
Justin Beals is the CEO and co-founder of Strike Graph, a company helping customers get through their cybersecurity audits. He’s a serial entrepreneur with expertise in AI, cybersecurity, and governance. He founded Strike Graph with the goal to make cybersecurity standards easy to understand and easily accessible. Tom Fox welcomes him to this week’s show to discuss cybersecurity, auditing, and building maturity within an organization.
SOC/SOC2 Audit
Justin explains to Tom the origins of SOC: it was created to ensure that third-party vendors who trade with public companies, and the public companies themselves, were implementing effective cybersecurity practices. SOC2 Audit is a cybersecurity standard that focuses on security within an organization in a number of ways including HR practices, code of conduct, and other compliance liability issues. SOC2 analysis is about how data is encrypted and how new codes get put on servers. “The achievement of something like a SOC2 represents two things: one is an organizational maturity and the second is an assessment of that maturity by an independent party,” Justin tells Tom.
Trust is Currency
Tom asks Justin to share a few tips for when hiring a SOC2 auditor and why it is necessary. “The selection of the right auditor is important strategically because you’re going to want to work with them for a while. Generally, you want to go back to the same auditor [because] it’s more efficient,” Justin responds. Auditors we are familiar with know our practices and can measure them well. He points out that buyers and investors will pick the more trusted company; a company that has done a SOC2 audit is preferred over a company that hasn’t. Trust is what drives them and is what will influence buyers’ decisions.
COVID-19 and What’s Next
Tom asks Justin to reflect on how the pandemic has affected Strike Graph. Justin remarks that his business was established during the pandemic and is a remote work organization. He adds that interest has grown due to the pandemic, and it helped build his company’s success. With the pandemic, certifications and audits are great tools that can help build trust with customers. Justin remarks that in the future, it’s going to be more commonplace to expect vendors to share any form of private information to achieve audits or certifications.
Resources
Justin Beals | LinkedIn | Twitter
StrikeGraph.com
Author: admin
In this Episode of the FCPA Compliance Report, I am joined by fan fav and now Hughes Hubbard & Reed partner Mike DeBernardis. We take a look back at some of the early pronouncements from the Biden Administration and consider where both enforcement and regulatory oversight may be headed into the rest of 2021. Highlights of this podcast include:
- What are the 3 top areas you and Hughes Hubbard are counseling clients to be aware of over the next few years?
- In addition to general areas the DOJ has signaled its interest in; other federal agencies are coming to life again. What should clients think about regarding expanded FTC, CFPB and CFTC oversight and enforcement?
- The pandemic changed the way many investigations are conducted. Other than Zoom interviews, did your substantive work really change in the areas of document review, background ETC?
- What about Board and senior management risk management issues. Has it changed or are these groups now focused on a broader set of risk management strategies?
- To the international arena. Are there any countries/regions you are watching more carefully than others in terms of ABC enforcement?
Resources
Mike DeBernardis on the HughesHubbard website
Mike DeBernardis on LinkedIn
In today’s edition of Sunday Book Review:
- Nuclear Folly: A History of the Cuban Missile Crisis by Serhil Plokhy
- Empire of Pain: The Secret History of the Sackler Dynasty by Patrick Radden Keefe
- Doom: The Politics of Catastrophe by Niall Ferguson
- Come Fly the World: The Jet-Age Story of the Women of Pan Am by Julia Cooke
Welcome to The Ethics Movement, special podcast series highlighting Converge21 The Workshop Edition. This podcast series will feature some of the speakers at the event. You can find out more information about the event and register here. In this podcast, I visit with Phil Knight, Senior Product Manager at Convercent who will help lead the discussion on the Workshop, Disclosure Automation is a Mindset. It Starts with Repeatable, Scalable Processes. In this podcast, we will lay the foundation for scaling your E&C program by building a repeatable process for conflict of interest management and why this is so important for the compliance professional.
Jay is moving this week so he is 000. Tom takes a solo look at this week’s stories top compliance and ethics stories which caught his interest on This Week in FCPA. He is joined by special guests Dave Lefort to talk about the upcoming Compliance Week 2021 and Matt Kelly on Alex Oh.
