The Security Strategist 22 September 2026 5 MIN

Preemptive by Design: Is GRC the New Front Line for Security?

“When an enterprise carries out its SOC 2 audit, most of them are not well prepared; it disrupts the business flow.”

Every CISO’s inbox is hot with this email at least once a year: the audit is four months away, and it's time to stop everything. 

As a result, progress comes to a halt, and a person then spends two weeks logging into 30 different consoles, taking screenshots in order to show that MFA has been turned on. After the audit is over, the evidence becomes invalid, and exactly twelve months later the same frantic situation begins all over again.

That is precisely the kind of situation that Jonathan Schipp, Senior Director of Product Management at Rapid7, aims to end, and it is the focus of the most recent episode of The Security Strategist podcast.

In this episode, host Richard Stiennon, Chief Research Analyst at IT-Harvest, is joined by Schipp to talk about the reason why governance, risk and compliance (GRC) is moving from being a yearly rush to becoming a continuous, API-driven element of security operations. They also address why AI is causing this change to happen more quickly than most GRC teams can keep up with.

“Compliance turns into something you have to put everything else aside for,” Schipp tells Stiennon. “When an enterprise carries out its SOC 2 audit, most of them are not well prepared; it disrupts the business flow.”

Why Compliance Drives Security?

Stiennon asks Schipp if regulation is increasing in both the United States and Europe, are CISOs gradually becoming compliance managers and if that change makes security better or worse.

Schipp says no, with a qualification. Frameworks such as CIS, NIST and PCI set out the fundamentals that enterprises are already having difficulty with: multi-factor authentication, keeping an inventory of assets and applying patches. This is because, "the basics are hard; it's a matter of people, process and technology all coming together". 

The issue is not the frameworks themselves but the fact that cybersecurity is seen as a cost centre everywhere except in the case of compliance. When it comes to compliance, it becomes a business enabler; essentially, without PCI DSS compliance, card payments cannot be processed.

"There is an opportunity for us to regard compliance as a means of achieving security rather than the other way around,” Schipp says, adding that we have it backwards.

Also Watch: Human-Led, AI-Driven: The Next Chapter of Security Operations

What Continuous Compliance Replaces

Rapid7 recently introduced CyberGRC, and the Rapid7 product lead makes use of it to illustrate what 'continuous compliance' means in practice. He also explains why it will not eliminate the need for annual audits entirely.

Although frameworks such as SOC 2 and ISO 27001 still require a point-in-time audit, it is the period between these audits that has changed. Rather than the assessor asking for a screenshot as proof that a control exists, the majority of current security and IT tools provide APIs which can automatically answer the same question. For instance, 'what is the list of users with MFA disabled?' as and when it is needed, rather than only once a year.

As Schipp points out, the more significant change is concerned with validation rather than merely with collection; if an administrator disables multi-factor authentication for a user to meet a business request, the continuous monitoring will immediately detect the deviation. They can record it in the risk register, rather than having it appear as a surprise finding eight months later.

"We always know what the configuration is; rather than having a screenshot show that this user is enabled but MFA is disabled, you can now simply ask the API," Schipp says. 

Also Watch: Is Your Attack Surface a Swiss Cheese? Solving Attack Surface Management (ASM) Challenges

Does AI Governance Break in GRC Before SOC?

Companies are adopting AI more quickly than governance teams can examine it. This is why Schipp says the resulting risks, such as shadow AI, data leakage, and ungoverned agents, reach the GRC department before they turn into a SOC incident.

He adds that we cannot deny it or stop all the ongoing workflow. Nor can we stop AI use, since there could be a serious impact on the enterprise’s competitiveness.

Are you enjoying the content so far?

His position is that the role of GRC is not to hinder the adoption of AI but to guide the enterprise through the risks rather than avoid them. This is why it’s necessary to put in place governance and monitoring measures in time so that the business does not fall behind its competitors. 

Now that Rapid7's GRC platform supports ISO/IEC 42001, the management system standard specific to AI, as well as the NIST AI Risk Management Framework, this reflects the fact that many of its about 11,000 customers are already asking for AI-specific controls.

Schipp tells Stiennon that AI can have vulnerabilities; it’s just software which uses a large language model (LLM), or machine learning, depending on the type of AI.

Throughout the episode, Schipp iterates that AI has not introduced a new kind of risk, but it has merely accelerated the existing one. Attackers continue to take advantage of misconfigurations and the absence of controls; most of the vulnerabilities that have been discovered are still not exploitable. 

Enterprises that are handling the situation most effectively are those which treat detection, exposure management and GRC as part of a single, integrated system rather than as three separate tools feeding into three separate backlogs.

Key Takeaways

  • Rapid7 launched CyberGRC to connect live security telemetry to compliance evidence
  • Continuous monitoring replaces manual screenshot evidence with API-based checks
  • SOC 2 and ISO 27001 still require annual audits; continuous monitoring closes the gaps between them
  • Roughly 1% of discovered vulnerabilities are actually exploitable, per Schipp
  • AI models are finding more vulnerabilities mainly by scanning source code faster
  • Automated exploitation attempts generate high log volume, making them detectable
  • Rapid7's GRC platform supports ISO/IEC 42001 and the NIST AI RMF
  • Rapid7 serves roughly 11,000 customers, many now requesting AI-specific controls
  • GRC's role is to move the business through AI risk, not block AI adoption
  • Boards typically have audit and risk committees but no dedicated security committee
  • Vulnerability risk should be classified by business impact, not treated as uniform
  • Basic controls — MFA, asset inventory, patching exploitable exposures — stop most attacks, AI-driven or not

Organizations around the globe rely on Rapid7 technology, services, and research to securely advance. The visibility, analytics, and automation delivered through our Insight cloud simplifies the complex and helps security teams reduce vulnerabilities, monitor for malicious behavior, investigate and shut down attacks, and automate routine tasks.