Compyl
Sponsored by:
The Conversation Starts in....
Days
Hours
Minutes
Seconds

Your Audit Was Clean. Your Cloud Wasn’t.

Who’s on this one

Michael Ratemo — Principal Security Consultant, Cyber Security Simplified. Co-author of Cloud Auditing Best Practices (Packt), on auditing AWS, Azure and Google Cloud, and author of the LinkedIn Learning course Building and Auditing a Cyber Security Program. A regular speaker at RSA Conference, Cloud Security Alliance and the ISACA GRC Conference, he has spent his career on both sides of the audit — building security programs, then auditing them.

Sid Roper — VP of Customer Solutions, Compyl. 24 years in cybersecurity and GRC, spent replacing manual chaos with automated trust and scalable compliance.

Daniel Tangney — Host, GRC Radio.

Who should be in the room

  • GRC and compliance managers — if you own the cloud controls inside your SOC 2 or ISO scope and have ever wondered what the auditor actually looked at, this is the session.
  • CISOs and security leaders — the report says you passed. This is the half about what it does not say — and how to explain that to the board before an incident does.
  • Cloud, platform and DevOps engineers — the people who make the changes the audit never sees.

Run of show

Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.

  • What a clean report actually certifies — scope, sampling, and the day the auditor looked.
  • Where the cloud drifts — the changes in AWS, Azure and GCP that happen between audits and never make it into evidence.
  • How auditors sample cloud controls — and why the misconfiguration that causes the breach is rarely the one they picked.
  • One control, four frameworks — mapping a single storage or identity control across SOC 2, ISO 27001, PCI and CIS without doing the work four times.
  • Building the cloud audit plan — what to sample, how often, and what “continuous” has to mean in practice.
  • The sentence for the board — what to say when someone asks whether the audit means you are secure.
  • Live Q&A — open floor.
When
October 28, 2026
Time
2:00 pm –
2:45 pm
Your Audit Was Clean. Your Cloud Wasn’t. — GRC Radio live webinar with Sid Roper and Michael Ratemo, October 28, 2026

We will cover:

  • Why a clean SOC 2 or ISO report tells you almost nothing about how your cloud is configured today
  • How auditors actually sample cloud controls — and why the misconfiguration that causes the breach is rarely the one they picked
  • The drift problem: what changes in AWS, Azure and GCP between one audit and the next
  • One control, four frameworks: mapping a single storage or identity control to SOC 2, ISO 27001, PCI and CIS at once
  • Building a cloud audit plan that samples what actually breaks
  • The sentence for the board: what “we passed” does and does not mean

"(Required)" indicates required fields

Name(Required)
Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies