#1748404: See, Our Compliance Framework Includes a Checkbox for Resilience

Description: If you want to keep the business up and running with as few fines as possible, focus on compliance first. But can we double up on that effort? Is there any way to build resilience first and let compliance follow as proof of the work already done?

This week's episode is hosted by me, David Spark, producer of CISO Series and Mike Johnson, CISO, Rivian. Joining us is our sponsored guest, Khushboo Kashyap, senior director of GRC at Vanta.

Running up the token meter
Every AI prompt hides a tab most employees can't see. It's token usage. Barbara Roos of Starboard Collectives raised this concern, arguing employees burn tokens with zero sense of what they cost. NVIDIA CEO Jensen Huang reportedly wants his engineers spending big on tokens. He sees spending on tokens as the sign of productivity. Is there a one-to-one correlation? Maybe it's time for a little token literacy? Are we trying to manage runaway costs, or rather understand how efficiently we're using AI? We're all still experimenting with AI, so there's inevitably going to be some token waste. Measuring ROI and building token awareness aren't the same conversation. We're still in the early days of AI adoption. Experimentation itself is the return. Watching how people use AI can look a lot like micromanagement with a budget attached. The real test of an AI strategy isn't whether staff understand tokens. It's whether leaders are managing outcomes instead of prompt efficiency.

Some risks resist a price tag
It's become almost cliché to say CISOs need to tie every risk to dollars, downtime, or data loss. William McBorrough CISO at MCGlobalTech, pushes back on that formula. How do you show things like compliance delaying market entry or eroded customer trust from a security incident on a balance sheet? Anchoring a risk to a promise the CEO already made lands harder than a quantification that invites endless questioning of the math behind it.

Resilience isn't a vacation policy
Security team resilience gets treated like a wellness slogan, but the alternative is burnout. Throwing more PTO or more headcount at a stretched team rarely fixes anything. The strain keeps compounding regardless of what sits on the calendar. AI adoption hasn't lightened the load either. More non-human identities to manage, more agentic sprawl to track, and an ever-burgeoning cognitive load on everyone. Real resilience means building structures that actually pull work off the pile, not stacking more responsibility onto the same headcount and calling it growth.

Compliance is the wrong finish line
Security outcomes follow whatever gets incentivized, regardless of intention. Joshua Copeland of Crescendo frames the attitude of "compliance first spending" as a security problem. But the roots of the issue run upstream to that of executive decision-making. Compliance spending isn't executives picking paperwork over protection. It's the baseline that keeps the business running at all. Whatever's left over goes toward securing the environment. Regulators and insurers set those incentives long before executives get a vote. The challenge is to flip the order: build real resilience first, so compliance stops being the goal and becomes the proof of the work already done.

Listen to the full episode on our blog or your favorite podcast app, where you can read the entire transcript. If you haven't subscribed to the CISO Series Podcast via your favorite podcast app, please do so now. Listen to the full episode here.
More info: https://www.linkedin.com/pulse/see-our-compliance-framework-includes-checkbox-resilience-wn5pc

Date added Aug. 4, 2026, 9:31 p.m.
Source LinkedIn
Subjects
  • Compliance regulations / Ethics - Various
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Security Management/Strategic Security/ROI/ROSI - CISO and Higher Level