DeepDive

Practice, at length.

A Speak to It™ term tells you what something is. This is where the same subject is worked through properly: what good looks like, what to require, how to evidence it, and where most teams get it wrong.

289 written, 1405 more commissioned. Free to read, because a common professional vocabulary should not depend on ability to pay.

Compliance

Assurance vs Validation

SOC 2 Provides Assurance. Your Specific Risk Requires Validation.

6 min read · 15 Sep 2026

Compliance

Audit Evidence Quality

Screenshot of MFA Enabled. One Role. Test Environment. Eleven Months Ago.

6 min read · 12 Sep 2026

Compliance

Audit Scope Limitations

Three Samples Passed. Forty-Five Were Not Tested. The Conclusion Was Effective.

7 min read · 10 Sep 2026

Compliance

Compliance Automation Gaps

Compliance Dashboard: Green. New Cloud Region Not Connected. New Auth System Not Integrated.

6 min read · 7 Sep 2026

Compliance

Compliance vs Security Gap

PCI-DSS Compliant. Breached Through an Out-of-Scope System. Both True.

6 min read · 5 Sep 2026

Compliance

Continuous Compliance Reality

All Controls Green. Friday Misconfiguration Detected Monday. Sixty-Three Hours.

6 min read · 2 Sep 2026

Compliance

Continuous Monitoring Gaps

Assessed Twelve Months Ago. Forty-Three Point Rating Drop Since. Nobody Noticed.

6 min read · 31 Aug 2026

Compliance

Contractual vs Actual Controls

The Contract Requires MFA. Nobody Has Verified It Is Enforced.

6 min read · 28 Aug 2026

Compliance

Control Duplication

Three Teams. Three Controls. All Doing the Same Thing. None Knowing About the Others.

6 min read · 26 Aug 2026

Compliance

Control Inheritance Misunderstandings

ISO 27001 Certified. The Certification Scope Does Not Cover Your Service.

6 min read · 23 Aug 2026

Compliance

Control Mapping Inconsistencies

One Control Mapped to Five Frameworks. The Mapping Accuracy Varies by Framework.

6 min read · 21 Aug 2026

Compliance

Control Testing Depth

No Critical Vulnerabilities Found. Internal Network Not in Scope. Neither Was the Cloud.

6 min read · 18 Aug 2026

Compliance

Control vs Implementation Gap

The Penetration Test Programme Exists. The Last Test Was Fourteen Months Ago.

6 min read · 16 Aug 2026

Compliance

Evidence vs Attestation

The Attestation Was Accurate for Two of Three Databases. One Was Different.

6 min read · 13 Aug 2026

Compliance

Exception Management Abuse

Forty-One Exceptions. Thirty-Seven Are Engineering Deferrals. Four Over a Year Old.

6 min read · 11 Aug 2026

Compliance

GRC Tooling Limitations

The GRC Platform Manages What You Put Into It. It Does Not Know What You Left Out.

7 min read · 8 Aug 2026

Compliance

Governance Accountability Gaps

RACI Matrix Exists. Nobody Made the 11pm Call. Nobody Read the Contract.

6 min read · 6 Aug 2026

Compliance

Governance Ownership Ambiguity

Three Teams Own the Vendor. None of Them Owned the Incident Response.

6 min read · 3 Aug 2026

Compliance

Policy vs Enforcement

Twelve-Character Policy. Eight-Character Configuration. Both Active Simultaneously.

6 min read · 1 Aug 2026

Compliance

Questionnaire Fatigue vs Real Risk

400 Questions. Three Weeks. The Specific Risk Was Never Asked About.

5 min read · 29 Jul 2026

Compliance

Regulatory Blind Spots

US Customer. US Vendor. Irish Data Storage. GDPR Applies. Was Never Assessed.

6 min read · 27 Jul 2026

Compliance

Regulatory Interpretation Gaps

Five Years From Collection. Five Years From Last Transaction. Both Claim Compliance.

5 min read · 24 Jul 2026

Compliance

Regulatory Overlap Confusion

HIPAA or PCI-DSS? Both. The More Stringent Requirement Applies.

6 min read · 22 Jul 2026

Compliance

Reporting vs Insight

Four Consistent Numbers. Six Months of Reports. Zero Decisions Informed.

6 min read · 19 Jul 2026

Compliance

Risk Acceptance Misuse

Accepted Three Years Ago. Still Accepted. Nobody Has Reviewed It.

6 min read · 17 Jul 2026

Compliance

Risk Appetite Misalignment

Risk Appetite: No Vendor Over Fifteen Percent. One Vendor at Forty-Two. Predates the Policy.

6 min read · 14 Jul 2026

Compliance

Risk Communication Gaps

The Risk Was Identified. It Was Documented. It Was Never Communicated to the People Who Could Have Done Something About It.

7 min read · 12 Jul 2026

Compliance

Risk Prioritisation Failures

Twelve High-Priority Items. One Matters Most. None Are Being Treated Differently.

6 min read · 9 Jul 2026

Compliance

Risk Quantification Challenges

Score of 47. Probability of Breach: Unknown. Financial Impact: Unknown.

6 min read · 7 Jul 2026

Compliance

Risk Register Accuracy

Ninety-Three Entries. Zero Closed in Eighteen Months. Not a Risk Picture. An Archive.

6 min read · 4 Jul 2026

Compliance

Risk Scoring Subjectivity

Same Evidence. Same Vendor. Score of 34. Score of 67. Both From Your Team.

6 min read · 2 Jul 2026

Compliance

SLA vs Enforcement

Four SLA Breaches in Eighteen Months. Four Service Credits Issued. Behaviour Unchanged.

6 min read · 29 Jun 2026

Compliance

Third-Party Audit Reliance

Big Four SOC 2. Clean Report. The Auditor's Mandate Was Not Your Risk.

6 min read · 27 Jun 2026

Compliance

Third-Party vs Fourth-Party Risk

Your Vendor Is Assessed. Their Subprocessor Processes Half Your Data. Unassessed.

6 min read · 24 Jun 2026

Compliance

Vendor Audit Rights Enforcement

Right-to-Audit: Three Years in the Contract. Three Years Never Exercised.

6 min read · 22 Jun 2026

Compliance

Vendor Control Drift

Assessed Two Years Ago. Sixty Percent Security Turnover Since. Drifting.

6 min read · 19 Jun 2026

Compliance

Vendor Reassessment Frequency

Assessed Eighteen Months Ago. Three Hundred Million More Records Since. Still Tier 2.

6 min read · 17 Jun 2026

Compliance

Vendor Risk Aggregation

Three Low-Risk Vendors. Same Cloud Provider. Same Dataset. Same Production Access. Not Low Risk.

6 min read · 14 Jun 2026

Compliance

Vendor Tiering Inaccuracies

Tier 3: Office Supplies. Also: Real-Time Warehouse System Integration. Both True.

6 min read · 12 Jun 2026