designing the Secure Data Center: Identity Governance and Zero Trust by Design

    Aug 4, 2026·1h
  5. 5

    The CFO’s Role in Cybersecurity & Compliance, w/ Steve Shaw, Fractional CFO - #AuditTuesday GRC Podcast

    Aug 4, 2026·42m
  6. 6

    Designing the Secure Data Center: Identity Governance and Zero Trust by Design

    Jerry Sasson hosts Robert Hilliker, Garrett Greyjack, and Kashif Mehmood on redesigning data centers for security, resilience, AI, and zero trust.

    Jun 24, 2026·1h·4 clips
  7. 7

    Turning Identity Data Into Cyber Risk Intelligence - RKON + YouAttest, #AuditTuesday

    Jun 9, 2026·43m
  8. 8

    From SBOM to Access Governance: Closing the Supply Chain Gap

    May 26, 2026·47m
  9. 9

    Who Has Access to Your Systems? Featuring Dino Price of AgileGRC

    Apr 29, 2026·39m
  10. 10

    Let's talk to The GRC Recruiter - #AuditTuesday w/ Pete Strouse

    Hidden gem

    Pete Strauss joins from St.

    Apr 7, 2026·36m·2 clips
  11. 11

    Time for an Identity Risk Assessment w/ Neil Chapman, Ph.D., and IntraSystems

    Hidden gem

    Identity risk is the day-to-day problem.

    Mar 24, 2026·40m·2 clips
  12. 12

    2026 DORA Audits: What Regulators Will Expect with Ralf Menegatti

    Hidden gem

    Bill opens the discussion on DORA.

    Mar 10, 2026·44m·2 clips
  13. 13

    #AuditTuesday - AI Governance in 2026 w Reliath AI

    This episode features a panel discussion on AI governance, regulation, risk, and readiness in 2026, focusing on what leaders need to understand and implement.

    Feb 25, 2026·1h 1m
  14. 14

    Finding (and Auditing) Those Microsoft Share Files w/ Alan Sugano

    Hidden gem

    Garrett and Ellen Sugano zero in on shared Microsoft files as a security issue that many organizations run into, especially once Microsoft 365 becomes part of everyday work.

    Feb 17, 2026·35m·2 clips
  15. 15

    #AuditTuesday - Executing SCuBA Compliance, featuring Jason Dunn-Potter (CW5-R) and Allgress

    Jan 27, 2026·57m
  16. 16

    Auditing Microsoft Active Directory for Compliance & Zero Trust Security

    Jan 14, 2026·28m
  17. 17

    After the BRICKSTORM Hack: An Identity-First Security Strategy for 2026

    Dec 17, 2025·29m
  18. 18

    Zero Day + Sloppy IAM = Catastrophe: Lessons from 2025’s Biggest Breaches w/ Darrick Richardson

    Dec 2, 2025·56m
  19. 19

    #AuditTuesday - SOX IT Audit Prep w/ Paul Feather and Craig Guinasso

    Nov 16, 2025·56m
  20. 20

    #AuditTuesday GRC Podcast - America's First AI Transparency Law, CA SB 53 w/ Karina Klever

    Oct 15, 2025·51m
  21. 21

    #AuditTuesday GRC Podcast - After the Hack - Keep SharePoint Secure w/ Greg Kutzbach

    Oct 8, 2025·42m
  22. 22

    #AuditTuesday GRC PodCast - AI Hacking featuring Alan Sugano and Shannon Noonan

    Sep 23, 2025·45m
  23. 23

    AI Governance - Ignorance is Not Bliss w/ Ashley Robinson and Allgress

    Sep 11, 2025·42m
  24. 24

    Master PCI DSS 4.0 Compliance w/ Truvantis and YouAttest

    Sep 11, 2025·32m
  25. 25

    #AuditTuesday - Who’s Really Inside Your System? w/ #ThatAuditGuy RobertBerry

    Aug 27, 2025·47m
  26. 26

    CISO’s: Strengthening Supply Chain Security with Identity Governance and InvisiRisk

    Aug 4, 2025·59m
  27. 27

    Starting An AI Project? Where Does GRC Fit In? With MyTech.Network's Robert Hilliker

    Aug 4, 2025·49m
  28. 28

    #AuditTuesday: v-CISOs: Scaling Identity GRC for Security and Compliance w/ YouAttest and Allgress

    Jun 13, 2025·57m
  29. 29

    #AuditTuesday: Hey MSPs! Time to Get on Board w/ YouAttest Managed UARs!

