The ITSPmagazine Podcast

Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin

Episode Summary

The first CTO of the US Nuclear Weapons Program left government convinced that the checklist approach to audits was holding the whole industry back. At Black Hat USA 2026 he explains how compliance as code turns an 18-month authority to operate into something closer to 30 days, with a better risk posture on the other side.

Episode Notes

Why does compliance paperwork fall behind the systems it describes? Because the systems change faster than the documents. Travis Howerton points to cloud native technologies that spin up and down on demand, which makes describing infrastructure in paperwork something that goes out of date instantly. Add new regulation for third party risk, supply chain, zero trust, and privacy, and an approach that was already expensive and frustrating stops being fit for purpose.

RegScale answers that with compliance as code. The company went to NIST and helped write the standard that became OSCAL, the Open Security Controls Assessment Language, then built the capability for machines to attest to their own state using it. Paperwork starts writing itself, and CISOs get risk and compliance outcomes as a byproduct of operational excellence rather than as a separate project.

Is automating the evidence trail a shortcut? Travis Howerton argues the opposite. It prevents corner cutting, because the alternative is what he calls compliance theater. An old general he worked for described that as a mother-in-law visit, where you clean the house to a ridiculous standard, everybody goes through the dance, and the moment the visit ends the kids destroy the house again.

Where should a security team start automating? Start with what hurts. He tells people to think like a surgeon, who opens by asking the patient what is wrong, then work backwards from the pain. There is no easy button, and the honest starting point is the truth about how fast teams will need to react.

That pain usually maps to one of three business drivers. Cut cost, or shift the share of budget going to checklist compliance toward tools that buy down risk. Get real-time assurance. Or earn the reps and certs needed to sell into a market, whether that is FedRAMP for government work or PCI for card data. Compressing those timelines by 70 to 80 percent lets a company get to market faster and grow revenue.

The results Travis Howerton cites are specific. One large government agency is touting over $100 million in labor savings, and a Department of War customer with a 52-week end-to-end cycle has compressed it by 36 weeks using RegScale technology alongside other integrated tools. Having tripled, doubled, and doubled again over the last three years, RegScale stays focused on the largest and most complex organizations, with international markets and the energy sector on the horizon.

This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

GUEST

Travis Howerton, Co-Founder and CEO at RegScale
LinkedIn: https://www.linkedin.com/in/travishowerton/

RESOURCES

Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
RegScale: https://regscale.com
OSCAL, the Open Security Controls Assessment Language: https://pages.nist.gov/OSCAL/

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

travis howerton, regscale, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, compliance as code, continuous controls monitoring, oscal, grc engineering, fedramp, fisma, authority to operate, ai agents, risk management, cybersecurity compliance

Episode Transcription

Compliance Moves at the Speed of DevOps When Paperwork Writes Itself | A Brand Briefing at Black Hat USA 2026 with Travis Howerton, Co-Founder and CEO at RegScale | Hosted by Sean Martin


 

[00:00:00] Sean Martin: Travis,


 

[00:00:09] Travis Howerton: how's it going,


 

[00:00:10] Sean Martin: man? Good to see you.


 

[00:00:12] Travis Howerton: Thanks for having me.


 

[00:00:12] Sean Martin: We're we're in Vegas.


 

[00:00:13] Travis Howerton: Yeah, man.


 

[00:00:14] Sean Martin: Vegas, baby.


 

[00:00:15] Travis Howerton: Mm-hmm.


 

[00:00:16] Sean Martin: That's where all the good conversations happening.


 

[00:00:17] Travis Howerton: Absolutely.


 

[00:00:18] Sean Martin: Hacker Summer Camp. We're here at Black Hat USA 2026. Having a good week.


 

[00:00:24] Travis Howerton: I am honored to be here with you today.


 

[00:00:25] Sean Martin: Ah, pleasure to have you.


 

So we're gonna get all the insights and scoop on RegScale. Mm-hmm. And before we do that, maybe a few words about your role and your journey to the CEO of, of, uh, the company.


