Absolute AppSec

Episode 309 - w/ Nathan Hunstad - Compliance, Security Governance


Listen Later

In this episode of Absolute AppSec, Nathan Hunstad, Director of Security at Vanta, discusses the intersection of security policy, governance, and technical defense. Drawing on his unique background in political science and the Minnesota state legislature, Hunstad argues that policy acts as the essential "conductor" for an organization's security tools. A major theme of the conversation is the challenge of compliance for startups, with the group advising founders to prioritize business survival and basic security hygiene—like password managers and IAM—before pursuing intensive certifications like SOC 2. The discussion also explores how AI is accelerating both development velocity and the ability to automate tedious security questionnaires. Furthermore, Hunstad contrasts the security posture of modern, cloud-native startups against legacy enterprises, noting that older organizations often struggle with "dark corners" of un-inventoried, vulnerable legacy tech. The episode concludes with a critique of outdated authentication standards, specifically advocating for the removal of mandatory password rotation in favor of NIST-aligned, phishing-resistant MFA.
...more
View all episodesView all episodes
Download on the App Store

Absolute AppSecBy Ken Johnson and Seth Law

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

17 ratings


More shows like Absolute AppSec

View all
Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,764 Listeners

Planet Money by NPR

Planet Money

30,690 Listeners

Risky Business by Risky Business Media

Risky Business

372 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,091 Listeners

Application Security Weekly (Audio) by Security Weekly Productions

Application Security Weekly (Audio)

12 Listeners