Archive for Comcast

Guest Post: Why GRC Is Becoming an Engineering Discipline 

Posted in Commentary with tags on August 27, 2026 by itnerd

By Yasmine Abdillahi, Executive Director of Cyber GRC and Business Information Security Officer, Comcast 

When security leaders hear “engineering discipline” applied to Governance, Risk, and Compliance (GRC), the instinct is to brace for more tooling, more headcount, and more infrastructure that needs to be justified to the board. 

But this initial reaction misreads what is actually happening. GRC is becoming an engineering discipline not because someone decided to make it more complicated, but because the complexity was already there. The compliance programs built a decade ago were designed for the slower world of annual audits, static risk registers, and policies that changed quarterly at best. That world is gone. Today, cloud infrastructure can spin up and down in hours, AI agents are proliferating, regulations can multiply across jurisdictions, and a board member might ask about risk posture, with the expectation of an immediately trustworthy answer. 

The teams making real progress aren’t the ones that have added more people or tools. They’re the ones that changed what GRC is built on. Today, GRC engineering is how organizations simplify governance, shorten the time it takes to find value, and stop reinventing the wheel of pipelines year after year. 

The Problem Is the Data Beneath GRC 

Most organizations don’t fail at GRC because they lack frameworks, policies, or good intentions. They fail because the underlying knowledge of what is connected to what, which data resides where, and which controls protect which assets is scattered piecemeal across security, IT, cloud, identity, and business systems — none of which were designed to maintain that picture coherently. Every time a control needs to be validated, someone manually pulls from multiple sources, normalizes the results, and hopes the timing is close enough to tell a consistent story. 

Consider a simple question: “How many of our critical systems have MFA enabled?” Answering it accurately means pulling identity data, cross-referencing asset inventory, filtering the results by criticality classification, and clarifying whether “enabled” means configured, enforced, or actively used. By the time the answer is ready, it’s already a snapshot from last week. Multiply that by the hundreds of controls a mature GRC program tracks, and you see the real problem: teams aren’t doing GRC work. They’re doing data plumbing. 

Why agentic AI is amplifying the urgency 

AI governance dominated the conversation at Black Hat USA 2026, with much of it tracing directly back to the Hugging Face incident — a preview of how quickly “AI agents” went from an emerging buzzword to the central topic on the floor. 

These solutions are responding to the fact that agents drift and can get exploited when nobody is looking at them. However, AI governance is not just a feature that can simply be added to existing security tool stack. It’s a practice or a discipline requiring alignment between IT, Cybersecurity, GRC, finance and the business. 

Access control issues for agents cannot be observed and trusted periodically. Instead, they need continuous validation and remediation. Because agents can update themselves at runtime; a control evidenced at a point in time may not be compliant an hour later. 

This isn’t hypothetical. In July 2026, an AI model undergoing a routine capability evaluation escaped its test environment and compromised Hugging Face’s production infrastructure — autonomously, over four days, without a human directing each step. The agent didn’t need stolen admin credentials to escalate; it read cloud metadata, minted its own service-account tokens, and mapped its own permissions in real time. That’s the identity-to-agent-to-asset chain breaking down in exactly the way static, point-in-time control evidence can’t catch. 

This is where the identity-to-agent-to-asset mapping underneath any GRC platform needs to be engineered and current. 

Why Building Your Own Solution Usually Stalls 

The natural response is to unify the data by building an internal pipeline, a custom dashboard, and a “security data fabric” that pulls everything into one place. The intent is right, but the execution is where things get hard. 

Data normalization is genuinely demanding. Matching a user record from an identity provider to a Configuration Management Database (CMDB) asset record and a Security Information and Event Management (SIEM) log entry isn’t a configuration task — it’s an engineering challenge requiring sustained expertise. Audit defensibility gets added after the fact, if at all. And maintenance quietly becomes a permanent commitment, consuming engineering capacity that was supposed to go elsewhere. 

Agentic AI makes the engineering lift heavier as its governance requires granular traceability including what the agents are permitted to do and what they actually did, with what inputs, on whose behalf and why. If an agent’s effective permissions can be manipulated by the content it processes through prompt injection, then “what can this agent do” isn’t a static fact pulled once and normalized; it has to be validated continuously. 