    May 29, 2025·45m
  30. 30

    #AuditTuesday: CISO Reality Check — Identity Risk w/ Larry Whiteside

    May 27, 2025·45m
  31. 31

    #AuditTuesday - AI Governance and Model Risk Management w/ James Sayles

    Apr 30, 2025·44m
  32. 32

    MSPs and GRC (Governance Risk and Compliance) w/ Shannon Noonan and Daniel Morrison

    Mar 25, 2025·50m
  33. 33

    Shared Signals - What They Mean for Authorization

    Mar 12, 2025·42m
  34. 34

    CMMC 2.0 Ruling - What Does this Mean? With ShortArm Solutions

    Mar 12, 2025·38m
  35. 35

    Automating AWS Entitlement Reviews - with CloudArmee

    Mar 12, 2025·32m
  36. 36

    EU's DORA and Identity Governance - with Ralph Menegatti from concedro

    Mar 12, 2025·51m
  37. 37

    Reviewing Privileged Accounts - with Synoptek MSP

    Mar 12, 2025·46m
  38. 38

    The Trump Administration and Cyber Regulations - Karen Klever, Mike Andrewes and Stacey Cameron

    Jan 17, 2025·56m
  39. 39

    Mentoring the Next-Generation of Cyber Professionals - Featuring Ted Alben

    Jan 16, 2025·15m
  40. 40

    Okta “No Password Flaw” - What Is It? How to Secure? - Featuring Greg Kutzbach

    Jan 16, 2025·31m
  41. 41

    German Cyber Hacks and EU DORA - Featuring Ralf Mennegatti

    Jan 16, 2025·10m
  42. 42

    GRC Fatigue and What Can Be Done - Featuring Stacey Cameron

    Jan 16, 2025·13m
  43. 43

    CMMC 2.0 Final Ruling - What Does This Mean? Featuring Michael Andrewes, Yastis

    Jan 16, 2025·13m
  44. 44

    MSPs: Automate Your Identity Audits

    Jan 16, 2025·12m
  45. 45

    MSPs: Automate Your Identity Audits w/ YouAttest "User Access Reviews" (UARs)

    Dec 10, 2024·12m
  46. 46

    HR-IAM Variance - Detecting Orphan Users and Privileges w/ YouAttest

    Dec 10, 2024·14m
  47. 47

    CMMC 2.0 Final Ruling Update - Yastis, Micahel Andrewes

    Dec 10, 2024·13m
  48. 48

    The Change Healthcare Hack - A Game Changer in Health Risk Management w/ Greg Kutzbach

    Dec 10, 2024·55m
  49. 49

    AWS - In-Depth Entitlement Audit by YouAttest w/ Raj Sawhney (CDW)

    Dec 10, 2024·17m
  50. 50

    GRC Fatigue and What Can Be Done w/ Stacey Cameron (CyCam Strategies)

    Dec 10, 2024·13m
  51. 51

    German Cyber Hack and EU DORA w/ Ralf Mennegatti

    Dec 10, 2024·10m
  52. 52

    HR-IAM Variance - Cleaning out Orphaned and Mis-Aligned Privileges, w/ Karina Klever

    Dec 10, 2024·14m
  53. 53

    CPF Coaching: YouAttest Product of the Week for MSPs - Christophe Foulon

    Dec 10, 2024·31m
  54. 54

    Getting Started w/ Your Compliance Project - Karina Klever and Cloud PSO

    Dec 10, 2024·48m
  55. 55

    YouAttest Next-Gen IGA on AWS Marketplace w/ Cloud Armee (Chris Kesik)

    Dec 10, 2024·27m
  56. 56

    NIST Frameworks and CMMC for Federal Contractors - Short Arm Solutions, Jeff Chao and Rick Mischka

    Dec 10, 2024·41m
  57. 57

    YouAttest ITS (Identity Trust Score) - For Managed Service Providers (MSPs) w/ Eldon Sprickerhoff

    Dec 10, 2024·51m
  58. 58

    YouAttest CGEIT Study Session - Summary, Episode 5 - Karina Klever and Kelly Gilmore

    Nov 13, 2024·1h 5m
  59. 59

    YouAttest CGEIT Study Session Domain 4 - Featuring Karina Klever and Kelly Gilmore

    Nov 13, 2024·1h 2m
  60. 60

    YouAttest Next-Gen IGA on AWS Marketplace w/ CloudArmee - #AuditTuesday

    Nov 13, 2024·27m
  61. 61

    The CDK Global (Car Dealership) Hack and the IAM/SSO Connection

    Nov 13, 2024·52m
  62. 62

    Errors in Cyber Vendor Selection and Vendor Mgmt - w/ David Gilies

    Nov 13, 2024·13m
  63. 63

    CISA and The Principle of Least Privilege - Identity Governance w/ David Worthington

