Ga naar de inhoud
PodcastsTechnologieSecurity & GRC Decoded

Security & GRC Decoded

Raj Krishnamurthy
Security & GRC Decoded
Nieuwste aflevering

38 afleveringen

  • Security & GRC Decoded

    The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong

    04-08-2026 | 46 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with James Huang, Head of GRC at Gong, to explore how Governance, Risk, and Compliance has evolved from a traditional audit function into a strategic engineering discipline.
    Drawing on experience building GRC programs at Ernst & Young, Cisco, Salesforce, and Gong, James explains why modern GRC leaders must think beyond compliance checklists and focus instead on understanding risk, partnering with engineering, and building scalable security programs. The conversation covers common control frameworks, continuous controls monitoring, third-party risk, AI's impact on GRC, Mythos, automation, and why future GRC professionals need to become business translators rather than framework experts.
    Key Takeaways:
    Modern GRC should focus on understanding and reducing risk—not simply satisfying compliance frameworks.
    A Common Controls Framework only succeeds when engineering and business teams understand the risks behind each control.
    Continuous controls monitoring should improve security posture, not just make audits easier.
    AI is transforming GRC by increasing both operational efficiency and third-party risk complexity.
    Successful GRC leaders act as translators between business, engineering, security, and compliance teams.
    What You’ll Learn:
    Why compliance frameworks should always be interpreted through the lens of risk
    How to build scalable Common Control Frameworks across complex organizations
    What continuous controls monitoring should actually accomplish
    How AI is changing vendor risk management and security governance
    Why the future of GRC belongs to technically-minded business partners
    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guests:
    James Huang | Head of GRC | Gong
    Connect on LinkedIn: https://www.linkedin.com/in/james-k-huang/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts:
    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC

    25-06-2026 | 38 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Rajiv Dattani and David Meyer from Artificial Intelligence Underwriting Company (AIUC) to explore one of the biggest unanswered questions in AI security:
    Can organizations actually trust AI agents?
    As enterprises rapidly deploy AI-powered products, copilots, and autonomous agents, traditional security assessments, compliance frameworks, and cyber insurance models are struggling to keep pace. Rajiv and David explain why insurers are beginning to exclude AI-related risks, why historical loss data no longer works in the age of AI, and how AIUC-1 was designed to become a trust and assurance framework for AI systems.
    The conversation explores AI certification, AI insurance, agent security testing, reliability, safety, accountability, statistical risk modeling, and the growing challenge of securing increasingly autonomous systems.

    Key Takeaways:
    Traditional cyber insurance models are struggling to underwrite AI risk because historical loss data becomes obsolete as models rapidly evolve.
    AIUC-1 combines governance controls, technical evaluations, and large-scale simulation testing to assess AI agent security and trustworthiness.
    AI assurance requires more than security controls—it must also evaluate reliability, safety, accountability, privacy, and societal impact.
    Statistical testing and large-scale simulations may become the foundation for measuring AI risk in probabilistic systems.
    The AI security community will play a critical role in shaping standards, liability models, and best practices for future AI deployments.

    What You’ll Learn:
    Why many insurance carriers are beginning to exclude AI-generated risks from cyber policies
    How AIUC-1 differs from frameworks like NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
    How AI agents are tested through both black-box and white-box security evaluations
    Why reliability and hallucination risks become more important in multi-agent environments
    How AI certification may influence future insurance pricing, risk management, and enterprise adoption

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guests:
    Rajiv Dattani | Cofounder | AIUC
    David Meyer | GTM | AIUC
    Connect on LinkedIn: https://www.linkedin.com/in/rajiv-dattani/
    https://www.linkedin.com/in/david-meyer-8586b17b/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts:
    https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath

    02-06-2026 | 53 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Sheron Chakalakal, Head of GRC at UiPath, to explore why the future of GRC looks far more like systems engineering than traditional audit management.
    Drawing from his experience at Salesforce, Deloitte, and UiPath, Sheron explains why point-in-time audits and checkbox compliance are failing modern engineering organizations — and why risk-driven, continuously monitored GRC programs are becoming essential. The conversation dives into AI governance, continuous risk monitoring, customer assurance, GRC engineering, AIUC-1, and how security, compliance, and engineering teams must evolve together.
    This episode reframes GRC as a technical reliability function that helps companies reduce operational risk continuously instead of simply passing audits once a year.

    Key Takeaways:
    Modern GRC programs must evolve from audit functions into engineering-driven reliability functions.
    Risk—not compliance—should be the central language for communicating with leadership teams.
    Continuous controls monitoring is essential because point-in-time audits create “checkbox theater.”
    AI governance requires technical evaluations, agent testing, and continuous assurance beyond traditional frameworks.
    Future GRC leaders will need technical depth, business context, and the ability to bridge engineering with executive leadership.

    What You’ll Learn:
    Why Sheron believes compliance should be designed into products from day one
    How UiPath approaches continuous risk monitoring and GRC engineering
    Why AIUC-1 introduces a fundamentally different approach to AI assurance
    How GRC teams can become the “translation layer” between business and engineering
    Why future GRC practitioners must develop technical and systems-thinking skills

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guest:
    Sheron Chakalakal | Head of GRC | UiPath
    Connect on LinkedIn: https://www.linkedin.com/in/sheronpaulc/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave

    05-05-2026 | 54 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur, Principal of Security & Assurance Engineering at CoreWeave, to explore how AI-native infrastructure is fundamentally reshaping GRC.
    Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems.
    Key Takeaways:
    Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them.
    Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal.
    GRC must evolve into an infrastructure-level capability that continuously emits assurance signals.
    Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight.
    Future GRC teams must operate more like engineering and reliability functions rather than audit teams.
    What You’ll Learn:
    Why AI infrastructure makes traditional audits ineffective
    What “GRC as infrastructure” actually means in practice
    How to move from point-in-time audits to continuous assurance
    The difference between automation, CCM, and agentic GRC
    How to position GRC as a proactive, business-critical function
    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guest:
    Jasmine Kaur | Principal of Security & Assurance Engineering | CoreWeave
    Connect on LinkedIn: https://www.linkedin.com/in/jask31/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
  • Security & GRC Decoded

    The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis

    21-04-2026 | 55 Min.
    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Val Dobrushkin, Director of GRC at Tricentis, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers.
    This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&A outcomes, and why solving for today while building for the future is the key to long-term success.
    Key Takeaways:
    Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls.
    SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity.
    GRC has a unique advantage over security in directly demonstrating business value and revenue impact.
    “Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition.
    Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early.
    What You’ll Learn:
    Why questionnaires and annual vendor reviews fail to capture real third-party risk
    How GRC teams can prove revenue impact through customer trust and assurance
    The hidden role of GRC in M&A, IPO readiness, and contract validation
    Why most GRC metrics fail and what meaningful measurement should look like
    How to implement a “solve now, build for future” strategy in fast-growing companies
    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com
    Watch more episodes: https://www.compliancecow.com/podcast
    Connect With Our Guest:
    Val Dobrushkin | Director of GRC | Tricentis
    Connect on LinkedIn: https://www.linkedin.com/in/dobrushkin/
    Rate, review, and share if you enjoyed the show!
    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683
    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
Meer Technologie podcasts
Over Security & GRC Decoded
How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!
Podcast website

Luister naar Security & GRC Decoded, De Groene Nerds en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies