GRC & Me: Recent Episodes

LogicGate

When Governance, Risk, and Compliance (GRC) issues are in the headlines, it’s usually a bad thing. It’s only when a major data breach happens, or a company runs afoul of some regulation, that these important responsibilities get their time in the limelight. GRC & Me is here to shine a light on those individuals tasked with safeguarding their employers’ information and integrity, day in and day out. Tune in each month as host Megan Phee, Director of International Sales at LogicGate, and her guests explore the issues and ideas that give shape to these interconnected functions. Just as GRC touches many parts of a business, so too will the podcast delve into a wide array of concerns—from current events and modern methodologies to cultural nuances and game-changing developments. Join us and learn why GRC is so critical to the future of any organization, where the industry has been—and where it’s going.

View Details

Join Vinted’s Group Risk & Compliance Officer, Elisabeth Quillatre, and Risk Process Manager, Goda Marija Vaitkeviciute, as they debunk common GRC myths in retail. From data privacy to supply chain risks, they explore the human side of risk and share practical insights on building a strong compliance culture, not just implementing controls.

View Details

Tune in as we’re joined by industry leaders from BCU, BillGo, and Centier Bank that share their unique perspective and insight on the future of the financial industry.

Hosted by Meghan Maneval, panelists Stephenie Southard, Steve Gasiamis, and Donald Rome dive into the key trends and challenges shaping the financial landscape in 2025. From navigating regulatory changes and ensuring security resilience, to exploring the rise of digital banking technologies like blockchain, AI, and open banking, guests will discuss how financial institutions must prepare for risks related to third-party management and more. Don’t miss out on a thought provoking and engaging conversation on the ever-evolving financial risk landscape.

View Details

In this episode, Google Continuous Assurance Engineering Director, Vikram Khare, and Senior Software Engineering Manager, Eric Zhang, discuss implementing continuous assurance, with tips for getting started and real-world examples through the lines of defense. They cover the challenges of keeping up with evolving controls and risks, as well as the reality of automating controls only to need updates again. Tune in to hear best practices for maintaining integrations and automations, how auditors and GRC professionals can embrace AI, and ways to quantify ROI to

View Details

In this episode, host Meghan Maneval is joined by Google’s Product Management Lead for Cybersecurity Compliance Products, Ruchi Khurana, to explore the current state of AI and automation in the GRC industry. They dive into key considerations for the role of AI and ML in the GRC domain, including critical success criteria and how to prioritize AI-related risks across departments. They also discuss the key challenges in the GRC industry. Tune in for insights on leveraging AI and ML to drive efficiency and improve GRC processes.

View Details

In the season 8 finale, guest host Jade Trombetta is joined by Salim Alameddin, Senior Vice President at Crossroads Strategies, LLC to discuss key cybersecurity and AI regulation trends and new administration objectives that will shape 2025. They explore a variety of topics from the evolving landscape of cybersecurity, including the growing threat of geopolitical cyberattacks, to AI and compliance under the new administration. They also chat about the challenges some of the cabinet may have jumping from the tech world into government work, and other 2025 economic trends our GRC community is interested in. Tune in for a conversation on the critical issues faced today.

View Details

In this episode, host Meghan Maneval is joined by LogicGate’s Chief Customer Officer, Jen Renna, to discuss the evolution of customer success at LogicGate. They dive into what success looks like from both a customer and internal perspective, and why people are at the heart of it all. The discussion also covers key considerations when selecting a GRC platform, what customers can expect from LogicGate moving forward, proving that GRC is not a cost center with value realization, and how the company drives value internally to foster success.

View Details

In this episode, host Meghan Maneval is joined by Macy Mody, VP of Customer Experience at SafeBase, to discuss the critical role that trust plays in business success. They explore how trust centers help reduce risks and increase efficiencies. And they dive into the advantages of AI and how it can enhance the experience, as well as the potential pitfalls and challenges of AI. Tune in for invaluable insights around fostering trust in your organization and leveraging technology to drive growth!

View Details

Join us in this episode as host Meghan Maneval and Michael Rasmussen - GRC Analyst & Pundit at GRC 20/20 Research, LLC - discuss vendor risk management and the differences between third, fourth, and fifth-party risks. They discuss essential regulations and standards in the financial and banking sectors, highlighting how they vary by organization maturity. As well as best practices for effectively building and managing a comprehensive vendor risk management program and staying current with risk management standards. Michael touches on the role of automation and AI in enhancing vendor risk programs, as well as their limitations. And he shares his 2025 regulatory predictions and their potential impact on vendor risk strategies in the financial services.

View Details

In this episode, we’re excited to explore the ever-changing landscape of banking compliance. We’ll cover best practices for staying audit-ready amidst constantly evolving regulations. The discussion will address compliance requirements, from NCUA mandates to state-specific privacy laws, PCI 4.0, and more. We’ll also talk about AI in banking along with third-party and vendor risks. This insightful conversation will highlight both the challenges and best practices in navigating compliance complexities across the industry.

View Details

Optimizing Risk: GRC is no longer a cost center - it’s a business enabler

Guests: LogicGate CEO, Matt Kunkel and CISO, Nick Kathmann

Historically GRC was viewed as one line in a budget sheet, but that is rapidly changing. GRC practitioners are elevating their programs with tools and technologies that aggregate data and story-tell situational risk, security, compliance changes and more so businesses can make risk-based decisions to move the needle forward. Matt Kunkel and Nick Kathmann will share why good security pays for itself, the role GRC plays in the boardroom and how to connect GRC programs to business impact.

View Details

Switching from traditional risk analysis methods like ordinal lists or red-yellow-and-green charts to more modern approaches like risk quantification requires a paradigm shift in how you think about measuring risk, but the increased accuracy, specificity, and reliability you’ll gain by doing so pays dividends.

On this episode of GRC & Me, Netflix’s Tony Martin-Vegue join LogicGate’s Chris Clarke to explore the best ways to navigate this transition, how to learn and leverage popular risk quantification frameworks like Open FAIR, and why you shouldn’t completely throw your colored charts out the window just yet.

View Details

They say it takes a thief to catch a thief, so why not a hacker to catch a hacker?

