Security & GRC Decoded cover art

Security & GRC Decoded

Security & GRC Decoded

Written by: Raj Krishnamurthy
Listen for free

About this listen

How today’s top organizations navigate the complex world of governance, risk, and compliance (GRC). Security & GRC Decoded brings you actionable strategies, expert insights, and real-world stories that help professionals elevate their security and compliance programs. Hosted by Raj Krishnamurthy. It’s for security professionals, compliance teams, and business leaders responsible security GRC and ensuring their organizations’ are safe, secure and adhere to regulatory mandates. Security & GRC Decoded brings you: Actionable strategies, expert insights, and real-world stories to elevate your Security GRC programs. Each episode explores frameworks, risk management strategies, and innovations shaping the future of GRC – from practitioners in the trenches. Subscribe now to unlock the tools and knowledge you need to succeed!

© 2026 Security & GRC Decoded
Economics
Episodes
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave
    May 5 2026

    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Jasmine Kaur, Principal of Security & Assurance Engineering at CoreWeave, to explore how AI-native infrastructure is fundamentally reshaping GRC.

    Drawing from her experience at companies like SAP, Google, and now an AI hyperscaler, Jasmine explains why traditional GRC models are failing in high-velocity, ephemeral environments—and what needs to replace them. From “GRC as infrastructure” to the rise of agentic GRC, this conversation dives into how compliance must evolve from a reactive audit function into a real-time assurance capability embedded directly into systems.

    Key Takeaways:

    • Traditional GRC models break in AI environments because systems are ephemeral and disappear before audits can validate them.
    • Compliance should be treated as a byproduct of strong risk modeling and control design—not the end goal.
    • GRC must evolve into an infrastructure-level capability that continuously emits assurance signals.
    • Agentic GRC is the next evolution beyond automation and CCM, enabling decision-capable systems with human oversight.
    • Future GRC teams must operate more like engineering and reliability functions rather than audit teams.

    What You’ll Learn:

    • Why AI infrastructure makes traditional audits ineffective
    • What “GRC as infrastructure” actually means in practice
    • How to move from point-in-time audits to continuous assurance
    • The difference between automation, CCM, and agentic GRC
    • How to position GRC as a proactive, business-critical function

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Jasmine Kaur | Principal of Security & Assurance Engineering | CoreWeave
    Connect on LinkedIn: https://www.linkedin.com/in/jask31/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683


    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450


    Show More Show Less
    54 mins
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis
    Apr 21 2026

    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Val Dobrushkin, Director of GRC at Tricentis, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers.

    This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&A outcomes, and why solving for today while building for the future is the key to long-term success.

    Key Takeaways:

    • Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls.
    • SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity.
    • GRC has a unique advantage over security in directly demonstrating business value and revenue impact.
    • “Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition.
    • Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early.

    What You’ll Learn:

    • Why questionnaires and annual vendor reviews fail to capture real third-party risk
    • How GRC teams can prove revenue impact through customer trust and assurance
    • The hidden role of GRC in M&A, IPO readiness, and contract validation
    • Why most GRC metrics fail and what meaningful measurement should look like
    • How to implement a “solve now, build for future” strategy in fast-growing companies

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Val Dobrushkin | Director of GRC | Tricentis
    Connect on LinkedIn: https://www.linkedin.com/in/dobrushkin/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683

    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450

    Show More Show Less
    55 mins
  • GRC Is Broken... And Nobody Wants to Admit It ft Dylan O’Dell, AVP Information Risk Officer @ Manulife
    Apr 7 2026

    In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Dylan O’Dell, AVP Information Risk Officer at Manulife, to challenge one of the biggest assumptions in the industry: that GRC is working as intended. Dylan argues that most organizations are stuck in control-centric thinking and missing the true purpose of risk management — translating data into business decisions.

    Drawing from his background in Lean Six Sigma and large-scale enterprise risk, Dylan breaks down why GRC needs to evolve beyond audits and control testing into automation, orchestration, and storytelling. This conversation explores how modern GRC teams can reduce operational friction, quantify real risk, and actually influence business outcomes.

    Key Takeaways:

    • GRC today is overly focused on control testing rather than true risk management and decision-making.
    • Automation should eliminate manual audit friction — not just make existing processes faster.
    • The future GRC professional must combine technical awareness with storytelling, influence, and business understanding.
    • Risk management should be rooted in probability and financial impact — not pass/fail compliance.
    • GRC teams can unlock funding and influence by tying their work directly to revenue, cost savings, and business outcomes.

    What You’ll Learn:

    • Why the “three lines of defense” model often breaks down in practice.
    • How to translate technical data into meaningful business risk narratives.
    • What modern GRC automation should actually look like (beyond tools).
    • How to position GRC as a revenue enabler — not just a cost center.
    • Why “start with why” is critical for influencing stakeholders and reducing friction.

    This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence.

    Learn more: https://www.compliancecow.com

    Watch more episodes: https://www.compliancecow.com/podcast

    Connect With Our Guest:
    Dylan O’Dell | AVP Information Risk Officer | Manulife
    Connect on LinkedIn: https://www.linkedin.com/in/dylan-odell-72a06412b/

    Rate, review, and share if you enjoyed the show!

    Subscribe to Security & GRC Decoded wherever you get your podcasts:

    Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683


    Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450


    Show More Show Less
    1 hr and 8 mins
adbl_web_anon_alc_button_suppression_c
No reviews yet