Get NIST-y cover art

Get NIST-y

Get NIST-y

Written by: Blacksmith InfoSec
Listen for free

About this listen

Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP. Each week, we'll dive into compliance topics based on real questions from our MSP partners and subscribers.Blacksmith InfoSec
Episodes
  • Continuous Compliance Isn’t a Product Feature
    Jan 20 2026

    Everyone’s selling “continuous compliance” right now. Cool. But what does that look like in a real company with real humans? Today we tackle this topic thanks to 2 related listener questions.

    Question 1: Is continuous compliance actually happening in smaller SOC 2 / ISO programs, or do we all still sprint before audits?

    Question 2: Our SOC 2 deadline is close and training completion is stuck at 20%. How do we fix this without turning into the Training Police?

    In this episode, we referenced some videos on social engineering. Here are some links to our favorites:

    • https://youtu.be/lc7scxvKQOo?si=DxCSbATtVNEsl8Vf
    • https://youtu.be/PWVN3Rq4gzw?si=InAvEbxQ-VrCya2y

    Want to get your own questions answered? Head on over to https://blacksmithinfosec.com/ask

    Show More Show Less
    22 mins
  • If Nothing’s Broken, Why Fix Security? Making Cyber Risk Visible
    Jan 13 2026

    If your systems are running and nothing bad has happened, how should leaders think about cyber risk?

    In this episode, we tackle two listener questions. Kevin, a COO in Phoenix, asks how business leaders should evaluate security risk when there has been no breach, outage, or audit failure to force the issue. Allison, an IT Director in Portland, wants to know how to show real progress in cybersecurity and compliance when success mostly looks like nothing going wrong.

    We break down how to think about cyber risk proactively, why progress often feels invisible, and how MSPs and business leaders can talk about security in a way that actually makes sense to executives.

    Have a security or compliance question you want us to cover? Submit it at blacksmithinfosec.com/ask.

    Show More Show Less
    21 mins
  • Compliance Predictions for 2026
    Jan 6 2026

    We're kicking off the 2026 season of Get NIST-y with some predictions about what's to come in the world of compliance and cybersecurity. At the end of year, we'll make sure to grade ourselves on how well we predicted things, too.


    Want to get your compliance or cybersecurity questions answered? Head over to https://blacksmithinfosec.com/ask

    Show More Show Less
    23 mins
No reviews yet