
About this episode
In this episode of the Distilled Security Podcast, we break down the Delve scandal—flawed SOC 2 reports, copy-pasted content, and oversight failures that expose deeper issues in compliance-as-a-service. Joined by Matthew J. Schiavone, we examine auditor accountability, quality review gaps, and key differences between SOC 2 and ISO 27001.
We also cover what companies should demand from auditors, the role of automation, and whether this scandal will drive real change in the industry.
Topics Covered
- The Delve scandal—leaked reports, copy-pasted audits & pervasive deficiencies
- The AICPA peer review process & AC Corp's adverse findings
- SOC 2 vs ISO 27001—oversight models, witness audits & accreditation
- The incentive structure driving compliance to the bottom
- Compliance automation — what works, what doesn't & AI's real role
- What to ask your auditor before signing anything
- Trust centers — done right vs. compliance theater
- Is SOC 2 dead? What needs to change & who has to change it
Hosts
- Justin Leapline – @justinleapline
- Joe Wynn – @wynnjoe
- Rick Yocum – @rickyocum
Hosts
- Matthew J. Schiavone - (Sikich)
Connect with Us
- Website: distilledsecuritypodcast.com
- X: @DisSecPod
- Email: [email protected]
Get every episode summarized
Each time Distilled Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Distilled Security Podcast

Episode 24: 2 Years, 24 Episodes & The State of Security in the Age of AI
Distilled Security Podcast

Episode 22: Is AI Good for Security, CIRCIA Starts the Clock, and the M&A Proble...
Distilled Security Podcast

Episode 21: AI Notetakers Are Illegal, GRC Tools Are Lying, and ISO 42001 Change...
Distilled Security Podcast

Episode 20 : 2026 Kickoff: Security Resolutions, Key Deadlines, and Don’t Mislea...
Distilled Security Podcast