 

[00:00:38] Travis Howerton: Sure thing. So I'm Travis Howerton with the co-founder, CEO here at RegScale. Uh, by way of background, I'm an old national security guy.


 

Spent a couple decades serving my country in a variety of roles. Um, ended up as the first Chief Technology Officer of the US Nuclear Weapons Program. Got to run one of the, uh, most stringent security programs in the world, and, uh, get a feel for what that was like. Went to the private sector and [00:01:00] uh, uh, got a feel for that as well.


 

And kind of everywhere I went. I felt like the way we think about compliance and the checklist approach we use to audits, I thought wasn't serving as well as an industry. At the same time, we were watching these trends that were happening, these cloud native technologies that spin up and down, and the idea of describing things in paperwork that goes outta date instantly would go from expensive.


 

And frustrating to just stupid as a function of time, like it won't be fit for purpose anymore,


 

[00:01:29] Sean Martin: right?


 

[00:01:29] Travis Howerton: The same time we're just piling more and more regulations on for third party risk, for supply chain, for zero trust for privacy. And so something just had to change and we thought, well, how can we make.


 

Um, compliance move at the speed of your DevOps and your cloud programs. And so we, uh, worked on this compliance as code approach. We went to NIST and helped 'em write a standard that ultimately became OSCAL, the Open Security Controls Assessment Language started, uh, building a capability for machines to attest to their own state using that [00:02:00] standard.


 

Paperwork would write itself. CISOs could focus on operational excellence in cybersecurity and get a lot of their risk and compliance outcomes for free. Right? And so that was the RegScale story. With the rise of AI, we've been adding AI agents that do what humans do in the workflow. Um, I started as the CTO and one of the co-founders.


 

Um, and so I've described myself as a recovering CTO. So while I've been the CEO chair, I'm still a very technical founder and enjoy the engineering aspect of, uh, of running the company.


 

[00:02:29] Sean Martin: And let's, let's touch on that 'cause it clearly nuclear systems, network security, endpoint security, all the stuff you probably looked after.


 

Very, very technical.


 

[00:02:39] Travis Howerton: Yep.


 

[00:02:39] Sean Martin: But in the government, it's no, no secret that. Mm-hmm. Things take a while.


 

[00:02:43] Travis Howerton: Yes.


 

[00:02:44] Sean Martin: And uh, so how did you kind of wrestle with that? 'cause bringing in technologies and building your own and getting 'em all to work mm-hmm. Is a big effort.


 

[00:02:54] Travis Howerton: Absolutely. So like, there's a couple reasons that government's slow and it's not because.


 

They've got lazy [00:03:00] people or any of the stereotypes you hear. Most of the government people I worked with were patriots. They worked hard. They just worked in a system that wasn't very well optimized. Um, you got a dysfunctional congress who can't ever pass a budget, so that makes their life hard. And then once you do get a budget, you gotta buy it.


 

That takes forever with all the rules they gotta deal with. And then the last part is before you can even use it, you gotta go through all these risk and compliance check boxes, uh, in the FISMA world, NIST SP 800-53, authority to operate. That takes forever. Um, I can't fix Congress. I don't know that much about procurement, but I know a lot about the last part.


 

Right? And so that last mile problem is the part that we're, we're really focused on helping with and trying to compress 18 month timelines down to 90 days. 30 days, or even less for customers, right? Um, while actually getting better security on the other. Yeah.


 

[00:03:48] Sean Martin: And it's not about, and assume mm-hmm. It's not about cutting corners.


 

[00:03:52] Travis Howerton: Yep.


 

[00:03:53] Sean Martin: Right. It's just having better insight and, and the ability to manage that stuff. Maybe talk about how that works.


 

[00:03:58] Travis Howerton: It's actually prevents you from being [00:04:00] able to cut corners.


 

[00:04:01] Sean Martin: Ah, right.