That was the premise behind Ted Harrington’s Independent Security Evaluators, a company dedicated to poking holes into other companies’ cyber defenses — for the right reasons, of course. On this episode of GRC & Me, Ted takes LogicGate’s Chris Clarke on a journey down the benevolent hacker’s rabbit hole, where they discuss:

  • The difference between white box and black box testing (and which is better.)
  • Why carrying these exercises out can build trust and become a competitive advantage in third-party risk assessment.
  • Why it’s important to shift your mindset from one that views security as an obstacle to one that views it as an opportunity.
  • Uncovering the unknown unknowns in cybersecurity.
  • How “defense in depth” strategies can put security teams a step ahead of threat actors.
  • The four traits that lead hackers to be successful, and why thinking like one can be an effective way to bolster your cyber defenses.

View Details

Few careers involve managing as much risk as one where you’re responsible for launching humans riding gigantic rockets into outer space. That’s exactly what Barrios Technology Chief Strategy Officer Ginger Kerrick did during her three-decade career working for NASA.

On this episode of GRC & Me, Ginger joins LogicGate’s Chris Clarke to discuss methods for developing methodical, standardized thought processes for risk decision-making in high-stakes scenarios, how NASA employees are trained to separate logic from emotion, how disasters can inform future mitigation planning, and why the most important part of managing risk is having the right leaders in place.

View Details

One of the most high-profile risk events of the last year was the swift collapse of Silicon Valley Bank and other regional banks amid spiking interest rates. Part of the problem? The lack of a complete, comprehensive view of the risks these banks were facing — in particular, liquidity risk.

Allstate Canada's Chief Risk Officer Jason Wang has spent his career assessing and analyzing risk in the financial services space, dedicated to anticipating and mitigating risks just like the one that sank SVB. On this episode of GRC & Me, Jason joins LogicGate’s Chris Clarke to discuss the importance of building a holistic risk register, how to position risk management as a strategic enabler instead of a “revenue prevention” department, why it’s critical to include your chief risk officer on the executive team, and more.

View Details

When doing business with the federal government and its myriad agencies, organizations are bound to run into plenty of mandates, regulations, and other requirements. Navigating them all can cause a headache for even the most detail-oriented compliance managers.On this episode of GRC & Me, Chris Clarke is joined by Intel Federal’s Compliance Program Manager, John Griffin. Griffin draws on his decades of experience in federal contracting and working with government agencies at companies like Honeywell and Boeing to explore methods for better managing product development and performing diligence on third-party vendor relationships while operating under strict and stringent government standards and requirements. Plus, learn a few of Griffin’s more creative methods for determining how risky a particular organization might be to work with.

View Details

Oftentimes, cyber risk teams are viewed as reactive “audit police,” swooping into projects to flag risks and forcing changes at key points. This approach can generate a resentful — even toxic — risk culture. There’s a better way to build healthier risk cultures: Taking a more collaborative, embedded approach to cyber risk management by positioning cyber risk leaders as advisors and partners, working side-by-side with project teams from the start.

On this episode of GRC & Me, Chris Clarke is joined by Cyberpink’s Founder & Owner, Praj Prayag-Deb, to discuss how to shift your organization’s risk culture toward this new approach, her formula for building successful cyber risk programs from scratch, how leveraging the right technology makes it all possible, and why adopting a growth mindset is critical for every cyber risk leader.

View Details

Oftentimes, cyber risk teams are viewed as reactive “audit police,” swooping into projects to flag risks and forcing changes at key points. This approach can generate a resentful — even toxic — risk culture. There’s a better way to build healthier risk cultures: Taking a more collaborative, embedded approach to cyber risk management by positioning cyber risk leaders as advisors and partners, working side-by-side with project teams from the start.

On this episode of GRC & Me, Chris Clarke is joined by GEICO’s Praj Prayag-Deb, Head of Cybersecurity Risk to discuss how to shift your organization’s risk culture toward this new approach, her formula for building successful cyber risk programs from scratch, how leveraging the right technology makes it all possible, and why adopting a growth mindset is critical for every cyber risk leader.

View Details

Cybersecurity programs involve lots of moving parts, and they only grow more complex over time as technology becomes more advanced and cyber threats become more numerous and sophisticated. Cyber risk quantification can be a crucial tool for keeping up with shifting cybersecurity landscapes.On this episode of GRC & Me, Chris Clarke is joined by Protiviti’s Daniel Stone, Director, and Tim Kelly, Associate Director, to discuss how cyber risk quantification can lead to better risk decision-making, how to beat analysis paralysis when you’ve got reams of risk data in front of you, and the best ways to use risk quantification to reduce reactivity and improve communication across your organization.

View Details

With information and cybersecurity incidents growing in frequency and severity, regulators in the European Union are hard at work devising new rules designed to incentivize organizations to harden their cyber defenses.

On this episode of GRC & Me, Megan Brown sits down with Wizz Air’s Andras Szabolcs, Cyber Risk Expert, and Peter Szigetvari, Operational Risk Expert, to break down the similarities and differences between two of these new European Union regulations — the Digital Operational Resilience Act, or DORA, and Network and Information Security Directive 2, or NIS2 — how they could affect nearly every company despite their official scope, and how organizations can prepare to comply with them using modern GRC technology.

View Details

In just a few months, artificial intelligence went from a fringe technology to full-speed ahead with the public release of ChatGPT. This fascinating technology has the potential to revolutionize how we automate our businesses, but there are numerous reasons to give pause before integrating it into your organization’s operations. On this episode of GRC & Me, Dorian Cougias, Co-Founder and CEO of United Compliance Framework and Chris Clarke sit down to discuss the risks and rewards of embracing AI-driven automation, corpora management, data ownership, and the necessity of double-checking everything generative AI spits out.

View Details

On this episode of GRC & Me, Andy Ruse and Mike Curl, former Regulatory Data Manager at Honeywell, discuss the benefits of building dashboards from the bottom up, how to get organizational buy- in when it comes to change management, and Mike's unique culinary approach to executive reporting.

View Details

Getting everyone on the same page about the risks your organization is facing is a crucial part of effectively managing organizational risk. Unfortunately, it’s also one of the hardest parts about effectively managing risk. On this episode of GRC & Me, Dimitrios Stergiou, Director of Information Security at Wayflyer, explains how risk quantification and proper use of standard frameworks can help you build a common language for understanding risk across your organization, break down organizational silos, and get buy-in for your programs.

View Details

On this episode of GRC & Me, Andy Ruse, LogicGate’s President of Field Operations, sits down with Cooley’s Mike Santos, Director of Security and Information Governance, to discuss his five-layer maturity model for building effective GRC programs, the different things a risk practitioner has to consider in decision making, and his own recommendations for maturing any risk program.