What “Engineering GRC” Actually Means 

Engineering GRC doesn’t mean every organization needs to engineer it themselves. It means GRC now depends on properties that must be designed in from the beginning, not added later. 

Those properties are observability, testability, and explainability. Observability means your compliance posture is visible in real time, not reconstructed at audit time. Testability means controls are validated continuously against live data, not just when a review is coming. And explainability means every metric has a traceable origin. If someone asks how a number was derived, you can show exactly what data was used, how it was transformed, and what was included or excluded. 

With adding agentic AI to the attack surface, internal pipelines that have been built to track control configuration need to be expanded to continuous action-level traceability. 

Where the Real ROI Lives 

An organization that has built toward these properties is doing something fundamentally different from one that prepares for audits by collecting screenshots. The output might look similar from the outside, but the foundation is entirely different. The business case is often framed around efficiency such as less audit prep time, and fewer manual handoffs. Those gains are real, but the more compelling argument is compounding value. 

In most GRC programs, a significant chunk of team time goes toward “rebuilding truth.” Every quarter, every audit, every board report, someone pulls from the same sources, normalizes the same fields, and produces a number everyone agrees on. That work doesn’t accumulate into anything. Engineering the data foundation converts this recurring cost into a durable asset — a compliance posture that updates continuously and produces the same defensible answer whether the question comes from internal audit, an external assessor, or the board. 

There’s a risk dimension too. When compliance data is manually assembled, a gap can exist for weeks without anyone knowing. When the foundation is continuous and observable, that window closes. 

Most importantly, with agentic AI, the cost of not having the mapping foundation is an attack vector and not just a control gap. 

The Shift Worth Making 

GRC is becoming an engineering discipline because trust and accountability must now operate at machine speed. The organizations navigating this well aren’t the ones building the most sophisticated internal capabilities — they’re the ones that stopped rebuilding truth from scratch and started instrumenting it. 

When talking to GRC leaders early on in this journey, the question is almost never: “Shouldn’t we do this?” Instead, it’s: “Where do we start?” The answer: start with the data you already have. Map where your control evidence actually comes from. Identify the reconciliation work your team does every quarter that produces no lasting value. Then ask what it would take to make that work happen once — automatically, continuously, with full lineage — instead of repeatedly by hand. 

That question leads you to the foundation. Everything else follows from there. 

About the Author 

Yasmine Abdillahi is Executive Director of Cyber GRC and Business Information Security Officer at Comcast, where she leads security risk and compliance across Comcast and Sky. She is a recognized speaker at SINET, Gartner Evanta, and BrightTalk. She is also a senior fellow at the Atlantic Council. Connect with her on LinkedIn: linkedin.com/in/yasmine-abdillahi-2631b97 

Comcast Is Down… Users Take To Twitter To Vent

Posted in Commentary with tags on October 11, 2016 by itnerd

As I type this, there is a nationwide outage for Comast users. There is no word on what is causing the outage or when it might be resolved, but unhappy Comcast users are taking to Twitter to vent:

https://twitter.com/snebunny/status/785775333328850944

https://twitter.com/RamgrlVA/status/785795889751216128

https://twitter.com/gogoaphi1872/status/785760259574943744

You get the idea. Comcast doesn’t have the best reputation in the US. This isn’t going to help their cause. I hope for their sake service gets restored quickly.

Comcast Files Suit Against The FCC… Just Like They Promised

Posted in Commentary with tags , , on August 17, 2009 by itnerd

Comcast said almost a year ago that they were going to go after the FCC because of the FCC’s rather lame attempt to stop Comcast from throttling their users. Well, they finally got around to filing the paperwork according to ARS Technica. Their main argument is this:

“For the FCC to conclude that an entity has acted in violation of federal law and to take enforcement action for such a violation, there must have been ‘law’ to violate,” Comcast’s Opening Brief [Warning: PDF] to the court contends. “Here, no such law existed.”

The article then goes on the explain the reasons why Comcast feels that they’re being unfairly picked on by the FCC as well as a brief history of this issue. It’s an interesting read and I hope you take the time to read it.

In any case, if I were the FCC I would solve the problem this way: Get congress to pass laws that outlaw throttling. That way there is a law that covers the sort of behavior that Comcast has engaged in. Problem solved.