 

[00:04:01] Travis Howerton: So a lot of what the old school approach to us is what I call compliance theater. Um, or like an old general I worked for, described it as a mother-in-law visit.


 

You know, you clean the house to a ridiculous standard. You pretend you always live this way. Everybody goes through the dance and then as soon as they leave, the kids destroy your house again. Right? A lot of cyber's kinda like that. Um, what we wanna get out of is quit polishing paperwork to get to security at a point in time, and let's be continuously secure.


 

Let's put in place the good GRC engineering so that we know our controls are in place. Everything's locked down, everything's in the state, we expect it to be, and let's. Just let the paperwork ride itself. So let's get rid of this high cost, low value activity, shift that into engineering, which is where sort of the rubber meets the road and sort of authority these attacks.


 

And we think that shift is good for the whole industry.


 

[00:04:50] Sean Martin: So let's talk about the engineering 'cause I think. Well, I think everybody wants the easy button.


 

[00:04:56] Travis Howerton: Yep.


 

[00:04:56] Sean Martin: Right? I mean, just buy off the shelf stuff.


 

[00:04:59] Travis Howerton: Mm-hmm.


 

[00:04:59] Sean Martin: Put it [00:05:00] in place and


 

[00:05:00] Travis Howerton: Yep.


 

[00:05:01] Sean Martin: Off I go. I'm the SOC 2 or I'm a Yep. FISMA or the FedRAMP or whatever it is, right.


 

We're trying to achieve.


 

[00:05:07] Travis Howerton: Mm-hmm.


 

[00:05:07] Sean Martin: Um, the realities of. Of the world that we operate in. Yep. And the need for engineering, what does that look like for you and your team?


 

[00:05:15] Travis Howerton: Yeah, it's uh, I'd say there's sort of levels to it. Like there's no such thing as an easy button. Like I hate vendors who say, you just buy us and we do everything, and you're good.


 

Like, that's not the reality. Mm-hmm. What I'd say is the best plan to start with the truth. The truth is you're gonna have to react faster. AI's gonna compress timelines for us. Um, this old school, check it once a year, once every three years, manually approached with auditors to check a box, to maintain whatever rep and cert you want your SOC 2, whatever it may be.


 

Um, won't allow you to survive in the future. So what you're gonna need is actual real world security. So you gotta change that mindset from checklist compliance to more GRC engineering excellence. Um, so it's really that, that shift that we're seeing and [00:06:00] there's levels to it. Some just need a SOC 2, it's much easier to make that shift if you're dealing with 30, 40 controls.


 

And if you're dealing with like a FedRAMP High or a DOD system, like. So there's gonna be levels and grads to this. Um, but I just tell people to think like a surgeon, like surgeons, when you go in, they ask you what's wrong with you, what hurts, right? Just start with the things that are hurting you the most.


 

Start automating there and eventually, like you'll get into a healthy state. Okay. And so if you can kind of work backwards from the pain is a good way of thinking about like, where do I start? How do I get started in automating? 'cause it's gonna be a journey. You're gonna need platforms that help you along the way on that journey.


 

But there isn't an easy button to it, unfortunately. It, it just requires, uh, engineering excellence end to end and how you do these things.


 

[00:06:46] Sean Martin: So let's, let's pull, uh, a little bit on this pain. Point.


 

[00:06:50] Travis Howerton: Mm-hmm.


 

[00:06:51] Sean Martin: Pun intended. Um, certainly if, if you're feeling pain


 

[00:06:56] Travis Howerton: mm-hmm.


 

[00:06:57] Sean Martin: You might know where to look. Maybe not. [00:07:00]


 

[00:07:00] Travis Howerton: Yep.


 

[00:07:00] Sean Martin: Right. My back hurts. Well, where, what, what's the, where my knee hurts? What's the causing? Mm-hmm. It could be a nerve in the back.


 

[00:07:06] Travis Howerton: Yep.


