The GRC Podcast: Recent Episodes

Mark Graziano

Governance, Risk and Compliance (GRC) touches EVERY aspect of the business. However, most Security professionals still view their GRC colleagues as insensible pains in the ass with limitless creativity to introduce friction to anything they touch. The GRC Podcast is here to set the record straight. Valuable GRC isn't about making generic policies, implementing check the box controls and grinding business to a halt in the name of security. The GRC Podcast highlights the nuance of GRC operations, acknowledges the mistakes we've made, and most importantly, provides practical solutions to create more secure outcomes and better (internal and external) customer relations.

View Details

In today's episode we take a candid look at the efficacy of vendor risk management programs in the face of breaches. This time, we're reflecting on a conversation that pushed me out of my comfort zone and made me question the very fundamentals of vendor risk management. The startling realization that the well-trodden path of best practices might not hold all the answers spurred a much-needed debate on whether it's time to disrupt the status quo and embrace a more proactive stance in managing vendor risks.

We're challenging conventional wisdom, by evaluating the October 2023 breach of Okta despite the collective efforts of nearly 20,000 customers' vendor risk management programs. The episode takes you through a journey of introspection and industry critique, examining how traditional defensive strategies might not be enough and why a shift in perspective is crucial. We don't just outline the problems; we also explore what it means to safeguard against the inevitable issues and the importance of leading with the taboo in conversations that could redefine industry standards.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Ever found yourself in a tug-of-war between hard numbers and gut instinct? Brace yourself for a candid journey into the world of data, as we uncover the truth behind the numbers that drive our decisions. This episode is not just another number crunching monologue; it's a story-rich exploration of how metrics can mislead and the power of anecdotal evidence, as demonstrated in a memorable moment with Jeff Bezos and Lex Friedman.

With a dynamic blend of personal anecdotes and professional insights, we uncover the double-edged sword of metrics. Dissecting the manipulation of data to fabricate success and the unintended consequences of metric-driven incentives, it’s a reality check for any business professional. And for those grappling with measuring the success of a GRC program, get ready for a thought-provoking discussion that will leave you reevaluating your approach. No graphs or spreadsheets needed—just a healthy dose of skepticism and a reminder that sometimes, the stories behind the stats are the real gold.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

In this episode we unpack the often overlooked value of starting with manual routines in GRC and the strategic path to effective automation.

Key Takeaways:

  1. The Value of Manual Work: Although manual work is often viewed with disdain, it holds significant value in understanding the nuances of GRC processes. Manual routines force a deeper engagement with the components of a process, leading to a more comprehensive understanding of what "better" truly looks like.
  2. Understanding Before Automating: Jumping directly to automation solutions without a clear understanding of manual processes can lead to inefficiencies and a misalignment with organizational needs. A profound comprehension of manual components is crucial before deciding on the path to automation.
  3. Incremental Automation as a Strategy: Transitioning from manual to automated processes doesn't have to be a leap. Incremental, lightweight automations, introduced step by step, can be more cost-effective and easier for teams to adapt to. This approach allows for continuous improvement and helps distinguish between mere inconveniences and actual pain points.
  4. Case Study - The Evolution of Segment's Customer Trust Practices: We delve into Segment's strategic journey from entirely manual processes towards a comprehensive spectrum of automation, culminating in the implementation of a SaaS-based Customer Trust Center. Initially reliant on manual methods, Segment incrementally integrated various technologies and automated solutions into their workflow. This gradual evolution continued until reaching a pivotal moment where the decision to build in-house versus procuring a specialized tool was reassessed. Opting for a purpose-built solution marked a significant milestone, demonstrating the effectiveness of an iterative approach to automation that not only enhanced operational efficiency but also solidified the foundation for future scalability.
  5. Practical Insights for GRC Professionals: The discussion provides practical insights for GRC professionals on balancing the desire for automation with the reality of manual processes. It emphasizes the importance of being intimately familiar with the processes before automating them and showcases the tangible benefits of incremental improvements.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

In this episode, we delve into a widely accepted notion within the industry: the idea that compliance is not equivalent to security. While I don't disagree with this perspective, our discussion draws attention to the fact that compliance frameworks didn't just appear out of nowhere; they were developed in reaction to recurring detrimental effects on consumers.