    Nov 13, 2024·52m
  64. 64

    Black Hat 2024 - Mel Reyes and Shaun Walsh

    Nov 13, 2024·52m
  65. 65

    Developing AI? Access Controls Matter - w/ GetSmart Cyber Defense

    Nov 13, 2024·43m
  66. 66

    EU'S DORA and Identity Governance - Special Guest: Ralf Menegatti

    Jun 26, 2024·51m
  67. 67

    YouAttest CGEIT Study Session: Domain 3 - Featuring Karina Klever and Shannon Brewster

    Jun 20, 2024·1h 4m
  68. 68

    CGEIT Training Session - Domain #2 w/ Karina Klever and Kelly Gilmore

    Jun 18, 2024·1h 1m
  69. 69

    Cybersecurity 80-20 Rule - Start with Identity w/ Michael Andrewes of Yastis

    Jun 18, 2024·46m
  70. 70

    Limiting the Identity Attack Surface - Red Cup IT Starring Dan Le

    May 28, 2024·52m
  71. 71

    Before the Breach - Strategy on Identity Security

    May 25, 2024·48m
  72. 72

    CGEIT Training Session - Domain 1 w/ Karina Klever and Kelly Gilmore

    May 25, 2024·1h 2m
  73. 73

    Identity Governance in Healthcare - featuring Steve Taccogna

    May 24, 2024·39m
  74. 74

    Change Healthcare Hack: Update - PoLP Matters featuring Carrie Jabs

    May 23, 2024·13m
  75. 75

    Consequences of a MSP Breach - Financial, Legal and Cyber Implications - Featuring Cynthia Stamer, Peter Gailey and John Allen

    Apr 4, 2024·1h 6m
  76. 76

    The Microsoft Email Hack - Service/User Accounts Used for OAUTH SSO w/ Greg Kutzbach

    Mar 1, 2024·27m
  77. 77

    Ego and the Start-up Entrepreneur with Professor David Carlson

    Mar 1, 2024·30m
  78. 78

    Cyber Security and Cyber Law - Identity Governance w/ Stacey Cameron, Shawn Tuma and Justin Corker

    Mar 1, 2024·1h
  79. 79

    Why IGA is Failing Our Enterprises - Stacey Cameron, Mel Reyes, Tom Sabbe

    Feb 7, 2024·55m
  80. 80

    Cybersecurity and Change Control, focus Identity - with John Young and Kelly Gilmore

    Jan 31, 2024·54m
  81. 81

    Entitlement Audit of AWS for Security and Compliance - Featuring Raj Sawhney

    Jan 27, 2024·17m
  82. 82

    Halloween Scary Stories on Identity Hacking w/ Craig Guinasso and Paul Feather

    Jan 27, 2024·30m
  83. 83

    MSPs - It’s Time to Get Outside of the Box w/ Eldon Sprickerhoff

    Jan 27, 2024·8m
  84. 84

    YouAttest “Segregation of Duties” for Identity Security and Compliance w/ Shannon Noonan

    Jan 27, 2024·15m
  85. 85

    Security Audits - What’s Missing? w/ Dmitriy Sokolovskiy

    Jan 27, 2024·17m
  86. 86

    What is Insider Threat and How Does GRC Address w/ Carrie Jabs

    Jan 27, 2024·7m
  87. 87

    AI and Search - What’s Next w/ David Novick

    Jan 26, 2024·14m
  88. 88

    Data Security and Identity Governance w/ Michael Andrewes

    Jan 23, 2024·9m
  89. 89

    CISA and The Principle of Least Privilege w/ CISA Security Advisor: Donald E. Hester

    Jan 16, 2024·59m
  90. 90

    AI Data and Sloppy Handling Will Get You Sued w/ Malcolm Harkins

    Jan 11, 2024·18m
  91. 91

    The SEC 10-K and Mandated Cybersecurity Messaging w/ DV Subramanyam

    Jan 11, 2024·58m
  92. 92

    SEC Charges Against SolarWinds and Tim Brown w/ Peter Schawacker

    Jan 11, 2024·8m
  93. 93

    Another Okta Attack, Another IAM Attack - What to Do? (With SHI Security SE Josh Gold)

    Jan 11, 2024·8m
  94. 94

    How Sloppy Identity Practices are Killing Us with Kevin Moss

    Jan 11, 2024·10m
  95. 95

    GRC 2024 - What to Hope For - What to Expect w/ Carrie Jabs

    Jan 3, 2024·12m