
Hosted by Justin Beals
Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance.
255 episodes · publishes weekly · latest 2026-06-16 · ~48 min/episode
Rank
#275
Substance
79.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#275 of 6182
Substance
Top 4%
outscores 96% of the index
Secure Talk Podcast ranks #275 on The B2B Podcast Index with a substance score of 79.0 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and originality. Dorian Cougias is a highly credible operator with 20+ patents in compliance automation, founded and scaled Unified Compliance Framework (world's largest GRC database), military background in Signal Intelligence, and is currently building infrastructure at the intersection of compliance and AI through MoxyWolf. His direct involvement with DCSA, O*NET, open standards bodies, and named partnerships demonstrates substantive operator status, not thought-leadership theater. His willingness to acknowledge mistakes and engage in harsh critique (firing people for communication failures, selling shares back for $1 to escape PE dynamics) adds authenticity.
Averaged across 2 recently scored episodes, with cited evidence.
The episode contains substantial, non-obvious ideas about compliance infrastructure - particularly the connection between Bloom's Taxonomy and cognitive load in compliance work, the three-silo problem in compliance (regulators, implementers, auditors), and the role of job mapping via O*NET. However, significant portions involve relationship-building, personal anecdotes (the Gartner booth meeting, the Directus platform failure), and general team-building philosophy that dilute the density of immediately actionable insights for operators.
“The compliance industry is built on three separate communities that rarely talk to each other. There are the regulators writing the 'thou shalts' - the laws and frameworks. There are the technical implementation people writing the STIGs and the CIS benchmarks - the 'how do I.' And there are the auditors and assessors deciding 'did I.'”
“If you assign the wrong person to the wrong cognitive task, the work doesn't get done. And no amount of technology will save you.”
The framing of CMMC failures as an HR/job-assignment problem rather than purely technical is relatively fresh and contrarian to typical compliance discourse. The connection to Bloom's Taxonomy, O*NET mapping, and the explicit articulation of a three-silo divide in compliance governance shows first-principles thinking. However, the core ideas (semantic harmonization across frameworks, dictionary/lexicon work) are extensions of prior work Cougias did at Unified Compliance Framework, so it's refinement rather than entirely new territory.
“People are failing CMMC because it's an HR problem. The wrong people are in charge, or nobody is in charge, or the system was stood up by someone who didn't understand what was being asked of them.”
“Bloom's is perfect for that. And so you have to tie it together... there's a real difference between asking someone to remember a procedure and asking them to evaluate, prioritize, and modify a control.”
Dorian Cougias is a highly credible operator with 20+ patents in compliance automation, founded and scaled Unified Compliance Framework (world's largest GRC database), military background in Signal Intelligence, and is currently building infrastructure at the intersection of compliance and AI through MoxyWolf. His direct involvement with DCSA, O*NET, open standards bodies, and named partnerships demonstrates substantive operator status, not thought-leadership theater. His willingness to acknowledge mistakes and engage in harsh critique (firing people for communication failures, selling shares back for $1 to escape PE dynamics) adds authenticity.
“Dorian Cougias has spent over two decades at the intersection of security compliance and applied technology... built what became the world's largest GRC database, accumulating 20+ patents in compliance automation along the way.”
“I have 20 plus patent books of patents, you know, with a couple of hundred claims. And so I've been around the block once or twice. And I can tell when somebody knows what they're talking about because I'll throw some words in and see if they know them.”
The episode opens with highly specific regulatory failures (Raytheon $8.4M, Penn State $1.25M, Georgia Tech $875K settlements), and Cougias mentions concrete details (550+ STIGs, 8,000+ regulatory guidelines, 80+ federal partners feeding data, one-tenth pricing of StigViewer). However, much of the mid-conversation lacks concrete metrics: the discussion of Bloom's Taxonomy, O*NET integration, and AI task assignment remains largely conceptual without Named examples of organizations, failure rates, or measured outcomes from the proposed solutions. The call with the manufacturer is mentioned but sparse on details.
“In May of 2025, Raytheon and RTX Corporation paid $8.4 million to settle False Claims Act allegations that they violated cybersecurity requirements in Department of Defense contracts... Penn State settled for $1.25 million. Georgia Tech settled for $875,000.”
“We're releasing native STIGs in JSON format with an API gateway... every organization needs at least 50 or so Stigs... we're not gonna put a limit on how many STIGs an organization can consume. We're just gonna say, here's the STIG library. 550”
Justin Beals asks solid, substantive questions that push Cougias toward specificity (e.g., 'have you identified what in your existing infrastructure doesn't meet CMMC requirements,' the O*NET mapping question). However, the host frequently allows tangential personal stories and relationship-building to consume airtime without sharp follow-ups (e.g., the Directus platform anecdote, the Gartner booth origin story, the PE firm critique at UCF). Beals could have probed deeper into the AI automation criteria, the O*NET-to-RACI mapping methodology, or concrete case studies of the job-assignment fix working. The conversation often feels like two aligned insiders speaking rather than an interview extracting maximum clarity.
“have you identified what in your existing IT infrastructure doesn't meet the CMMC requirements that would force you to go and adopt this other platform? And these guys were manufacturers, so they hadn't been around the software space as much as you and I have. And they were like, well, no, not really.”
“Let's talk a little bit about Onet and the job applicability to the activity.”
First period on the Index - history builds from here.
2 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/secure-talk-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/secure-talk-podcast/badge.svg" alt="Ranked #35 on The B2B Podcast Index" width="360" height="136" />
</a>Track Secure Talk Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.