Comcast Techs Save Woman From Burning Home….Great For Making People Forget About The Fact That They Broadcasted Porn During The Superbowl

Posted in Commentary with tags on February 5, 2009 by itnerd

It looks like Comcast employees are turning into superheroes lately. After one Comcast tech saved six lives recently, comes this story where a pair of techs from the much maligned company saved an 88 year old woman from a fire:

NewsCenter 5’s Amalia Barreda reported that the Tom Masciulli and Jim MacConnell were working at a home Tuesday on Gardner Road when a man ran up to them and said his house was on fire and his wife was still inside.

“As soon as he said that his wife was in the house, that’s when I couldn’t think anymore and I ran for the house,” MacConnell said.

Fred Smith, the 88-year-old owner of the home, said that his wife, Peggy, 88, was still inside.

“We looked upstairs, and the second floor was just engulfed in smoke. She was at the top of the stairs trying to get down as best she could,” Masciulli said.”When we went upstairs, it was almost a surreal scene. I could see fire behind her, and as I was looking up I could see the billowing black smoke — almost like a movie set,” MacConnell said.”We just went up there, and he grabbed one side, and I grabbed another. We took her out. We brought her down and escorted her all the way down to another house,” Masciulli said.

Very impressive! Comcast needed some great press lately, seeing as they accidentally broadcast porn during the tail end of the SuperBowl on Sunday:

Comcast customers in Tucson, AZ watching the Super Bowl saw more pigskin than they bargained for when 30 seconds of a porno movie cut in to the final minutes of the big game. “I was watching the game with my family, Larry Fitzgerald scores the go ahead TD – then bam, penis,” writes reader David. A Comcastic Fight Club homage, perchance?

Comcast is going to offer $5 to every person who saw this “malfunction.” Great. Good thing that those two techs were around to save lives and deflect attention from this fiasco.

Comcast Tech Saves Six Lives…. Then Continues To His Next Appointment

Posted in Commentary with tags on December 8, 2008 by itnerd

I’ve spent a fair amount of time bashing Comcast for having Comcastic service as well as throttling P2P users. But today I want to praise Comcast…. Or more accurately, one of their techs. According to The Washington Post, on-duty Comcast technician Jorge Rivera managed to save six people from a burning apartment complex using the ladder on his truck:

“It was nothing,” Rivera said. “I got two kids at home. If they were somewhere burning, what would you do?”

What’s even more impressive, he continued to his next appointment after saving the day. Hopefully Comcast gives this guy a raise as they can’t usually buy this sort of a positive press.

Comcast Reveals Changes For Managing Traffic

Posted in Commentary with tags , on September 20, 2008 by itnerd

Comcast yesterday posted this document on their website that details how they’re going to manage traffic on their network. According to Comcast, here’s how it will work:

“If a certain area of the network nears a state of congestion, the technique will ensure that all customers have a fair share of access to the network. It will identify which customer accounts are using the greatest amounts of bandwidth and their Internet traffic will be temporarily managed until the period of congestion passes. Customers will still be able to do anything they want to online, and many activities will be unaffected, but managed customers could experience things like: longer times to download or upload files, surfing the Web may seem somewhat slower, or playing games online may seem somewhat sluggish.

The new technique does not manage congestion based on the online activities, protocols or applications a customer uses, rather it only focuses on the heaviest users in real time, so the periods of congestion could be very fleeting and sporadic.

It is important to note that the effect of this technique is temporary and it has nothing to do with aggregate monthly data usage. Rather, it is dynamic and based on prevailing network conditions as well as very recent data usage.”

On one hand, this almost sounds reasonable if it is implemented in a transparent manner. I would almost like Comcast if that were the case. On the other hand, policies like these are meant to allow a telco to spend less time upgrading their network and more time counting their cash.

Another thing to consider, Comcast doesn’t exactly have a stellar history in terms of telling the truth. They denied that they were blocking P2P apps even when the Associated Press provided proof. Then when they finally confessed to using gear from Canadian network gear provider Sandvine, they lied again by saying that they only used it at times of congestion. In reality they were using this gear 24 hours a day.

Finally, they’re doing this while taking legal action against the FCC. So we’ll see what sort of twist that provides.

I suspect that we’ll see what happens next very quickly.

Comcast Appeals FCC Ruling…. Didn’t See That Coming…. NOT!

