Imagen de portada del espectáculo Security & GRC Decoded

Security & GRC Decoded

Podcast de Raj Krishnamurthy

inglés

Negocios

Oferta limitada

2 meses por 1 €

Después 4,99 € / mesCancela cuando quieras.

  • 20 horas de audiolibros / mes
  • Podcasts solo en Podimo
  • Podcast gratuitos
Empezar

Acerca de Security & GRC Decoded

How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!

Todos los episodios

35 episodios

Portada del episodio From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave

From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave

In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur [https://www.linkedin.com/in/jask31/], Principal of Security & Assurance Engineering at CoreWeave [https://www.coreweave.com/], to explore how AI-native infrastructure is fundamentally reshaping GRC. Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems. Key Takeaways: * Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them. * Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal. * GRC must evolve into an infrastructure-level capability that continuously emits assurance signals. * Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight. * Future GRC teams must operate more like engineering and reliability functions rather than audit teams. What You’ll Learn: * Why AI infrastructure makes traditional audits ineffective * What “GRC as infrastructure” actually means in practice * How to move from point-in-time audits to continuous assurance * The difference between automation, CCM, and agentic GRC * How to position GRC as a proactive, business-critical function This podcast is brought to you by ComplianceCow [https://www.compliancecow.com/] — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com [https://www.compliancecow.com/] Watch more episodes: https://www.compliancecow.com/podcast [https://www.compliancecow.com/podcast?utm_source=chatgpt.com] Connect With Our Guest: Jasmine Kaur | Principal of Security & Assurance Engineering | CoreWeave Connect on LinkedIn: https://www.linkedin.com/in/jask31/ [https://www.linkedin.com/in/jask31/] Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 [https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683] Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 [https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450]

5 de may de 2026 - 54 min
Portada del episodio The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis

The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis

In this episode of Security & GRC Decoded, Raj Krishnamurthy [https://www.linkedin.com/in/rajkrishnamurthy/] sits down with Val Dobrushkin [https://www.linkedin.com/in/dobrushkin/], Director of GRC at Tricentis [https://www.tricentis.com/], to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers. This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&A outcomes, and why solving for today while building for the future is the key to long-term success. Key Takeaways: * Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls. * SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity. * GRC has a unique advantage over security in directly demonstrating business value and revenue impact. * “Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition. * Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early. What You’ll Learn: * Why questionnaires and annual vendor reviews fail to capture real third-party risk * How GRC teams can prove revenue impact through customer trust and assurance * The hidden role of GRC in M&A, IPO readiness, and contract validation * Why most GRC metrics fail and what meaningful measurement should look like * How to implement a “solve now, build for future” strategy in fast-growing companies This podcast is brought to you by ComplianceCow [https://www.compliancecow.com/] — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com [https://www.compliancecow.com/] Watch more episodes: https://www.compliancecow.com/podcast [https://www.compliancecow.com/podcast?utm_source=chatgpt.com] Connect With Our Guest: Val Dobrushkin | Director of GRC | Tricentis Connect on LinkedIn: https://www.linkedin.com/in/dobrushkin/ [https://www.linkedin.com/in/dobrushkin/] Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 [https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683] Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 [https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450]

21 de abr de 2026 - 55 min
Portada del episodio GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife

GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife

In this episode of Security & GRC Decoded, Raj Krishnamurthy [https://www.linkedin.com/in/rajkrishnamurthy/] sits down with Dylan O’Dell [https://www.linkedin.com/in/dylan-odell-72a06412b/], AVP Information Risk Officer at Manulife [https://www.manulifeim.com/en], to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions. Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why GRC needs to evolve beyond audits and control testing into automation, orchestration, and storytelling. This conversation explores how modern GRC teams can reduce operational friction, quantify real risk, and actually influence business outcomes. Key Takeaways: * GRC today is overly focused on control testing rather than true risk management and decision-making. * Automation should eliminate manual audit friction — not just make existing processes faster. * The future GRC professional must combine technical awareness with storytelling, influence, and business understanding. * Risk management should be rooted in probability and financial impact — not pass/fail compliance. * GRC teams can unlock funding and influence by tying their work directly to revenue, cost savings, and business outcomes. What You’ll Learn: * Why the “three lines of defense” model often breaks down in practice. * How to translate technical data into meaningful business risk narratives. * What modern GRC automation should actually look like (beyond tools). * How to position GRC as a revenue enabler — not just a cost center. * Why “start with why” is critical for influencing stakeholders and reducing friction. This podcast is brought to you by ComplianceCow [https://www.compliancecow.com/] — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.  Learn more: https://www.compliancecow.com [https://www.compliancecow.com/] Watch more episodes: https://www.compliancecow.com/podcast [https://www.compliancecow.com/podcast?utm_source=chatgpt.com] Connect With Our Guest: Dylan O’Dell | AVP Information Risk Officer | Manulife Connect on LinkedIn: https://www.linkedin.com/in/dylan-odell-72a06412b/ [https://www.linkedin.com/in/dylan-odell-72a06412b/] Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 [https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683] Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 [https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450]

7 de abr de 2026 - 1 h 7 min
Portada del episodio Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security & GRC @ Yahoo

Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security & GRC @ Yahoo

In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security & GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogies to explain vulnerabilities, to reframing GRC as the “Draymond Green” of cybersecurity, Steven shows how the best security leaders translate complexity into clarity, help the business make better decisions, and meet people where they are instead of overwhelming them with jargon. Key Takeaways: * Security and GRC succeed when they communicate clearly to humans, not when they simply present more technical detail. * The best GRC teams act as guides that help the business make reasonable, compliant, cyber-conscious decisions. * Metrics only matter when they drive a clear outcome or decision, not when they exist for their own sake. * Strong GRC teams build trust by doing the hard, cross-functional work that others often avoid. * Storytelling is a core security skill because people act on messages they understand, remember, and relate to. What You’ll Learn: * Why Steven believes security is ultimately a human communication problem. * How to tailor security messaging for engineering leaders, CISOs, and business stakeholders. * What “guardrails not gates” looks like in a practical GRC program. * How to think about data, metrics, and reporting without overwhelming your audience. * Why AI may change the consumption layer of GRC, but not eliminate the human need for storytelling. This podcast is brought to you by ComplianceCow [https://www.compliancecow.com/] — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com [https://www.compliancecow.com/] Watch more episodes: https://www.compliancecow.com/podcast [https://www.compliancecow.com/podcast?utm_source=chatgpt.com] Connect With Our Guest: Steven Asifo | Director of Security & GRC | Yahoo Connect on LinkedIn: https://www.linkedin.com/in/asifosays/ [https://www.linkedin.com/in/asifosays/] Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 [https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683] Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 [https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450]

24 de mar de 2026 - 59 min
Portada del episodio The 3 Year GRC Reckoning: Customer Trust, Real-Time Assurance, and the Future of Risk ft Bryan Culp, Senior Director of Customer Trust @ Box

The 3 Year GRC Reckoning: Customer Trust, Real-Time Assurance, and the Future of Risk ft Bryan Culp, Senior Director of Customer Trust @ Box

In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Bryan Culp [https://www.linkedin.com/in/bryanculp/], Senior Director of Customer Trust at Box [https://www.box.com/home], to explore how governance, risk, and compliance is evolving beyond certifications and into real-time trust. Bryan shares why the next two to three years will fundamentally change how GRC operates — driven by automation, AI, large financial institutions demanding real-time internal metrics, and growing pressure to translate security posture into business language. From managing both customer trust and third-party risk at Box, Bryan offers a rare dual perspective: how companies present assurance to customers while simultaneously evaluating vendors themselves. This conversation challenges the idea that certifications alone create security and makes the case for risk being the true language of leadership. Key Takeaways: * Customer Trust is not traditional GRC — it translates security and compliance work into business confidence for customers. * Certifications enable market access, but they do not eliminate breach risk. * Risk must be communicated in executive language to influence real business decisions. * Large financial institutions are beginning to demand real-time internal security metrics instead of snapshot audits. * AI is transforming GRC workflows — not to cut people, but to enable deeper, higher-value analysis. What You’ll Learn: * Why Bryan believes GRC will look materially different in the next 2–3 years. * How Customer Trust functions differently from compliance and audit teams. * Why certifications alone cannot prevent major security incidents. * What “real-time assurance” could look like for large SaaS companies. * How to think about AI and automation as long-term growth enablers in GRC. This podcast is brought to you by ComplianceCow [https://www.compliancecow.com/] — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com [https://www.compliancecow.com/] Watch more episodes: https://www.compliancecow.com/podcast [https://www.compliancecow.com/podcast?utm_source=chatgpt.com] Connect With Our Guest: Bryan Culp | Senior Director of Customer Trust | Box [https://www.box.com/home] Connect on LinkedIn: https://www.linkedin.com/in/bryanculp/ [https://www.linkedin.com/in/bryanculp/] Rate, review, and share if you enjoyed the show! Subscribe to Security & GRC Decoded wherever you get your podcasts: Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683 [https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683] Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450 [https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450]

10 de mar de 2026 - 1 h 6 min
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
Soy muy de podcasts. Mientras hago la cama, mientras recojo la casa, mientras trabajo… Y en Podimo encuentro podcast que me encantan. De emprendimiento, de salid, de humor… De lo que quiera! Estoy encantada 👍
MI TOC es feliz, que maravilla. Ordenador, limpio, sugerencias de categorías nuevas a explorar!!!
Me suscribi con los 14 días de prueba para escuchar el Podcast de Misterios Cotidianos, pero al final me quedo mas tiempo porque hacia tiempo que no me reía tanto. Tiene Podcast muy buenos y la aplicación funciona bien.
App ligera, eficiente, encuentras rápido tus podcast favoritos. Diseño sencillo y bonito. me gustó.
contenidos frescos e inteligentes
La App va francamente bien y el precio me parece muy justo para pagar a gente que nos da horas y horas de contenido. Espero poder seguir usándola asiduamente.

Elige tu suscripción

Más populares

Oferta limitada

Premium

20 horas de audiolibros

  • Podcasts solo en Podimo

  • Disfruta los shows de Podimo sin anuncios

  • Cancela cuando quieras

2 meses por 1 €
Después 4,99 € / mes

Empezar

Premium Plus

100 horas de audiolibros

  • Podcasts solo en Podimo

  • Disfruta los shows de Podimo sin anuncios

  • Cancela cuando quieras

Disfruta 30 días gratis
Después 9,99 € / mes

Prueba gratis

Sólo en Podimo

Audiolibros populares

Empezar

2 meses por 1 €. Después 4,99 € / mes. Cancela cuando quieras.