I know, that’s already established. I already acknowledged we had different experiences. I have no idea what you’re pushing for at that point
Compliance and security are entirely different practices in a well-run firm. Security can inform compliance. Compliance should not inform security engineering.
If you search my name and "SOC2" in the search bar below, I've expanded on this quite a bit.