Who’s on this one
Michael Ratemo — Principal Security Consultant, Cyber Security Simplified. Co-author of Cloud Auditing Best Practices (Packt), on auditing AWS, Azure and Google Cloud, and author of the LinkedIn Learning course Building and Auditing a Cyber Security Program. A regular speaker at RSA Conference, Cloud Security Alliance and the ISACA GRC Conference, he has spent his career on both sides of the audit — building security programs, then auditing them.
Sid Roper — VP of Customer Solutions, Compyl. 24 years in cybersecurity and GRC, spent replacing manual chaos with automated trust and scalable compliance.
Daniel Tangney — Host, GRC Radio.
Who should be in the room
- GRC and compliance managers — if you own the cloud controls inside your SOC 2 or ISO scope and have ever wondered what the auditor actually looked at, this is the session.
- CISOs and security leaders — the report says you passed. This is the half about what it does not say — and how to explain that to the board before an incident does.
- Cloud, platform and DevOps engineers — the people who make the changes the audit never sees.
Run of show
Forty-five minutes. Roughly 35 of conversation, 10 of your questions. No slides.
- What a clean report actually certifies — scope, sampling, and the day the auditor looked.
- Where the cloud drifts — the changes in AWS, Azure and GCP that happen between audits and never make it into evidence.
- How auditors sample cloud controls — and why the misconfiguration that causes the breach is rarely the one they picked.
- One control, four frameworks — mapping a single storage or identity control across SOC 2, ISO 27001, PCI and CIS without doing the work four times.
- Building the cloud audit plan — what to sample, how often, and what “continuous” has to mean in practice.
- The sentence for the board — what to say when someone asks whether the audit means you are secure.
- Live Q&A — open floor.
