{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Signed","title":"Are Your Security Tools Actually Protecting You?","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/d2e53b10\"></iframe>","width":"100%","height":180,"duration":11908,"description":"Your security tool says you're protected. Most of the time nothing is lying to you on purpose. It's just reporting what it was configured to report, whether or not anyone ever checked if that setup was correct in the first place. \nZach Stewart, CISO and Director of IT at Steno, spends this conversation walking through exactly where that gap hides, and it's not only the tool. There's the BAA that only protects you if you configured it correctly, and most companies never click the button. The SOC 2 stamp that tells you someone ran a pen test, not that you're secure. An MDR service marketed as round the clock remediation that turns out to only detect, and a maturity score that gets handed to a board and answers a question nobody in the room actually asked. \nIt also covers the buying side of all of this: what it actually looks like to evaluate a vendor without falling for the slide deck, why nobody wants to buy secure web gateway until it's already saved them, and the exact moment a customer contract forces corporate owned devices with no plan in place. \nGo find out right now if your tool, and everything else you're trusting, is actually telling you the truth. \n\nWhere to Start\nYou're evaluating a new vendor and you're tired of getting a slide deck instead of the actual tool. → Jump to [49:20]\nA vendor passed every checkbox on paper, but something still feels off. → Jump to [1:17:36]\nYou just got a SOC 2 report from a new vendor and you're not sure what it actually tells you. → Jump to [1:05:18]\nYour BAA says you're HIPAA compliant, and you've never checked whether the tool is actually configured for it. → Jump to [1:08:35]\nYou're being sold on an MDR service, and you don't know if there's a real person on the other end at 2am. → Jump to [1:33:14]\nYou need the rest of leadership to take a risk seriously before it becomes an incident, not after. → Jump to [1:56:38]\nYour security budget looks fine on the spreadsheet, but nobody's checked if it's enough for what it's...","thumbnail_url":"https://img.transistorcdn.com/d8NGarPLhvklmJcOQEYdHcKCmSM85HfY2AEspyWoL-M/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NzJl/MzE1NTFmNzgzMjVk/NTdhOTc4ZGU2YWYx/Zjc5Ny5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}