Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC

1:53:57
 
Share
 

Manage episode 505167697 series 3577687
Content provided by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.


Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC


Episode 16 of the Distilled Security Podcast is here!

In this episode, Justin, Joe, and Rick christen the new studio and dive into some of the trickiest challenges in measuring, reporting, and governing security programs. From maturity models to board reporting, the conversation unpacks how scoring systems can mislead, how to communicate bad news effectively, and why boards need more than just “checkbox” cyber expertise.

The team also explores the rise of vGRC (Virtual GRC) services—what they are, how they differ from vCISO offerings, and when organizations should consider fractional models. And of course, no episode would be complete without a pour: this week, a rich Woodford Reserve Double Double Oaked bourbon.


Topics Covered

  • New Studio Upgrade: Behind-the-scenes on mics, cameras, and why the couch had to go.

  • Measuring to the Score: The dangers of chasing maturity numbers instead of real security outcomes.

  • Scoping, Rubrics & Auditor Whim: Why assessments are subjective and how leadership often misunderstands the results.

  • Cultural Incentives: How bonuses, compliance checkboxes, and “auditor shopping” distort security reporting.

  • Prepping for New Tools: Setting expectations with leadership when visibility spikes after deploying monitoring or vulnerability tools.

  • Boards and Cybersecurity Expertise: Should cyber knowledge be mandated at the board level—or does it risk creating the illusion of safety?

  • Virtual GRC vs. vCISO: What fractional GRC services really deliver, how they differ from vCISO roles, and why naming clarity matters.

  • Bourbon Review: Woodford Reserve Double Double Oaked — syrupy, smooth, and perfect for a holiday pour.

Hosts

  • Justin Leapline
  • Joe Wynn
  • Rick Yocum

Connect with Us
🌐 Website: distilledsecuritypodcast.com
🐦 Twitter: @DisSecPod
📧 Email: [email protected]

  continue reading

17 episodes

Artwork
iconShare
 
Manage episode 505167697 series 3577687
Content provided by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Distilled Security, Justin Leapline, Joe Wynn, and Rick Yocum or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.


Episode 16: When Metrics Mislead: Security Scoring, Board Gaps, and vGRC


Episode 16 of the Distilled Security Podcast is here!

In this episode, Justin, Joe, and Rick christen the new studio and dive into some of the trickiest challenges in measuring, reporting, and governing security programs. From maturity models to board reporting, the conversation unpacks how scoring systems can mislead, how to communicate bad news effectively, and why boards need more than just “checkbox” cyber expertise.

The team also explores the rise of vGRC (Virtual GRC) services—what they are, how they differ from vCISO offerings, and when organizations should consider fractional models. And of course, no episode would be complete without a pour: this week, a rich Woodford Reserve Double Double Oaked bourbon.


Topics Covered

  • New Studio Upgrade: Behind-the-scenes on mics, cameras, and why the couch had to go.

  • Measuring to the Score: The dangers of chasing maturity numbers instead of real security outcomes.

  • Scoping, Rubrics & Auditor Whim: Why assessments are subjective and how leadership often misunderstands the results.

  • Cultural Incentives: How bonuses, compliance checkboxes, and “auditor shopping” distort security reporting.

  • Prepping for New Tools: Setting expectations with leadership when visibility spikes after deploying monitoring or vulnerability tools.

  • Boards and Cybersecurity Expertise: Should cyber knowledge be mandated at the board level—or does it risk creating the illusion of safety?

  • Virtual GRC vs. vCISO: What fractional GRC services really deliver, how they differ from vCISO roles, and why naming clarity matters.

  • Bourbon Review: Woodford Reserve Double Double Oaked — syrupy, smooth, and perfect for a holiday pour.

Hosts

  • Justin Leapline
  • Joe Wynn
  • Rick Yocum

Connect with Us
🌐 Website: distilledsecuritypodcast.com
🐦 Twitter: @DisSecPod
📧 Email: [email protected]

  continue reading

17 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play