Full Metal Packet Cybersecurity Podcast

ISO 27001 Compliance vs Security: What CISOs Must Fix in 2026


Listen Later

What is the difference between ISO 27001 compliance and operational security? John Verry explains compliance theater, shadow AI, and the role of ISO 42001 and the EU AI Act.

Security leaders will learn how to operationalize controls, inventory AI use, and govern agentic systems without adding unnecessary GRC complexity.

John Verry is the Managing Director at CBIZ Cybersecurity, ISO 27001 certified lead auditor since 2006, and has guided hundreds of organizations through ISO 27001, SOC 2, CMMC, FedRAMP, and HITRUST. He has seen firsthand what separates organizations that get genuinely secure from those that just collect certifications.

John explains:

◼ Why you can be fully compliant and completely insecure at the same time

◼ Why operationalizing your security program inside tools your team already uses matters more than buying another GRC platform

◼ How 65% of SaaS platforms now have AI built in and why most organizations have no inventory of it

◼ Why the EU AI Act's August 2026 deadline is real and what organizations need to do now

◼ Why agentic AI shifts the risk from hallucination to autonomous business decisions made at scale without a human in the loop

Timestamps

(00:00) Introduction

(06:27) Meet John Verry: Managing Director at CBiz Cybersecurity

(07:47) What compliance theater actually means and why it matters

(09:34) Security is a journey, compliance is a destination

(12:30) The most common mistakes companies make after getting certified

(15:07) What it actually takes to operationalize a security program

(17:34) The merchants of complexity problem and why less tooling wins

(20:50) Third party risk management and the hidden operational debt of every new vendor

(22:19) What shadow AI is and why most organizations still do not know they are using it

(28:21) How to balance moving fast on AI with slow-moving compliance frameworks

(31:40) Why ISO 27001 updates slowly and why that might actually be a good thing

(36:41) How to risk model different types of AI from Grammarly to agentic systems

(40:14) Why shadow AI is lower risk than deeply integrated AI but still dangerous

(43:29) Sycophantic AI behavior, what causes it, and why it creates real danger

(52:29) AI coding AI, the hard takeoff, and the model collapse problem

(54:24) EU AI Act deadlines, ISO 42001, and why AI compliance urgency is now

(58:44) How ISO 42001 works as an extension of ISO 27001

(01:01:27) When auditors do not understand AI governance and certifications become theater

(01:02:28) The main blocker stopping CISOs from escaping compliance theater

(01:05:41) The next 12 to 18 months: why the era of agentic AI is already here

(01:07:48) Closing thoughts: What should actually scare every CISO right now

Connect with John Verry on LinkedIn

https://www.linkedin.com/in/jverry/

Hosts ⬇️

Alex: https://www.linkedin.com/in/alex-paguis-53a21815/

Yegor: https://www.linkedin.com/in/yegor-sak-725330b2/

Powered by Control D

...more
View all episodesView all episodes
Download on the App Store

Full Metal Packet Cybersecurity PodcastBy Control D