Why I’m Hosting the ICT Compliance Pod
A few months ago, the team at CNXTD approached me about hosting a new podcast focused on ICT compliance.
My first reaction was that it sounded interesting. My second was probably the more important one: there is a real need for this conversation. After nearly two decades working at the intersection of product security, certifications, and global regulatory compliance, this felt like a natural extension of the work I've been doing throughout my career.
I’ve spent much of my career working in the space where cybersecurity standards, government requirements, technology, and business realities collide. Common Criteria, FIPS 140, NESAS, the Cyber Resilience Act, FedRAMP, post-quantum cryptography — these can sound like highly specialized topics, and in many ways they are.
But the decisions being made around them have very real consequences for technology companies.
A new regulation can determine whether a product can be sold in a particular market. A change to a certification requirement can affect product architecture, engineering resources, release schedules, and millions of dollars in investment. And increasingly, companies aren't dealing with one requirement at a time. They're trying to understand how requirements across the United States, Europe, and other markets fit together — or don't.
That’s why I agreed to host the ICT Compliance Pod.
Getting the People in the Room
Having spent years working with vendors, laboratories, standards organizations, regulators, and government agencies, I've learned that every group sees a different part of the problem. My goal is to bring those perspectives together in a way that's useful for the organizations and people building products.
One of the things I’ve learned over the years is that some of the most useful conversations happen when you bring together people who see the same problem from very different perspectives.
Regulators see one part of the picture. Standards organizations see another. Labs and consultants see another. Technology companies — and the people actually responsible for building products that have to meet these requirements — see something else entirely.
I want the ICT Compliance Pod to bring those perspectives together.
The goal isn't simply to explain what a regulation or standard says. There are plenty of places to find that information.
I’m much more interested in what happens next.
What does this actually mean for companies trying to build and sell products? Where are organizations struggling? What are regulators trying to accomplish? Where are the unintended consequences? And what should companies be thinking about now rather than waiting until a deadline is staring them in the face?
Those are the conversations I want to have.
Yes, I Now Host Two Podcasts
For those who have been following Trust and Turbulence, don't worry. It isn't going anywhere.
The two podcasts serve different purposes.
Trust and Turbulence is mine. It gives me the freedom to explore a much broader set of questions around technology, trust, cybersecurity, leadership, and change — and to talk with people who may have nothing whatsoever to do with cybersecurity compliance as I did with Debra Woog.
The ICT Compliance Pod is much more focused. It's an industry podcast, produced by CNXTD, centered specifically on the rapidly changing ICT compliance ecosystem. The podcast also supports another mission that's important to me. CNXTD brings together the global cybersecurity compliance community through conferences like ICMC, ICCC, EU Cyber Acts . I'm excited that the podcast extends those conversations beyond the conference stage. As it evolves, you'll see me recording live interviews with attendees, speakers, and exhibitors, bringing even more voices from the community into the discussion.
For me, they're complementary.
Starting with CRA and Q-Day
For the premiere episode, we started with two subjects that demonstrate just how quickly this world is changing: the EU Cyber Resilience Act and post-quantum cryptography.
I had the opportunity to speak with experts from Red Alert Labs, ABI Research, AWS, and NIST about the approaching CRA deadlines, what companies should be doing to prepare, the transition to post-quantum cryptography, and the much-discussed arrival of “Q-Day.”
These aren't theoretical issues anymore.
The CRA is moving toward implementation. Organizations are making decisions today about products that will still be in the market when its requirements fully apply. At the same time, the transition to post-quantum cryptography raises questions about technology that may need to remain secure for years or even decades.
That makes this a particularly interesting time to be having these conversations.
And that's really why I said yes when CNXTD asked me to host the podcast.
After spending years working inside this ecosystem, I get to sit down with many of the people shaping the future of cybersecurity compliance, ask the questions I think matter, challenge assumptions when appropriate, and hopefully make a complicated and rapidly changing world a little easier to understand.
That sounds like a pretty good way to spend an hour.
Listen Now: