The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran

The End of Security Theater: Why TPRM and SOC 2 Are Broken | Guest: Rachel Curran

Source: YouTube · GRC Engineering Club · published Jul 25, 2026 · 47:36

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

Rachel Curran argues that third-party risk management (TPRM) has become "security theater" driven by outdated compliance checkboxes, urging a shift toward practical, evidence-based security and continuous monitoring.

Key Takeaways:
• Static questionnaires and one-time audits are ineffective; companies must prioritize continuous monitoring of actual security controls over compliance paperwork 1:50
• MFA remains the single most impactful control for preventing breaches, yet it's frequently neglected in favor of complex, less effective measures 2:40
• Small startups should skip SOC 2 and instead focus on demonstrating core security hygiene through transparent vendor conversations 6:25
• Third-party risk can be a competitive differentiator; companies that proactively share their security posture are more likely to win enterprise deals 14:35
• Organizations must stop using third-party risk as an excuse for poor internal data governance and minimize vendor breach impact through least privilege and robust backups 39:10

As the digital ecosystem becomes increasingly interconnected, the focus must shift from bureaucratic compliance to practical risk reduction, ensuring that security practices actually protect business operations.

Sources:

  • 1:50 Security theater in TPRM
  • 2:40 MFA as critical control
  • 6:25 SOC 2 unsuitability for small startups
  • 14:35 Security as competitive differentiator
  • 39:10 Internal data governance and least pri

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome friends to another edition of the Eti Checkbox Podcast. I am joined today by somebody like I keep saying at the top of these, I get to I'm in this game just to talk to cool people and this is one of the ones that I look forward to on a subject that I'm keenly I keenly want to just sit there and and and learn from the ineitable Rachel Curran. Rachel, welcome. >> Oh, thank you so much for having me. I'm really excited to chat with you today and get to actually meet you and chat in person. >> Absolutely. We I've been a fan of yours for a long time, but it's it's kind like internet friends, you know, I'm I'm of the age where internet friends I know there's a difference. It's not the assumption. So, it's cool to like finally meet you like you said and and chat, but uh walk me through te…