Why Don't You Tell Me Which Metrics Sound Most Impressive?
Jul 28, 2026 · 48m
Summary
Hosts David Spark and Andy Ellis join guest Pavi Ramamurthy to critique vanity metrics, SIM failures, and the Delve audit scandal. They discuss the pitfalls of checkbox compliance, the futility of "I told you so" risk logs, and the need to redesign systems rather than blame human error. The episode concludes with a debate on when AI agents will gain trust for autonomous purchasing.
Topics discussed
Introduction and guest welcome
Andy's story about destroying minimalist art
The problem with vanity metrics in security
Reporting meaningful metrics to the board
Critique of phishing simulation campaigns
Flaws in SOC 2 audits and TPRM questionnaires
Vendor risk management and incident response
Debate: Compliance vs. effective security training
The futility of checkbox security awareness
Risk registers and CISO job protection
AI governance and prompt injection risks
Reducing friction and eliminating passwords
Book plug and closing remarks
Listen ad-free on Castria