View Details

Properly measuring risk is the most important ingredient in effectively communicating risk, and communicating risk leads to a richer risk culture at your organization. On this episode of GRC & Me, we sat down with OKTA’s Anthony Riley to hear his best practices for measuring and communicating risk.

View Details

This episode takes a deep dive into creating a business case for investing in GRC technology by proving its cost-saving impact. LogicGate CEO Matt Kunkel spoke with Michael Rasmussen, a renowned GRC expert, to discuss the past, present, and future of GRC spending. Listen to discover how to build a business case for upgrading to the latest and greatest in GRC.

View Details

On this episode of GRC & Me, we explore business resilience and the differences between proactive, reactive, and preemptive approaches to crisis management with Howard Mannella, Senior Staff of Global Business Continuity and Security at Udemy. We learn how Howard stays ahead of risks by focusing on their impact and how organizations of all sizes can evolve their GRC programs. Listen to the full episode for valuable insights any business can use to stay resilient.

View Details

This episode tackles the essential topic of how to build and mature a risk program aligned with business objectives. Andy Ruse, LogicGate’s president of field operations, recently caught up with James Bundy, practice director at cybersecurity consulting firm Optiv, to explore how businesses across all industries can create a holistic GRC program that contributes to real business growth. How can compliance requirements become business enablers? Listen to find out.

View Details

LogicGate’s Megan Phee sat down with Jason Wang, Chief Risk Officer at Synergy Credit Union, to explore the importance of creating or refining business continuity plans in the face of volatility. Business continuity plans help you make critical decisions before you need them. Otherwise, you make those decisions during a business-impacting event when every hour matters. Listen to the full episode to hear Jason’s valuable advice for making enterprise-wide decisions to improve your resilience.

View Details

Making things easier and less paper-bound through digital technology is a top priority for many organizations, especially when it comes to their GRC initiatives. In this episode, LogicGate’s Megan Phee is in London with UAE-based Proxis founder and managing director, Tina Chugani. Join us as Megan and Tina talk about the concept of process digitalization and trends that Tina is seeing within her region. Plus, how technology is helping to make it rain in the desert. Learn more about Proxis at proxis.me

Make sure to visit agility.logicgate.com to learn how you can join us at our GRC user conference in Downtown Chicago on September 22nd and 23rd at the Swissotel Chicago or virtually. Hope to see you there!

View Details

When people think of GRC, generally, they tend to categorize it within the framework of financial or regulated sectors. Even the entertainment business needs GRC. In this episode, Megan Phee is joined by Tony Martin-Vegue, Senior Information Security Risk Engineer at Netflix, who shares his risk quantification journey, how to get tactically started, and how risk quantification can provide positive business outcomes.

View Details

Welcome to a special edition of GRC & Me featuring the audio version of LogicGate's newest eBook on Third-Party Risk Management.

This audio eBook reveals:

  • How to effectively manage third-party relationships (hint: it’s not with spreadsheets)
  • Steps to building a robust third-party risk management program that connects ALL the dots
  • Why third-party risk management is everyone’s business
  • How an interconnected risk program helps you calculate, communicate, mitigate, and report third-party risks

Ready to get proactive with your Third-Party Risk Management strategy? Visit logicgate.com today!

View Details

Great conversations leave you wanting more and that is exactly what happened when LogicGate's own Megan Phee appeared with James (Jim) Rees on Razorthorn's podcast. So when they both felt like there was more to discuss, we invited Jim to join us on GRC & Me. Jim is Razorthorn's Managing Director and Principal Security Consultant with decades of experience in information security. He has worked with some of the largest and most influential organizations worldwide. In this episode of GRC & Me, Megan and Jim continue their chat on the ever-changing complexities of compliance, how regulatory models ask for consistency, and quick wins for those starting on their InfoSec and GRC journeys.

View Details

At GRC & Me, we like to go big or go home. In this episode, we do just that and take on the topic of global standards. We brought in the perfect person for the task, Rob Fulcher, Head of Sales for the Americas at CUBE. Rob chats with LogicGate's Director of International Sales, Megan Phee, about why we find ourselves in our current regulatory situation, how and where global standards can help, and how new technology can help or hinder the future state of regulatory standards.

View Details

It seems like everywhere you look there’s a new article about the “Great Resignation” and the challenges with keeping talent. Businesses, regardless of industry, are being impacted. So where do we go from here? In this episode of GRC & Me, LogicGate’s CEO, Matt Kunkel, and new Chief People Officer, Caroline Werner, chat about the reality of the current talent landscape, what they’ve learned from the last few years, and how they’re adjusting their strategies to help adapt.

View Details

Our customers' success means a lot to us at LogicGate. That is why we decided to have no other than Szuyin Leow, VP of Customer Success, as a guest host. Szuyin sits down with one of our rockstar customers, Stephen Crouch from Texas Mutual. Stephen is a risk analyst in the workers' compensation insurance space and at Texas Mutual, he quickly got involved with revamping the vendor risk management program. In this episode, Stephen recounts his GRC journey. He highlights how he has seen vendor risk management evolve, plus other reflections and best practices to build successful vendor risk management programs.

View Details

We decided it was time for some inner reflection here at GRC & Me. Or, in GRC terms, an Internal Audit. Guest host Heath Anderson, LogicGate's Information Security Leader, does just that as he goes in-house and turns the mic on LogicGate's own Security Compliance Manager, Elizabeth Walker. Elizabeth is a fountain of knowledge for LogicGate and the GRC community. In this episode, Elizabeth defines what internal audit means, her perspective on the players, personalities, and challenges, and some valuable tips from her playbook.

View Details

At the end of last season, we learned how resilience, agility, and integrity are perfect additions to GRC practices that merit more focus. In this episode, we kick off season five of GRC & Me and continue this discussion by looking deeper into resiliency and agility. To get us there, LogicGate's CEO, Matt Kunkel, speaks with Chris Patteson, The Risk Wrangler, to help us understand what resiliency and agility mean for organizations and their boards.

View Details

For centuries philosophers have given us the four cardinal virtues: prudence, justice, fortitude, and temperance. For the GRC community at large, there is more than enough room to add to these to cover our unique world and its dealings. At LogicGate, we think that resilience, agility, and integrity are perfect additions.