We explore this concept further using one of my favorite analogies—the shopping cart theory—to underscore the importance of self-governance and the critical role integrity plays in our actions. Whether it's the simple act of returning a shopping cart as an individual or the complex responsibility of protecting customer data as a business, integrity lies at the heart of both.

However, the necessity for compliance brings with it a plethora of challenges. We delve into the ongoing conflict between the innovative spirit of information security and the perceived rigidity of compliance frameworks. Through relatable examples, such as navigating a crosswalk, I illustrate the intricate balance of risk mitigation, control design, and enforceable rules that shape our approach to maintaining both secure and ethical business practices.

This conversation goes beyond mere adherence to a checklist. It's about acknowledging that, although there is no singular approach to risk mitigation, a balanced integration of individual integrity, innovation, and compliance is crucial for the protection of our products and data.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Listen in as we tackle the gritty complexities of risk management within the sphere of Governance, Risk, and Compliance (GRC), highlighting the delicate dance between aspirational security protocols and the more achievable, pragmatic solutions. This discussion takes place through the lens of PCI DSS compliance and examines the interplay of power, liability, and practicality as companies navigate the prescriptive demands of payment card brands. This insights highlight the complex layers of risk management, unearthing the tug-of-war between what's ideal and what's doable in the world of Governance, Risk, and Compliance.

This narrative goes beyond mere compliance checklists; it's a candid exploration of how risk is offloaded to merchants and service providers, and the implications that have for everyone involved. Drawing from years of experience, I dissect the underlying motives of payment card brands and the resulting security awareness inadvertently driven by the PCI SSC. We grapple with the economic and social impact of technological changes, understanding the unintentional yet significant consequences of comprehensive system overhauls. By the end of our discussion, you'll have a richer appreciation for the nuanced realities that govern our transactions and the innovative thinking required to navigate this ever-evolving landscape.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Unlock a new perspective on GRC that intertwines innovation with customer-centric values. This segment shines a spotlight on the integral role of user experience in governance, risk, and compliance, advocating for a business approach that isn't merely beneficial but fundamentally the right thing to do. Drawing from the wisdom in Tony Fadell's book 'Build', the episode intricately examines the strategic decisions that kept Nest afloat, highlighting the broader implications for solution minded GRC professionals.

Prepare to challenge the status quo of traditional GRC as we dissect the necessity of thinking like a builder rather than a blocker. Insights from Nest's legal strategies underscore the importance of agile and creative problem-solving . This episode promises to arm you with the mindset to lead and influence across all aspects of a business, ensuring that your expertise in GRC is not just a back-office function but a pivotal force in crafting products and strategies that resonate with users and stand the test of legal and market challenges. Join us for a candid exploration into the art of blending GRC savvy with a proactive business ethos.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

In this conversation, Gina Gabriel shares inside information, tips and tricks for resume building that she accrued from over a decade of tech recruiting experience. Gina and I discuss the importance of resumes in career development and growth. We explore the resume review process, including what happens once job postings go live and resumes start coming in. We debunk common misconceptions about resumes and provide tips for making resumes memorable. We also discuss the value of referrals and networking in the job search process. Gina shares success stories of transforming resumes and offers insights into the storytelling aspect of resumes. Gina and I even conduct a live review of my actual resume, highlighting changes and recommendations. Gina provides information about her consulting services and offers free resources for resume improvement.

Unlock the secrets to transforming your job application from forgettable to formidable, as Gina and I share the tools you need to navigate the tumultuous waters of the job market. From uncovering the behind-the-scenes chaos of job postings to mastering the applicant tracking systems like Workday, our comprehensive chat is the beacon you've been seeking. Discover the potent combination of an impactful resume, the weight of employee referrals, and the nuanced art of tailoring your narrative to sail through the hiring process.

