J
Jake Bernardes
3
APPEARANCES
3
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
Sep 16, 2026
Why Most CISOs Don't Know What Their Business Actually Does
5:26
5:37
5:47
5:59
8:03

Jake BernardesGUEST
Then I go, okay, I've now got a whole set of security tools, like you pointed out, whether it's DR or Endpoint or GRC, whatever it might be, right? I'm now going to align that to my risks.

Jake BernardesGUEST
If I have after that point, if I have a risk where there's no tool, no headcount, no consulting, no services associated, that risk is exposed.

Jake BernardesGUEST
On the flip side, if I now have a product or a person or a service where I can't attach it to any of my specific risks, why do I have it? Like I can't demonstrate the business need for that thing.

Jake BernardesGUEST
So by presenting the risk register as my business case, effectively saying, here's my risks.

Deo OkelloHOST
I don't know why, but if you were to bring it down to a layman and, yes, definitely, like our procedure, without it feeling like a checkbox which someone is supposed to complete, how do you best present it to people who are being audited and also, at the end of the day, how are you able to manage that pressure?
SECURE& | “AI Won’t Take Your Job… It Will Change It” with Jake Bernardes | S5 Ep6
4:13
4:19
4:26
12:05

Jake BernardesGUEST
what will we do next? Like, if we now have this data, like, forget, like, here's the control, here's the evidence, here's the auditor.

Jake BernardesGUEST
Like, what workflows can I build? Like, how can I look at things that we're still doing and try to do them in a smarter way? So maybe look at, like, a risk assessment.

Jake BernardesGUEST
Historically, still, like, risk is like a finger in the air job, right? Everyone's risk register is, I take a number of risks.
7 MINS LATER

Jack BrandwoodHOST
Is that a massive concern? I know you said it shits on shits out, but do people actually trust what it is spitting out because it's so high stakes, a lot of this stuff?
ISACA Podcast: Why You Should Use the F Word More
1:16
1:22
6:30

Jake BernardesGUEST
I've written that in a lot of places, in a lot of different variants, but I'll give you the most condensed version.

Jake BernardesGUEST
I think compliance has broken from every direction, right? I think if you look at how we came to a compliance journey, really like SOC 2 was written in the late 20 noughties.

Safia KaziHOST
And you were just touching on this, but could you give us a little bit more detail on FedRAMP 20X? What is it really doing differently? And then why should people who are listening to this be thinking about this compliance overhaul?