 

[00:07:06] Sean Martin: Um, also, you may not feel any pain. Yep. Maybe something going on still. Mm-hmm. So how do you help organizations kind of. And there may be other scenarios you wanna touch on, but uncover the, the stuff that hurts and finding the source of it.


 

Mm-hmm. And maybe uncover things that,


 

[00:07:23] Travis Howerton: yeah.


 

[00:07:23] Sean Martin: May not hurt yet, but down the road they might do a problem.


 

[00:07:26] Travis Howerton: Yeah. Typically we do some discovery with 'em and try to meet 'em where they are. There's always some overlap about. What hurts? It's typically one of a couple things, like the things cost too much and they're trying to reduce the cost, or they're not trying to reduce cost overall in security, but they're trying to change the proportion of the budget.


 

That goes to checklist compliance, so they can buy better tools and other things that actually buy down risk. So sometimes it's a cost equation, ROI, and we can help 'em with business case and thinking through that. Other cases, it's more the assurance layer. What they want is real time assurance to [00:08:00] drive risk down.


 

So that's sort of the, the second factor. So if that tends to be what drives most of the CISOs we talk to. Right. And then the third one is, um, more of a business driver. You need certain reps and certs to do business in markets. If you wanna sell to the government, you need FedRAMP. If you are gonna process credit card data, you're gonna need PCI.


 

There's a variety of these that you need. If we can compress those timelines by 70, 80% for you, then you can get to market faster and grow revenue. Right? So they're either looking to cut costs, reduce risk, or grow revenue. It tends to be the three value drivers, and it's dependent on each customer and sort of what their specific use case is.


 

[00:08:36] Sean Martin: And so I wanna be slimmer and stronger. Yeah. And more nimble.


 

[00:08:40] Travis Howerton: Mm-hmm.


 

[00:08:41] Sean Martin: Common thread across. Those probably eat healthy.


 

[00:08:44] Travis Howerton: Yeah.


 

[00:08:45] Sean Martin: Go to the gym. Yep. So there's probably some standard things that you


 

[00:08:49] Travis Howerton: mm-hmm.


 

[00:08:49] Sean Martin: Help organizations with. How do you, what's, what's a conversation sound like with the CISO?


 

[00:08:54] Travis Howerton: Mm-hmm.


 

[00:08:54] Sean Martin: Such that they can then translate that into conversation with their executive leadership team, perhaps the [00:09:00] board if, uh, their


 

[00:09:02] Travis Howerton: Yeah.


 

[00:09:02] Sean Martin: Governed by one, I guess.


 

[00:09:03] Travis Howerton: Yeah, we just try to set 'em up for success. Like, if that's the outcome you need, let's work backwards from it and let's put you, um, technology in place that's built off best practices. So one of the things we pride ourselves on at RegScale is we've got just some of the world's best SMEs in some of these areas.


 

And we built it to just work outta the box. So rather than sort of a choose your own adventure, like some of the Gen 1 GRCs, where long implementations build a lot of snowflake factories, they're very brittle, very expensive to maintain. Most of our customers are saying, look, you guys are the experts.


 

Just give us something that's gonna work, that gets it done faster, that gets it done cheaper, and leaves me in a better place than where I started. And so we can work backwards from that, but it's some common sense things like if you are gonna have multiple regulations, let's get you on sort of a common control mapping architecture that we have in place.


 

All that's built as code. Now let's do some automated evidence collection so you can get your assurance posture up. Let's start validating that. [00:10:00] Let's connect to the telemetry you already have. So the paperwork can largely start writing itself. Then let's figure out where you don't have enough humans to do the things you want to do, and let's let our AI agents start doing what those humans would do in a workflow.


 

So you're humans are just looking at how do I make risk-based decisions, but they're not being human gofers that are collecting data and doing all the drudgery that's historically gone into these types of jobs.


 

[00:10:22] Sean Martin: So it really drives to the decision.


 

[00:10:25] Travis Howerton: Yes.