In our season 4 finale of GRC & Me, LogicGate CEO Matt Kunkel and GRC expert Michael Rasmussen covered resilience and agility. In this episode, the two are back to discuss integrity and apply it to the latest GRC trend, ESG or Environmental, Social, and Governance.

View Details

It's a new year, and that means new resolutions. Move over pushups and pilates; we're kicking off the new year with a two-part podcast meant to get your 2022 off to a great start. If you are looking to have a more resilient and agile GRC program — and to find out how these two intersect with GRC practices and why they matter — then you have come to the right place!

In this episode of GRC & Me, Michael Rasmussen and our CEO Matt Kunkel discuss why resiliency is critical for a risk management program. Michael also provides insights into how agility aligns with your organization's strategic plans.

View Details

Have you ever wondered what exactly holistic GRC is? What does it look like, and do people really mean when they say a “holistic GRC program”?

In this episode of GRC & Me, returning guest Dustin Owens, VP of Cyber Risk and Resilience at Kivu Consulting, will break down all the what's, how's, and why's regarding holistic GRC programs and platforms. Dustin also shares some GRC stories about how companies use a holistic GRC approach to achieve business outcomes.

View Details

Have you ever worried about how you should communicate risks to the board? How much data can they handle?

In this episode of GRC & Me, we are joined by Richard Seiersen, who has previously worked for Twilio, GE, and LendingClub as CISO, was a co-founder of Soluble that was acquired by Lacework in 2021, and is currently the Chief Risk Officer at Resilience Insurance. His books include How to Measure Anything in Cybersecurity Risk and The Metrics Manifesto: Confronting Security with Data. Together with Mark Tattersall, VP of Product at LogicGate, we get the skinny on what kind of conversations are happening at the board level and what they really want to see and hear, plus, the rise of insurtech, technology being a driver for consistency, and how all these topics inspired Richard to write his books.

View Details

Do you see cybersecurity troubled waters coming your way but don’t know how to navigate the storm? With a good course charted, a strong and united crew, and a savvy captain you can navigate even the scariest of threat seas.

In this GRC & Me episode, we are joined by Adam Gladsden, a third-party risk advisor who heads up the risk advisory practice at SecurityScorecard. Adam guides us as we look at the current cyber threat landscape, the connection to the enterprise's third-party and cyber risks, and how it affects all risk categories. We also discuss how organizations can improve and mature their third-party risk programs.

View Details

What does a “high” risk mean to you? What does it mean to your colleague? Does your organization have multiple risks marked as “high” but it’s hard to figure out which one to focus on first? If you answered yes to the last question, risk quantification may be the right fit for you. However, risk quantification has proven to be a popular and complex subject. That is why we invited Bob Maley, Chief Security Officer at Black Kite to talk to us about how risk quantification helps risk pros use quantification to make sense of qualitative data and effectively communicate risk across an organization. Bob is CRISC, CTPRP, and an Open FAIR™ certified risk quantification expert who has led state-of-the-art risk management programs.

In this episode of GRC & Me, Bob discusses the importance of risk quantification and how it can help organizations make better strategic decisions. We also discuss how Black Kite’s Open FAIR™ based solution calculates the probable financial impacts of cyber breaches and how it communicates risks in quantitative, easy-to-understand business terms so that organizations can risk smarter and with confidence.

View Details

Charlie Meyer is LogicGate’s Implementation Services Manager. In his role, he has served at the helm of countless implementation strategies for GRC solutions.

Charlie provides guidance for best practices for implementation and shares real-world examples of how companies have run successful launches with a GRC provider.

While Charlie primarily works in the initial implementation process, he advises customers to maintain a relationship with their GRC provider and look for ongoing opportunities for improved services and applications.

View Details

Jason Wang, Chief Risk Officer at Synergy Credit Union, joined the financial institution  to build out and enhance its  enterprise risk management functions, including a disaster recovery and pandemic response framework — all just before the start of the pandemic.

Jason’s forethought and preparation positioned Synergy to successfully navigate COVID-19.

In this episode of GRC & Me, Jason shares his experiences chairing Synergy’s COVID-19 Committee and discusses how to evaluate new risks that have emerged within your company in the aftermath of the pandemic. Jason also speaks to the importance of understanding Environmental Social Governance (ESG), why it’s here to stay, and what you should be doing about it.

Jason believes that everyone is a risk manager in your organization and provides strategies to help you create company-wide buy-in for mitigating risk and protecting your data.

View Details

Dustin Owens’ extensive background in GRC began with an undergraduate degree in computer information systems.

When he realized programming wasn’t his professional calling, he transitioned to the security and cybersecurity space — now, he’s accrued 25 years of experience in the field.

After being introduced to risk quantification in 2003 as part of the National Security Agency’s INFOSEC Assessment Methodology, Dustin hasn’t looked back.

As LogicGate’s Principal GRC Architect, he focuses heavily on how risk quantification can help obtain consistent risk findings that are accurately defined in monetary terms.

In this episode of GRC & Me, Dustin breaks down why organizations have much to benefit from adopting risk quantification practices to better assess, manage and respond to risk. Plus, it helps organizations better prioritize the activities that require more attention and investments.

“It makes it very easy to compare risk mitigation activities and whether they do risk acceptance or transfer risk, based on the amount of impact that that risk has to the business,” explains Dustin,” which allows organizations to “see if it makes sense to go in one direction versus another.”

View Details

LogicGate’s Chief Marketing Officer Gina Hortatsos joins the podcast to discuss the findings. One of the surprising results is that while the vast majority (91%) acknowledged the importance of GRC programs to their organization, but only 45% of survey respondents said their current programs are extremely effective.

View Details

How can you best articulate the value of your security program to non-security professionals in your organization? Or even to board members?

It starts with asking questions. Five of them, to be exact.

Emily Heath, DocuSign’s Chief Trust & Security Officer, covers five questions or pillars to ensure you’re able to confidently speak about your company’s security program.

In this episode of GRC & Me, Emily returns to the podcast to discuss her advice for organizations seeking to drive transparency and competence with both their board of directors and customers. Because the pandemic has changed the risk landscape, Emily believes that the world of GRC must become more resilient. By that, she means organizations should improve their ability to rebound with minimal impact to business. 

A global pandemic has taught both organizations and people that risk is everywhere. And while Emily, who also serves on the board of directors for LogicGate and NortonLifeLock, is determined to help organizations prepare for risks, she also finds time for the small things, such as the cooking blog she began during the pandemic.