Step into the inner circle of application strategy, where we spill the insider details on making your resume resonate with recruiters and hiring managers alike. Through a live review of my actual resume, Gina and I show you firsthand how to stand out in the interview process by selling yourself as effectively as the slickest SaaS product. You'll learn how to format your resume to tell your professional story and how to wield your job titles like a seasoned marketer, ensuring your skills and experience capture the spotlight.

Concluding our journey, we explore the treasure trove of free resources that can elevate your job application toolkit to new heights, and Gina extends an open invitation to anyone seeking tailored advice for career advancement. Whether you're a fresh-faced job seeker or a seasoned professional, my conversation with Gina arms you with the strategies to not just land the interview, but to ace it and confidently step into your next career chapter. Join us, and let's turn the page together on your professional success story.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Join us for an insightful exploration of Security & GRC hiring with Tom Alcock from Code Red Partners. Tom illuminates their bespoke recruitment strategy, expertly aligning Security organizations with candidates who are not just technically proficient but also a cultural fit. We delve into the ever-changing world of Security & GRC employment, delivering actionable strategies for both industry novices and veterans. The conversation underscores the significance of perpetual learning and the power of networking in this rapidly evolving field.

Tom highlights the crucial role of community engagement in Security hiring, demonstrating how building a trusted network can open doors to extensive connections and opportunities. We discuss the pivotal moments when specialized firms like Code Red become invaluable, be it for large-scale recruitment drives or assembling foundational teams for emerging startups. This episode brims with insights for those contemplating the right time and approach to engage with recruitment experts who deeply understand the ins and outs of security organizations and the ever changing security landscape.

Wrapping up, we focus on Security & GRC career progression strategies. Tom provides pragmatic guidance on role transitions, from individual contributor to managerial positions, emphasizing the advantage of maintaining hands-on involvement in certain situations. We also venture into pathways leading to senior management and C-suite roles, sharing inspiring success stories and identifying the distinctive qualities of industry leaders. Tune in for a compelling discussion about forging a triumphant career in the dynamic world of Security & GRC.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

In this episode of the GRC Podcast, we sit down with Chris Honda, a seasoned Senior Security Analyst at Whistic, who walks us through the multifaceted world of Governance, Risk, and Compliance (GRC). With his unique journey into the world of Security, Chris sheds light on the transformative nature of cultivating GRC expertise and the value those skills can bring to the business and security landscapes.

GRC Unpacked: More Than Acronyms
Chris starts by demystifying GRC, breaking it down into its core components: Governance, Risk, and Compliance. He shares an accessible approach to explaining these concepts to non-experts, using relatable analogies like the Rosetta Stone, underscoring the importance of GRC as the lingua franca that bridges the gap between business operations and security imperatives.

The Human Element in InfoSec
Delving into the art of presenting at conferences, Chris emphasizes the need to bring one's personality into play. By humanizing InfoSec, he advocates for presentations that resonate on a personal level, which in turn fosters a more resilient and relatable security culture within organizations.

Career Trajectories in GRC
Reflecting on his own path, Chris discusses how asking the critical question "why" catalyzed his move from finance to security, highlighting the role of curiosity in driving career progression within GRC. He reassures listeners that a background in IT is not a prerequisite for a successful career in GRC, as the field welcomes diverse professional experiences.

Technical” Redefined
Chris challenges the misconception that one must be highly technical to succeed in security. He argues that problem-solving, communication, and understanding technology as a means to exceptional outcomes are just as crucial. This broader definition of 'technical' opens doors for GRC professionals to be recognized for their strategic and enabling contributions. (but also they should strive to have developer empathy and recognize stagnation in learning will significantly limit upward mobility, salary and future employability.)

The Convergence of Security and Privacy
Exploring the nuanced relationship between security and privacy, the discussion pivots to how these disciplines intersect within GRC frameworks. Chris provides insights into how evolving privacy laws create new opportunities for those passionate about privacy and compliance, demonstrating the dynamic nature of the GRC field.