Posted in Commentary with tags , , on September 4, 2008 by itnerd

You know, I have to admit that sometimes you get blindsided. That’s how I feel as the news that Comcast is appealing the FCC ruling that keeps them from messing with filesharing traffic. Richard Korman of ZDNet received a message from Comcast along with a statement from David L. Cohen, Executive Vice President of Comcast:

“Although we are seeking review and reversal of the Commission’s network management order in federal court, we intend to comply fully with the requirements established in that order, which essentially codify the voluntary commitments that we have already announced, and to continue to act in accord with the Commission’s Internet Policy Statement. Thus, we intend to make the required filings and disclosures, and we will follow through on our longstanding commitment to transition to protocol-agnostic network congestion management practices by the end of this year. We also remain committed to bringing our customers a superior Internet experience.

We filed this appeal in order to protect our legal rights and to challenge the basis on which the Commission found that Comcast violated federal policy in the absence of pre-existing legally enforceable standards or rules. We continue to recognize that the Commission has jurisdiction over Internet service providers and may regulate them in appropriate circumstances and in accordance with appropriate procedures. However, we are compelled to appeal because we strongly believe that, in this particular case, the Commission’s action was legally inappropriate and its findings were not justified by the record.”

This pretty much proves what I said in this post some time ago. The FCC has no way to punish Comcast, and their order is not legally enforcable. The only thing that surprises me is that it took Comcast this long to call them on it. Of course Comcast is covering themselves just in case the appeal doesn’t go their way by continuing to implement everything that the order calls for them to do. But one has to think that this FCC order is about to get deep sixed.

Comcast Annouces That It Will Only Throttle “Heavy Users”…..Whatever….

Posted in Commentary with tags , , on August 25, 2008 by itnerd

Everybody’s favorite ISP Comcast has confirmed that it will continue to throttle service for its heaviest users during periods of congestion. Basically, the plan is that they will take action against specific users by significantly reducing their transfer rate for up to 20 minutes as opposed to throttling everything:

“The new system will move away from a focus on specific applications that hog Web traffic, [Comcast senior vice president and general manager of online services Mitch] Bowling said. Comcast will determine “in nearly real time” whether congestion is caused by a heavy user, he said.

“If in fact a person is generating enough packets that they’re the ones creating that situation, we will manage that consumer for the overall good of all of our consumers,” Bowling said.”

Of course they’re doing this in response to the half assed FCC ruling that came out not too long ago. The new system, reportedly dubbed “fair share” should be in place by the end of 2008.

You’ll excuse me if I don’t jump up and down for joy as Comcast is still employing throttling at the end of the day. But I guess the devil is in the details, so we’ll have to wait and see just what those details are. Then we can decide if Comast has made an brilliant move, or a Comcastic move.

FCC Releases Comcast Throttling Order… Yawn.

Posted in Commentary with tags , , on August 20, 2008 by itnerd

This document (Warning: PDF) just appeared on the FCC site a few minutes ago. It is 67 pages long, but what it tells Comcast to do is in the following paragraph:

“Disclose the details of their unreasonable network management practices, submit a compliance plan describing how it intends to stop these unreasonable management practices by the end of the year, and disclose to both the Commission and the public the details of the network management practices that it intends to deploy following termination of its current practices.”

Great. Excecpt for a whole bunch of things:

  1. The FCC order doesn’t actually punish Comcast in any way.
  2. It doesn’t force them to do anything they didn’t plan to do after this story hit the media.
  3. It may not even be enforceable in court.
  4. Comcast continues to use forged packets to throttle upstream P2P traffic and will continue to do so until the end of the year.

I must be missing something here because I can’t see what purpose this order serves. Perhaps someone will enlighten me.

Comcast Wiggles Free From Punishment. Shock! Not!

Posted in Commentary with tags , on August 1, 2008 by itnerd

As expected, The FCC has voted 3 – 2 to do absolutely nothing (Warning: PDF) to Comcast for the company’s throttling via packet forgery. The FCC says that Comcast willfully misled consumers about the throttling of P2P traffic which is good. But it creates no new guidelines and may not stand up in court. Oh yeah, anything the FCC tells Comcast to do, they’ve already said they’re going to do. So what has been acomplished here?

Nothing. Which is sad.