View Details

Brian Clark has had a front-row seat to both sides of the regulatory compliance coin: He was a regulator during the post-financial crisis in 2008. Years later, he transitioned to being a chief compliance officer and general counsel.

With such varied experience, the president and founder knew exactly what he set out to solve when he founded Ascent in 2015: simplifying the knowledge work required to keep up with regulations and maintain compliance. 

To help clients build and automate repeatable compliance programs, Ascent employs artificial intelligence (AI) to produce knowledge sets and streamline processes — for example, it can produce an output in two minutes for a task that could take humans thousands of hours (it’s true!)

In an episode of GRC & Me, Brian explains why AI is the right tool for the job because it allows “people to unlock their potential and their time to focus on different activities.”

View Details

Peter Berger and David Ngu both work for global consulting firm Protiviti in the Netherlands, helping clients figure out how to integrate governance, risk management, and compliance technology into their workplace.

In this episode of GRC & Me, Peter and David provide some of their valuable insights about how to incorporate agile GRC technology to make sure it’s actually doing its job to help manage the risks in your company and ensure your business is aligned so successful risk governance can take place and nothing slips through the cracks.

We all face risks in our daily lives, now more than ever. Peter and David are here to help companies handle them with agility and flexibility, and stay tuned: they’re even offering listeners a complimentary consulting session to talk about GRC technology and agile risk governance. Reach out to Peter and David directly: peter.berger@protiviti.nl & david.ngu@protiviti.nl

View Details

Just what is Risk Cloud Exchange (RCX) and what benefits could it offer your organization? These questions are explored on this episode of GRC & Me with LogicGate’s Amrutha Sivakumar and Emily Affinito. 

View Details

After nearly two decades in tech, including stints at the Big Four security firms, Scott Jordan is on his 148th governance, risk, and compliance (GRC) implementation. Now the principal and partner at Agile GRC Solutions, Scott puts it simply on this episode of GRC & Me: “I’ve seen a few things in the market.” Specifically, he’s watched as companies large and small have become more vulnerable to ransomware and other types of cyberattacks. While assessing the damage, he’s spotted a few common mistakes, which he calls “security landmines.” GRC tools like LogicGate are powerful and necessary, but they work best when the humans wielding them are doing their due diligence. That’s where Scott and his experience come in. That is if he can resist the tempting job offer from his eight-year-old daughter...

View Details

Legacy technology’s grasp on GRC processes is slowly loosening. As LogicGate’s Director of Customer Success Szuyin Leow explains, it appears the future is here, thanks to flexible data models.

A former cybersecurity consultant, Szuyin now helps LogicGate’s customers leverage the flexible data model that powers the risk cloud platform the company is recognized for.

Adaptability is key across any industry, and that’s what this model specializes in, even in a climate with many unknowns.

In this episode of GRC & Me with host Megan Phee, Szuyin explains that compared to rigid data models, flexible ones let organizations “slot things in where they're needed” when external changes force a shift within data structures and new requirements must be implemented.

Still, the grass isn’t always greener. Too much design and customization can pose an obstacle for organizations building out their data structures, but Szuyin and her team encourage them to follow LogicGate’s best practices.

Can you guess how flexible data models benefit industries outside of GRC? That’s what the LogicGate Risk Cloud IRL competition will reveal.

View Details

When the effects of COVID-19 began to tear across industries, GRC Technology Manager Priyam Shah didn’t hesitate to pivot PwC’s services to support their customers.

Because PwC resolves complex GRC issues across various industries, Priyam says its collaboration with LogicGate was natural to support the facilitation of the “return to work” program PwC created as a part of its pandemic response.

In this episode of GRC & Me with host Megan Phee, Priyam discusses how the PwC x LogicGate Risk Cloud™️ relationship helped organizations bring their workforce back to the office by providing the necessary controls and processes.

She also shares thoughts about what to consider as you discover the right tools and solutions for your programs as well as rising trends in the GRC landscape.

Then Megan and Priyam discuss common pitfalls faced by companies along with different points of the GRC journey.

When it comes to your governance structure, what do you think is preventing you from seeing the value you need? (Hint: Enabling all your programs at once!)

View Details

Asureti co-founder and Practice Director, Melissa Ryan, has been fascinated with language for as long as she can remember — and she has the spelling bee record to prove it. Since she’s worked with people across business operations, the multi-faceted data protection expert has seen firsthand how a common language can bridge gaps between departments, allowing for truly valuable and meaningful conversations. That technical jargon flying across your teams? It actually pulls your organization further apart. Melissa uses a risk rating matrix, for example, to better facilitate communications with clients. These tools — or points of reference like taxonomies — contribute immeasurable value when they are defined through a shared language and then used across the business. “We find that leaders who are leveraging these common definitions, these standard rating, and translation tools, and incorporating them into a GRC technology are truly finding enhanced value,” explains Melissa. Here’s the key: Make sure the underlying structure, calculations, and design of the common language of your tools and technology are consistent. Ready to learn how to connect the dots between the teams in your risk organization?

View Details

In the age of COVID-19, virtual conferences reign supreme — without the handshaking, warm hugs and mingling breaks, are they as compelling and worthwhile to attend?

When the content is as relevant and valuable as it was at Agility 2020, LogicGate’s first-ever virtual user conference, the answer is an easy yes.

Couldn’t make it? Tune in to this special episode of GRC & Me with host Megan Phee for highlights from the engaging conference that featured a line-up of notable hosts, including LogicGate’s all-star leadership team: CEO Matt Kunkel, VP of Product Management Mark Tattersall and CFO Kevin Jacobson.

Through riveting presentations, the leaders addressed the current state of the GRC space, where it’s going and how the LogicGate Risk Cloud™ can build a new path forward.

Listen as Matt discusses the importance of enterprise risk management in the emergence of the risk cloud, as Mark explains how vital customer feedback is during product development, and as Kevin shares his journey with the risk cloud to more effective vendor management.

While next year’s plans develop, ponder this: What do you want to learn at LogicGate’s 2021 user conference to sufficiently strengthen your organization’s risk protocols in an evolving and post-pandemic environment?

View Details

David Ponder, a partner at Cential, has used COVID-19 to teach his five-year-old daughter about the interconnectedness of the world: “To change the world, you've got to start with yourself first and your closest circle second,” he advises.

