Episode 220
Your Security Tool Says You're Protected. Is It Lying?
August 12, 2026 • 3 hrs 18 mins
Your security tool says you’re protected. Most of the time nothing is lying to you on purpose. It’s just reporting what it was configured to report, whether or not anyone ever checked if that setup was correct in the first place.
Zach Stewart, CISO and Director of IT at Steno, spends this conversation walking through exactly where that gap hides, and it’s not only the tool. There’s the BAA that only protects you if you configured it correctly, and most companies never click the button. The SOC 2 stamp that tells you someone ran a pen test, not that you’re secure. An MDR service marketed as round the clock remediation that turns out to only detect, and a maturity score that gets handed to a board and answers a question nobody in the room actually asked.
It also covers the buying side of all of this: what it actually looks like to evaluate a vendor without falling for the slide deck, why nobody wants to buy secure web gateway until it’s already saved them, and the exact moment a customer contract forces corporate owned devices with no plan in place.
Go find out right now if your tool, and everything else you’re trusting, is actually telling you the truth.
Find Your Situation
- You’re evaluating a new vendor and you’re tired of getting a slide deck instead of the actual tool. Jump to 49:20
- A vendor passed every checkbox on paper, but something still feels off. Jump to 1:17:36
- You just got a SOC 2 report from a new vendor and you’re not sure what it actually tells you. Jump to 1:05:18
- Your BAA says you’re HIPAA compliant, and you’ve never checked whether the tool is actually configured for it. Jump to 1:08:35
- You’re being sold on an MDR service, and you don’t know if there’s a real person on the other end at 2am. Jump to 1:33:14
- You need the rest of leadership to take a risk seriously before it becomes an incident, not after. Jump to 1:56:38
- Your security budget looks fine on the spreadsheet, but nobody’s checked if it’s enough for what it’s supposed to protect. Jump to 2:03:09
- Your continuity plan treats an outage and a breach as the same problem. They’re not, and that’s costing you. Jump to 2:06:30
- A customer just told you their contract requires corporate owned devices, and you don’t have a plan for that yet. Jump to 2:22:28
- You’re bringing a maturity score into your next board meeting, and you already know it’s not going to land. Jump to 2:28:39
- You’re about to consolidate onto one security platform, and you haven’t worked out what you’d be giving up to do it. Jump to 2:39:50
- You rolled out passkeys, and you’re still not sure if you actually replaced your passwords or just added a step. Jump to 2:48:24
- Nobody at your company can tell you what percentage of your applications actually sit behind single sign on. Jump to 2:57:47
- You’ve read a breach postmortem and thought, any one thing on this list would have stopped it. You don’t know if that’s true for you too. Jump to 3:07:02
Chapters
- 49:20 Show me the tool, not the slide deck
- 1:05:18 A new vendor says they’re secure because of SOC 2. What else to check
- 1:08:35 The HIPAA BAA loophole nobody reads closely enough
- 1:23:29 SSO can cost more than the product it’s attached to
- 1:33:14 The real math behind running your own SOC, and where MDR falls short
- 1:40:07 Test your backups. Actually test them
- 2:03:09 The company running its entire security budget at under a dollar per employee
- 2:06:30 Outage risk and breach risk need two different plans
- 2:22:28 When a customer contract forces corporate owned devices
- 2:28:39 Why a one to ten maturity score means nothing to your board
- 2:48:24 Passkeys are useful. Most companies deployed them wrong
- 2:57:47 The SSO coverage gap nobody’s counting
- 3:07:02 The breach where almost anything would have stopped it
What We Mentioned
- SOC 2, HIPAA, PCI, CMMC, and ISO 27001
- NIST CSF and NIST SP 800-171
- Google Workspace OAuth (Sign in with Google)
- Microsoft Entra, E5 and E7 security bundling
- Apple Business Manager and zero touch MDM enrollment
- MDR and SOC staffing models
About Zach Stewart
Zach Stewart is CISO and Director of IT at Steno, where he spends his days doing exactly what this show is about: buying technology in a market built for the people selling it, then fighting to get it funded and adopted inside his own company. Zach is someone ITBroker.com works with directly, which is part of why he was on the show.
LinkedIn: https://www.linkedin.com/in/zacharykstewart/ Company: https://steno.com
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast.
If you’re in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com. Buy tech without regret.
