114 episodes
- AI is reshaping enterprise risk by introducing new concerns like drift, hallucination, model security, and expanded data use, while also amplifying existing operational and compliance challenges. Organizations are feeling growing pressure to move faster with AI, even as critical gaps in visibility, collaboration, and enforcement make governance harder to scale.
In this episode, ISACA’s Donnie Carpenter, Principal, Information Security and Professional Practices, Research Development, speaks with Michael Siegrist, Field CTO and Head of Americas Risk Solutions at OneTrust, about what an integrated approach to risk and compliance looks like in practice—from assessing AI across the IT ecosystem to prioritizing risk in ways that support business growth rather than stall innovation.
Michael unpacks how organizations can govern AI responsibly, translate emerging risks into enforceable controls, and build greater visibility across their risk landscape. Listeners will come away with a clearer framework for managing emerging AI risks while enabling innovation with greater confidence.
Related Resources & Stay Connected
Learn More About OneTrust: Discover how OneTrust helps organizations manage risk, compliance, privacy, data, and AI governance while building greater trust across the enterprise.
OneTrust
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.
ISACA Podcast Library
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
ISACA YouTube Channel
Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology. The New Rules of Governance: Achieving Continuous Compliance with Adaptive Identity
2026-09-03 | 48 mins.As AI shifts from a theoretical advantage to an operational reality, the race is on to define the rules of engagement. Yet, for enterprise leaders, the real dilemma isn’t just waiting for regulations to land—it’s realizing that static, point-in-time compliance is officially dead. To secure and govern a dynamic, AI-driven ecosystem, organizations must evolve from rigid access controls to a model of adaptive identity.
In this episode, ISACA’s Safia Kazi, Principal Research Analyst, Privacy, Research Development, speaks with Jeff Purrington, Identity Strategist at SailPoint, to cut through the compliance noise and explore how adaptive identity can act as a real-time control plane—allowing organizations to continuously assess risk, automate governance, and secure both human and non-human identities.
Tune in to discover:
The shift to adaptive governance: How to move from static, periodic compliance reviews to a continuous, real-time adaptive identity model that automatically aligns with evolving global regulations.
Securing the non-human frontier: Proven strategies to apply adaptive controls to AI agents, machine identities, and automated service accounts, ensuring they remain compliant and visible.
Audit-ready automation: Actionable steps to leverage identity security as a dynamic guardrail, allowing your organization to innovate rapidly with AI while staying continuously audit-ready.
Related Resources & Stay Connected
Learn More About SailPoint: Discover how SailPoint helps organizations manage and secure identities, strengthen governance, and navigate the evolving demands of AI-driven enterprises.
SailPoint
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.
ISACA Podcast Library
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
ISACA YouTube Channel
Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology.- Containers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production.
In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most.
Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot.
Related Resources & Stay Connected
Explore DockSec on GitHub: Review the open-source DockSec project, explore its features, and learn how it uses AI to identify insecure Dockerfile patterns, embedded secrets, and container misconfigurations.
https://github.com/OWASP/DockSec
Learn More About DockSec from OWASP: Discover more about the DockSec project, its approach to container security, and how it helps developers identify risks that traditional signature-based scanners may miss.
https://owasp.org/DockSec/
Connect with Advait Patel on LinkedIn: Follow Advait for insights on container security, cloud infrastructure, site reliability engineering, Docker, and AI-powered security.
https://www.linkedin.com/in/advaitpatel93/
Explore Advait Patel’s GitHub: View Advait’s open-source projects, technical work, and contributions to cloud and container security.
https://github.com/advaitpatel
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
https://www.youtube.com/@IsacaHq
Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology. - As threats have evolved, so too has the approach to modern identity security. A privilege-centric approach must be adopted to address this evolution. Identity management for all accounts within an organization must mature to meet the demands of the cloud, nonhuman identities (NHIs), agentic AI, and modern attack vectors. Your strategy must now manage and mitigate not only traditional privileged access (root and administrator accounts), but also attacks targeting modern identities with paths to privileged access.
These paths to privilege remain one of the most valuable targets for cybercriminals because many organizations continue to defend their environments with fragmented or siloed security strategies and solutions. Security gaps and risks exist across endpoints, cloud environments, SaaS applications, third-party access, and now agentic AI and NHIs, making today's threat landscape more complex than ever.
In this episode, ISACA's Donnie Carpenter, Principal, Information Security and Professional Practices Research Development, speaks with Christopher Hills, Chief Security Strategist at BeyondTrust, about the evolution of identity security and why organizations must rethink how they protect privileged access in today's rapidly changing technology landscape.
Related Resources & Stay Connected
Learn more about BeyondTrust: Discover how BeyondTrust helps organizations protect identities, manage privileged access, and reduce cyber risk across cloud, endpoint, SaaS, and hybrid environments.
BeyondTrust
Additional Resources from BeyondTrust:
Shadow AI Governance: How to Detect Shadow AI Governance
Microsoft Vulnerability Report: Microsoft Vulnerability Report
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging technology insights.
ISACA Podcast Library
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
ISACA YouTube Channel
Don't forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, and risk. - FedRAMP 20x is redefining what federal compliance looks like. Designed to modernize the authorization process, this bold initiative is moving cybersecurity governance toward automation while reducing the lengthy timelines and documentation burdens that have traditionally defined FedRAMP.
Join host Safia Kazi as she speaks with Jake Bernardes, CISO at Anecdotes, about what FedRAMP 20x is, why it matters, and how this transformation will reshape governance, risk, and compliance (GRC) automation. Together, they explore what organizations can expect as federal compliance evolves and what the changes mean for enterprise customers navigating the future of cybersecurity governance.
Related Resources & Stay Connected
Learn more about Anecdotes: Discover how Anecdotes is helping organizations transform governance, risk, and compliance with AI-powered automation, continuous monitoring, and audit-grade data that enables faster, smarter, and more scalable GRC programs. https://www.anecdotes.ai/
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq
Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.
More Business podcasts
Trending Business podcasts
About ISACA Podcast
The ISACA Podcast gives you insight into the latest regulations, trends and threats experienced by information systems auditors and governance and security professionals. Whether you are beginning your career or have decades of experience, the ISACA Podcast can help you be better equipped to address industry challenges and embrace opportunities.
Podcast websiteListen to ISACA Podcast, A Bit of Optimism and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


ISACA Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.


