This lesson parallels the interconnectivity of risk management ecosystems — organizations should never stop reevaluating the principles that determine their actions.

Why? Because risk management is no longer done by standalone entities. Like herd immunity, transformative risk management introduces the idea that if one organization in the risk ecosystem is weak (or strong!), everyone else is, too. One band; one sound.

Enter Jannie Wentzel, a partner and principal consultant at Cential, who authored a whitepaper about the emerging tools and technologies that are transforming risk management today.

Together, Jannie and David assert that transformative risk management’s emphasis on data will provide leaders the confidence to base critical decisions and drive valuable business solutions for each participant in a risk ecosystem.

With host Megan Phee, these GRC experts posture that risk leaders will soon shift their understanding of compliance-focused risk management and GRC as a whole. Could this be the Next Big Thing of risk?

View Details

What do you get when you cross innovation and pioneering? CEO Matt Kunkel and Chief Product Officer Jon Siegler — AKA two of the three founders of LogicGate.

Historically, the old-school GRC software space aimed to operationalize regulatory risk and compliance and security programs in two ways: 1) Using technology platforms with rigid data models and 2) Using point solutions — that don’t integrate well with other applications — to solve specific use cases, third-party risk and more.

In Matt and Jon’s opinion, that’s why The Risk Cloud™ represents a departure from what we know about GRC.

In this episode of GRC & Me, tune in to hear how these visionaries have disrupted the GRC industry with The LogicGate Risk Cloud, a platform that presents a solution and has the flexibility to reimagine what risk is entirely.

With host Megan Phee, they discuss The Risk Cloud’s extensibility at length, especially what it enables companies (and risk managers!) to do. After listening, ask yourself this: How can The LogicGate Risk Cloud enable effective risk operation for you?

View Details

A simple question — “why?” — jumpstarted Heath Anderson’s journey with governance, risk and compliance (GRC).

Today, he’s LogicGate’s Information Security Manager. Before that, he worked with development teams in the United States Air Force designing tests to ensure compliance, and the rest is security — err, history.

For his first-ever podcast appearance, Heath joined an episode of GRC & Me to discuss how The LogicGate Risk Cloud adds value to the company as well as how he uses it to push security frameworks forward.

The LogicGate Risk Cloud is essential for Heath, and not just because he was able to adjust his program to accommodate society’s new normal — it automates Control Management activities and even revealed how he and his team could improve their third party risk management return on investment (ROI) metrics.

Plus, can you guess the neat hobby that gets his creative juices flowing?

View Details

In the Season 2 premiere of GRC & Me, Megan is talking to John Mumford, Chief Risk Officer at Fellsway Group, a Boston-based consulting firm.

Listen in as John discusses why GRC professionals today are hungry for a new way of thinking about risk compliance, how to tackle cyber risk as a business risk, and his passion for risk-taking - not just in business but on the ice rink, too.

View Details

In this special episode of GRC & Me, Megan sits down with LogicGate CEO Matt Kunkel and CMO Gina Hortatsos to discuss how a risk management company is handling the COVID-19 pandemic. Matt and Gina walk us through their reactions when the news broke about the pandemic, the free Business Continuity Plan offer for LogicGate customers, and the challenges of leading a company during the statewide shelter-in-place order.

View Details

Top 3 Quotes

  • “Trust really is ‘security, compliance, and privacy’—it's the three-legged stool.”
  • “The ‘compliance’ is a byproduct [of risk], ‘governance’ is the way you operate, but how you truly define ‘risk’ is where the focus is.”
  • “Sensitive data being pushed around an organization through e-mails and spreadsheets—that kind of model is not sustainable.”

Show Highlights

[01:43] From a detective in England to Chief Trust & Security Officer at DocuSign
[03:17] Duties and responsibilities of a Chief Trust Officer
[04:26] Evolution of GRC
[05:26] Exciting trends in GRC
[06:42] “Duct tape and bubble gum” concept is alarming
[07:30] What compelled Emily to join LogicGate’s Board of Directors?
[08:57] Advice for women in tech who are seeking leadership roles
[11:15] A little birdy told us...

Resources:

  • Connect with Emily on LinkedIn
  • Connect with Emily on Twitter
  • DocuSign

View Details

Top 3 Quotes

  • There's a number of players providing solutions, but only a small number of true winners that will emerge to set this new standard for usability and effectiveness combined with affordability.
  • Risk and compliance needs change so fast that the technology has to be flexible enough to keep up.
  • The market is wide open for a company to set the pace for the rest of the pack and for the industry.

Show Highlights

[01:26] Karry's humble start
[03:44] What lead Karry to the GRC space
[04:50] The emergence of SaaS as a business model and how Karry got involved with it
[06:18] Why GRC is a perfect fit for SaaS delivery model
[07:34] What is exciting about GRC today?
[08:33] Where else the market is going in the future?
[09:27] Karry's one element that instills positive culture

Resources:

  • Connect with Karry on LinkedIn
  • Connect with Karry on Twitter
  • Karry’s LogicGate Profile

View Details

Top 3 Quotes

  • Risk assessment is not the same thing as conducting an assessment of your compliance program.
  • The risk assessment is not designed to be an audit of every activity your company is doing; it’s designed to scan across the breadth of what your company is doing
  • The skill-set needs are changing.

Show Highlights

[01:41] Jack shares what led him to risk and compliance as a career path.
[03:51] How Jack crossed paths with LogicGate founders.
[04:34] Jack explains what is RAMP and how it benefits clients today.
[06:19] How companies can adopt continuous improvement within their compliance programs according to Jack.
[08:58] Some more examples of what you can do for continuous improvement.
[10:13] How things are changing in the near, medium and long term future in the risk and compliance world.
[13:24] The processes clients and companies have taken to ensure success and enabled them to move forward.
[15:00] A brief origin of Jack's other talent.

Resources:

  • Connect with Jack on LinkedIn
  • Connect with Jack on Twitter
  • Connect with Deloitte on LinkedIn
  • Deloitte US
  • Deloitte UK
  • Navigant Consulting
  • Huron Consulting
  • KPMG
  • LogicGate
  • Matt Kunkel LinkedIn

View Details

Top 3 Quotes

  • “I'm a firm believer that cyber security is very much a journey.”
  • “Do the basics and do them well—that's a strong foundation.”
  • “Doing security from a sustainable point of view is trying to develop the right people, the right processes and technologies, which would allow for cyber resilience against whatever the threat landscape might be.”

