
Trust Issues
Hosted by Bruno Lecoq · BEMO
For decades, government contractors and regulated SMBs have been trapped inside compliance checkboxes - it's time for change. They’re on the lookout for real security solutions, and Trust Issues is where that conversation begins.
20 episodes · publishes weekly · latest 2026-06-23
Rank
#11
Substance
56.3
/ 100
Why it scores where it does
Trust Issues ranks #11 on The B2B Podcast Index with a substance score of 56.3 out of 100, scored across 4 recent episodes. It scores highest on guest caliber and insight density. Norris Cardin is a lead certified CMMC assessor and principal consultant with CISSP/CISA, years on both the implementation and auditing sides - a genuine hands-on practitioner directly relevant to the topic, not a thought-leader.
The five-dimension breakdown
Averaged across 4 recently scored episodes, with cited evidence.
Insight Density
11.3 / 20The opening ten minutes is a meandering career biography with low value, but the back half is dense with practical, non-obvious compliance insights (the four assessment phases, 'periodically' meaning no less than annual, the SSP being the thing assessed, Active Directory not being a system of record).
“What that's asking you to do is periodically, not every day”
“they define periodically as no less than annual”
Originality
10.5 / 20Offers genuinely practitioner-shaped framing rather than recycled compliance platitudes - the restaurant inspection analogy, the gym/marriage analogy for documenting controls, and the Active Directory 'system of record' critique are fresh interpretations for this niche.
“You've got a restaurant, you're building a restaurant. You don't have food yet”
“It's almost like you're, you're telling like your wife that you're committed to going to the gym”
Guest Caliber
13.0 / 20Norris Cardin is a lead certified CMMC assessor and principal consultant with CISSP/CISA, years on both the implementation and auditing sides - a genuine hands-on practitioner directly relevant to the topic, not a thought-leader.
“lead certified CMMC assessor and principal consultant for Centaur, working directly with defense contractors”
“I've been on the consulting side doing the gap assessments”
Specificity & Evidence
11.3 / 20Strong on named requirements, certifications, numbers and concrete failure scenarios (3.3.3 event review, 110 requirements/320 objectives, $6,000, time source mismatch on a new firewall), though several companies and templates are deliberately anonymized.
“pulled up 3.3.3 which is event review. Review and update logged events. 5 words”
“these 320 objectives. We need to be writing our”
Conversational Craft
10.3 / 20The hosts ask some genuinely useful clarifying questions and one sharp analogy to SOC Type 1/Type 2 history, but it's largely a collegial peer conversation with affirmations rather than probing pushback or productive disagreement.
“if I go to the SOC world... for the CMMC, when you go do the assessment, do you need to have X months prior”
“What percentage of organizations are doing the mock audit these days?”
Standout episodes
- The four phases of a CMMC assessment64
2026-06-16
- Treat AI agents like human employees60
2026-06-09
- 56
Rank over time
First period on the Index - history builds from here.
Episodes
4 scored on substance · 20 tracked in total.