Stories
- Alex Oh resigns. Matt Kelly in Radical Compliance.
- What are 3 top BOD priorities? Maria Motes in CCI.
- Why compliance must understand business process. Mike Volkov in Corruption Crime and Compliance.
- Post pandemic business resiliance. Jim Deloach in CCI.
- What is location risk? Atul Vashistha in CCI.
- Investor due diligence on modern slavery. Subodh Mishra in the Havard Law School Forum on Corp Governance.
- ComEd as a wake up call. Vincent Wu in the Global AntiCorruption Blog.
- May is Internal Auditors Month. Navez Global’s Ethics and Compliance Matters Blog.
- German ups its AML game. Risk and Compliance Platform Europe.
- Want insight in WFH procrastion? Dick Cassin says look to writers, in the FCPA Blog.
Podcasts and Events
- Tom and Megan Dougherty are doing a special podcast series around The Falcon and The Winter Soldier, currently streaming on Disney+. Check out Episodes 1&2, Episode 3, Episode 4, Episode 5. Episode 6 drops next week.
- This month on The Compliance Life, Tom welcomes Jonathon Kellerman. In Episode 1, Jonathon discusses the path he took to compliance. In Episode 2, he talked about his early professional career in healthcare compliance consulting. In Episode 3, he moves to the CCO Chair. In Episode 4, Jonathon looks down the road for what’s next in compliance.
- Join K2 Integrity on 6 May 2021 for a webinar, presented in Spanish, “Reputational Due Diligence for Companies and Investment Firms.” The team will discuss scenarios and cases in which reputational due diligence helped uncover hidden areas of risk and opportunities for our clients. Learn more and register here.
- Join Tom and Jay at Converge21, the Workshop Edition, click here. Best of all, its free.
- Join Jay and Tom at Compliance Week 2021. For information and registration, click here. Listeners to this podcast can receive a discount of $200 by using the code PODCAST599 at check out.
- CCI releases a new eBook, The FCPA Year in Review by the Compliance Evangelist, Tom Fox. You can obtain a copy here. Best of all its available at no charge.
- Tom announces his latest book, The Compliance Handbook, 2nd edition is available for presale purchase. Use the code FOX25 and go here. The Compliance Handbook 2ndedition will be available in both print and eBook editions. This week on The Compliance Handbook podcast, Eric Young joins Tom for a deep dive into the role of internal controls in a best practices compliance program.
Tom Fox is the Voice of Compliance and can be reached at tfox@tfoxlaw.com. Jay Rosen is Mr. Monitor and can be reached at jrosen@affiliatedmonitors.com.
Welcome to The Ethics Movement, special podcast series highlighting Converge21 The Workshop Edition. This podcast series will feature some of the speakers at the event. You can find out more information about the event and register here. In this podcast, I visit with Tess Macapinlac, Privacy Associate at OneTrust who will help the discussion on the Workshop, From Fear to Enthusiasm: Embracing Data Privacy with Confidence. Do not let fear of the unknown stop you from tackling data privacy. We’ll show you exactly where your weak spots are. It might even be fun!
In today’s edition of Daily Compliance News:
- Disneyland reopening. (NYT)
- Oh out at SEC. (Radical Compliance)
- Biden and can-do unity. (Bloomberg)
- Farewell to AOL and YaHoo!? (WSJ)

Dheeraj Thimmaiah is Global Director of Ethics and Compliance, heading Compliance Analytics at AB InBev. He is data-driven and passionate about innovation. Dheeraj is dedicated to spending close time with AB InBev’s users and customers because even if you have the best tools, your organization will not get far without an audience. He joins Vince Walden to share insights about his role and work at AB InBev.
BrewRIGHT is AB InBev’s advanced data analytics program, which has 15 different apps and compliance workflows in 60 different countries. BrewRIGHT continuously monitors compliance (which has been especially useful during the pandemic), assists in managing investigations, and allocates resources effectively.
Dheeraj shares tips on how to get started on the analytics journey for compliance: ask yourself how you can control the uncertainties, identify the problems, and find a way to use technology as an enabler in building impact.
Resources
Dheeraj Thimmaiah on LinkedIn
AB-InBev.com