Show Highlights

[01:12] How Dominic got into his current position
[02:35] The answer to Megan's million dollar question
[03:16] Dominic shares his favorite story
[04:32] How small businesses can develop cyber security while staying in budget
[05:34] Megan agrees that CIS control set is a great tactical and practical way to begin
[06:14] Differentiating cyber security from corporate and enterprise needs
[08:18] Security issues in Canada and how it differs from anywhere else in the world
[09:30] What keeps Dominic up at night
[10:52] What is sustainable security and how to attain it
[12:18] Dominic tells how he got into comedy

Resources:

  • Cyber SC
  • Connect with Dominic on LinkedIn
  • Connect with Dominic on Twitter
  • Cyber SC Facebook
  • Cyber SC Twitter
  • Cyber SC YouTube Channel

View Details

Top 3 Quotes* “The more that you can show your customers that you're being a good steward with their data, the more they're likely to trust you. And from a reputational standpoint and a branding standpoint, that's always one of the best benefits and one of the reasons that consumers will choose one product or service over the other.” * “And I think if you look carefully, the CCPA is quite a blessing. It helps reduce expenses and monetize the information life cycle because you have a better understanding of what's under the hood in your company.” * “...you know there's not one silver bullet when it comes to preparing data for an information governance strategy, IG is essentially a multidisciplinary type of approach.”

Show Highlights[01:28] Rafael’s background in law and consulting
[02:35] Discussing Rafel’s company and beginnings
[04:36] The “Olympics of Privacy”
[05:59] A watershed moment in Compliance and Privacy
[08:05] Rafael’s personal connection to records in California
[09:05] The incredible moment Rafael received his birth records
[12:00] The “blessing” of CCPA
[14:11] Rafael’s personal opinion of CCPA
[16:19] Best practices for privacy and policy management
[19:30] Policy management systems
[21:04] How to read more about Rafael’s thoughts on these issues
[22:58] The Little Girl With The Big Voice
[24:03] Vendor Risk Management
[25:00] Being mindful of what’s outside your company walls as well as what’s within them

Resources:* Connect with Rafael on LinkedIn * Connect with Rafael on Twitter * Rafael’s Website * The Little Girl With the Big Voice

View Details

Top 3 Quotes* “Ultimately, you wouldn't go through any of these assessments unless it's driving business.” * “You don't want to be more secure just so you can be more secure, it's got to be a part of your overall business plan.” * “You have to start looking at this as a positive business driver instead of something that is just a line item that costs money at the end of the year.”

Show Highlights[01:15] How Bryan got to where he is now
[01:54] SAS 70 Solutions was born
[03:18] Bryan starts with Abacode
[04:21] The trend Bryan is witnessing in cybersecurity
[05:28] How companies determine what to apply
[07:01] What is FedRAMP?
[08:31] The FedRAMP process
[10:36] What to do internally before seeking outside counsel
[12:39] Bryan's value for customers in the market today
[15:41] GRC best practices and cybersecurity trends
[17:54] A different type of security that Bryan provides!

Resources:* Connect with Bryan on LinkedIn * Abacode Cybersecurity Website * Abacode Cybersecurity LinkedIn * Abacode Cybersecurity Twitter * Abacode Cybersecurity Facebook * Tampa Bay Dalmatian Rescue

View Details

Top 3 Takeaways* Transparency is very important to consumers right now. You want to make sure that you're clear about what's happening to personal information. * Have a full and complete understanding of who you share information with. * You don't want to be held liable for a vendor who misused data.

Show Highlights* [00:50] Sharing Donata’s background * [02:12] The nitty-gritty of regulations * [03:30] The CCPA Bill exodus * [05:49] Who does the CCPA Bill apply to? * [06:50] How does the CCPA affect consumers today? * [07:45] The fundamental differences between CCPA and GDPR * [10:40] CCPA penalty provisions * [11:52] Top three tactical tips to ensure compliance * [15:34] Will there be swifter actions for non-compliant companies? * [17:29] CCPA as a bellwether for future regulations. * [19:24] Trends to anticipate * [22:32] How Donata and Termageddon works with folks * [24:05] Termageddon's origin and the impetus behind

Resources:* Termageddon * Connect with Termageddon on Twitter * Connect with Termageddon on Facebook * Connect with Donata on LinkedIn * US Federal Privacy Law Tracker * GDPR * CCPA

View Details

Top 3 Takeaways

  • Defensibility is the ultimate concept that everybody drives to—whether they say it out loud or not.
  • In the security landscape we see today, there are many opportunities for improvement.
  • Even when I employ all of my resources, even when I put my best foot forward out there, failures can occur in my ability to protect data.

Show Highlights

[00:47] Neil introduces Asureti.

[01:23] What is SRCP?

[02:45] Do organizations have solid strategy around GRC principles today?

[04:50] The functions that need to be in place.

[07:36] The concept of "Good enough can be the cool."

[09:30] What should organizations be thinking about in terms of preparedness or potential consequences?

[11:09] The cliche of "Nothing bad has ever happened before.''

[12:54] Neil's encouragement to everyone.

Resources:

Asureti Website

Connect with Neil on LinkedIn

View Details

Show Highlights:
[00:22] A new taste of the podcast
[00:26] Meet your new host
[00:55] What to expect moving forward

Resources:
Connect with Megan on LinkedIn
Connect with Megan on Twitter
Connect with Megan on LogicGate

View Details

Top 3 Quotes

  • Risk Management is not really a profession. It's a competency that should be part of most degrees, if not all the degrees, at universities.
  • Most organizations have been disillusioned with the astrology version of risk management.
  • Sometimes, even a little quantification improves the quality of decision-making significantly.

Show Highlights

[01:17] Alex shares what the Risk Academy provides

[03:02] How Alex got into risk

[05:13] Alex's "controversial" blog

[08:04] Methodologies, strategies, importance

[13:52] What forces Alex to be controversial

[16:16] Brilliant idea of dumbing it down

[17:42] Approaching risk quantification

[20:37] The real question is, how complex can we go?