 

[00:10:26] Sean Martin: And not getting mired in the. The paperwork that,


 

[00:10:28] Travis Howerton: yeah, because that's why we collect all the data is to get to a point of like, should I feel good about this or not?


 

Right? It just takes a lot to get there. We're trying to make all that toil and dwell time that you have there. Just go away.


 

[00:10:40] Sean Martin: Do you have a use case or case study or customer story you wanna share? Where you help them compress or get. Get better results than they were getting prior to working with RegScale.


 

[00:10:49] Travis Howerton: Absolutely. We have one large government agency that's touting over a hundred million dollars of labor savings and what it took to historically do all this types of work. We have another [00:11:00] department of war, um, that's looking at uh, uh, 52 week average to get through this cycle, end to end. They've been able to compress that by 36 weeks using our tech and some others that we've integrated with.


 

Um, so you're seeing just sort of massive savings in some cases. Other cases, what you're seeing is massive schedule compression. In all cases, what you're seeing is a better assurance posture that's lower risk, which I think every CISO, I mean CISOs are risk officials. That's what they care about at the end of the day, is to protect the company, uh, or their organization.


 

And so, uh, the risk outcome is always a guarantee.


 

[00:11:33] Sean Martin: Yeah. And the ability to communicate what it is to those that, that, uh, need to know


 

[00:11:38] Travis Howerton: absolutely.


 

[00:11:39] Sean Martin: Whether it be internal at the company or external for cyber insurance. Coverage or whatever. It's Right.


 

[00:11:44] Travis Howerton: Yep. Absolutely.


 

[00:11:46] Sean Martin: So what, um, what's the, what's the future hold for RegScale?


 

[00:11:51] Travis Howerton: Yeah,


 

we're,


 

[00:11:51] Sean Martin: where, where are you headed?


 

[00:11:52] Travis Howerton: We're continuing to grow fast. You know, we've, uh, the last three years we've tripled, doubled, and doubled again. So I think our message and, and our platforms [00:12:00] resonating in the market. Um, I think we'll continue to, to. Focus on sort of the top of the market. So the largest, most complex organizations in the world, uh, government, financial services, healthcare, um, high tech companies, um, that's where we're kind of focused today.


 

I think in the future, you're gonna see us go international. Probably a fair amount of, uh, new markets we might go into, like, uh, uh, energy sector seems to be, uh, a prime market for us as well. And so I think you'll just see us go more places and, and take this story into more highly regulated environments and try to find ways we can help.


 

Yeah,


 

[00:12:34] Sean Martin: so the goal is today. Actually reduce and manage the risk.


 

[00:12:39] Travis Howerton: Yes.


 

[00:12:40] Sean Martin: Not just report that you did something that hopefully did.


 

[00:12:42] Travis Howerton: Yeah. Not just to check the box so that you can sell. Right? Because at the end of the day, you don't want your company to get breached. Um, you don't want an embarrassing audit coming downstream.


 

All the reputational loss that goes into those things. So it's trying to take what's a low value activity that you have to do and turning it into a high value activity that [00:13:00] mostly takes care of itself.


 

[00:13:02] Sean Martin: Common. Best practice.


 

[00:13:04] Travis Howerton: Absolutely.


 

[00:13:04] Sean Martin: Why not apply that and use your team to do it?


 

[00:13:07] Travis Howerton: Mm-hmm.


 

[00:13:08] Sean Martin: Travis,


 

[00:13:09] Travis Howerton: it's been an absolute


 

[00:13:09] Sean Martin: pleasure.


 

Appreciate it.


 

[00:13:10] Travis Howerton: Mm-hmm.


 

[00:13:11] Sean Martin: Thanks everybody. Hopefully, uh, enjoyed this conversation with Travis and, uh, hope you connect with him on LinkedIn and the RegScale team. And, uh, stay tuned for more coming from ITSPmagazine here at Black Hat USA.


 

Cool.