[23:29] How and when organizations should approach quantification

[26:00] An unrealistic fairytale based on averages

[29:03] Cultural difference in risk management approach

[30:00] Alex's predictions in the coming years

[34:17] Final nuggets of wisdom

Resources:

RISK-ACADEMY

Connect with Alex on LinkedIn

Connect with Alex on Twitter

Prospect Theory: An Analysis of Decision Under Risk by Daniel Kahneman and Amos Tversky

Judgment under Uncertainty: Heuristics and Biases by Daniel Kahneman and Amos Tversky

Foundations of Behavioral and Experimental Economics by Daniel Kahneman and Vernon Smith

How to Measure Anything: Finding the Value of ‘Intangibles’ in Business

Probability Management Conference

Monte Carlo Simulation

Moneyball

The Flaw of Averages: Why We Underestimate Risk in the Face of Uncertainty by Sam L. Savage

View Details

Top 3 Takeaways

  • It's tough to keep up without good technology
  • The transparency between parties is tough with financial institutions
  • A single point of failure can also be a single point of fraud

Show Highlights:

[02:50] Challenges that the smaller financial institutions have in their risk management programs

[07:13] The significant irony in financial institutions

[09:01] What Terri brings to the table

[10:50] Creating a culture of risk-awareness

[12:24] Reactive planning versus strategy planning

[14:25] The shift Terri has seen

[15:32] The unfortunate indicator

[16:45] Terri's opinion on banks reducing their operational costs

[19:43] One of the areas of challenge of heavily-regulated organizations

[21:37] What works and what doesn't for acquired financial institutions

[25:03] More tips for acquiring financial institutions

[26:49] Guilty by association

[27:59] Rounding up with the most shocking fraud story

Resources:

Secura Risk Management Website

Connect with Terri on LinkedIn

Connect with Terri on Twitter

Ozark Show

View Details

Top 3 Takeaways:

  • There's a big need in the marketplace for a technology that’s flexible and dynamic, yet easy to use from an end-business-user perspective.
  • “I took an educated bet that the market was right for a disruptive perspective.”
  • “Everyone is somewhere between ought-to-buy and needs-to-buy a GRC platform.”

Show Highlights:

[01:08] How the committee got started.

[2:53] Matt's handling of projects related to the Lehman Brothers’ fallout and the Madoff scandal

[3:11] Starting a custom app dev group at Navigant Consulting

[3:41] How he helped JPMorgan Chase’s mortgage bank get out of consent order with OCC

[4:11] What is the Dodd-Frank Ruling?

[4:54] The platform technology built for JPMorgan Chase to get compliant

[7:43] Why Chase ultimately went to Navigant

[9:25] The ‘lightbulb moment’ for Matt

[10:38] The search for different solutions

[11:50] Matt shares why he started LogicGate

[12:21] How did Matt pull the trigger and decide to leave his comfortable position and take that huge risk?

[14:18] The most interesting part of the platform

[15:36] How Matt views LogicGate

[16:31] Insight on how the company’s mascot (The GOAT) came to be

[18:05] What’s next for LogicGate?

Resources:

LogicGate's Website

Connect with Matt on LinkedIn

Connect with Matt on Twitter

Navigant Group

Dodd-Frank Ruling

GDPR

California Consumer Privacy Act

View Details

Top 3 Takeaways:

  • Focus on critical items first and make sure you have people and processes in place beforehand.
  • If technology is flexible, you can continue to scale and grow and change your processes over time.
  • Start simple, drive value in one place, and then build that over time.

Show Highlights

[1:35] Szuyin’s consulting background and why she got certed

[2:33] Finding out about LogicGate

[03:34] The common challenges getting started

[4:46] The number one thing Szuyin recommends

[6:23] Keep it simple and less is more

[7:58] What holds small and mid-sized companies in a status quo?

[12:36] Preparing and ensuring a successful launch and avoiding losing the momentum post-implementation

[15:14] The other big thing

[16:45] Processes involving high-level metrics and what to look for

[18:02] A brief tangent on fair risk methodology

[20:04] What trends and solutions are making the biggest impact?

[22:32] The key priority right now

[23:00] Using risk to inform business-making decisions

Resources:

LogicGate

Connect with Szuyin on LinkedIn

Read up on Szuyin’s Work on Medium

View Details

Top 3 Takeaways

  • It’s important to first establish what your company is trying to accomplish with its GRC program.
  • Frameworks are like the human body; you've got multiple systems involved. All those come together to help form a GRC program.
  • In light of data breaches, consumers are picking up on privacy. They're demanding better practices with their personal data.

Show Highlights

[01:09] How Michael got involved in GRC

[02:35] What frustrates Michael

[04:39] The GRC moves, changes, and challenges

[06:32] Why organizations need strategy around GRC

[09:17] Deciding what framework is the best fit

[13:37] The trends Michael sees and what it indicates

[14:56] Success metrics for GRC teams

[17:17] Defining agile and what’s behind the emergence

[20:09] The differentiating factors among GRC solutions

[21:26] Massive data breaches; how they will shape the future of GRC

[22:45] Michael answers a “loaded” question

Connect with Michael on LinkedIn

Connect with Michael on Twitter

GRC 20/20

GDPR

California Consumer Privacy Act

Ten Thousand Commandments

The Competitive Enterprise Institute

View Details

Top 3 Takeaways

  • A data model is the underlying architecture that underpins any GRC program.
  • We live in a world that is constantly moving, changing, and evolving. That’s why flexibility in business systems is key.
  • Flexibility means being able to put a program in place on day one, without a final vision of where it’s going—it can change and adapt to changing requirements along the way.

Show Highlights

[01:07] Matt’s background

[03:50] Why data models are important to an effective GRC program

[05:10] The problems with a traditional data model

[07:55] How a flexible data model is really different

[09:25] Why choose a flexible data model

[12:24] How data model flexibility is innovating how we do business

[13:48] What innovation is developing from a flexible data model

[15:42] Matt's advice

[16:18] How Matt helped companies overcome obstacles

Resources:

  • LogicGate's Website
  • Connect with Matt on LinkedIn
  • Connect with Matt on Twitter

View Details

Just like the billion-dollar GRC industry it covers, GRC & Me helps companies achieve their revenue goals while managing risk and compliance issues with integrity.

This podcast is perfect for you if:

  • You’re in a role concerned with corporate governance, risk management, or compliance (GRC)
  • You want to protect your company and your brand
  • You simply love GRC like Kelley does!

Tune in every month to learn from GRC experts and thought leaders, catch up on industry-shaping news, and better understand the decisions that drive results in your company.

Connect with Kelley on LinkedIn!