The Specialist vs. Generalist Debate
Chris shares his experiences as a GRC generalist in a smaller company, weighing in on the benefits of wearing multiple hats against the deep focus of specialists in larger firms. He advocates for the value of generalist roles, highlighting their ability to manage a broad spectrum of GRC challenges and drive comprehensive security strategies.

Giving Back and Building Community
The episode wraps up with Chris reflecting on the importance of giving back to the GRC community. By volunteering and engaging in acts of kindness, professionals can cultivate a supportive network that not only fosters personal fulfillment but also strengthens the collective knowledge and resilience of the GRC industry.

Join us in this enriching discussion that promises to inspire both personal and professional growth, whether you're new to GRC or a veteran looking to reinvigorate your career with a fresh perspective.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Join us for a special year-end episode of the GRC podcast, where we revisit some of the most significant insights and dialogues from the past year. This episode is a compilation of valuable lessons and insights that have shaped our understanding of Governance, Risk, and Compliance (GRC) and provided practical solutions to common obstacles faced by GRC professionals.

In this episode:

  • Dustin Bailey underscores the importance of understanding the 'why' behind our actions, which not only strengthens stakeholder relationships but also fosters a unified team effort.

  • Steven Nguyen offers his unique insights and challenges us to be introspective about the value and necessity of the work we perform, viewing our services as products that provide business value and enjoyable user experience.

  • Patrick Ayerte illuminates the importance of personal branding and visibility within the workplace. He shares practical advice on how to make sure your work doesn't go unnoticed, a critical aspect for career advancement.

  • Jake Bernardes delves into privacy legislation, shedding light on its ethical implications and the importance of data protection, particularly for the next generation growing up in a digital age.

  • Daniel Redding emphasizes the role of simplicity and practicality in risk management, showcasing how effective context framing and pointed dialogues can facilitate risk identification, assessment, and mitigation.

  • Monica Smith discusses the importance of security transparency and the benefits of proactively communicating your organization's security culture and practices during the sales cycle.

  • Leif Dreizler highlights the transformative power of community networking and how it can lead to new opportunities for professional advancement, team performance and community growth.

  • Jeevan Singh breaks down walls between GRC and security engineering teams, stressing the importance of effective, consistent communication and team work.

  • Ariel Shin explores the practical application of GRC frameworks, demonstrating the need for user-friendly and accessible GRC practices, products and services.

  • The conversation concludes with Alex Bovee's insights on the growing need for scalable and automated identity and access management systems, particularly in an era where SaaS adoption is accelerating.

Whether you've followed us throughout the year or are tuning in for the first time, this episode offers valuable takeaways for GRC professionals at any career stage. Tune in to deepen your understanding of the principles that can guide you towards a successful and rewarding journey in the GRC world

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

In this episode of our podcast, we sit down with Alex Bovee, the CEO and co-founder of ConductorOne, to explore the crucial problem of identity and access management, a problem that is rapidly gaining complexity in the modern digital landscape. We delve into the potential risks and vulnerabilities that surface when companies fail to manage access efficiently. From dormant accounts of contractors off-boarded years ago to the worrying trend of over permissioning, Alex takes us on a deep dive into the spectrum of issues that underline identity management and discusses how they escalate as a company grows.

During our insightful conversation, Alex also illuminates how fundamentally, this problem is non-human scale, explaining why manual solutions simply don't cut it in a sprawling digital environment. By discussing the importance of an identity orchestration layer, scalable visibility, and making the secure option the path of least resistance, he emphasizes the necessity for modern, automated solutions for identity and access management, but at the same time, focusing on the need for these tools to be customizable to a company's specific pain-points. Balancing robust security with the demand for fast, efficient workflows forms the core backbone of Alex’s views.

Furthermore, our discussion veers towards future trends in identity management and how these trends will shape a new generation of identity security solutions. We examine the possible implications of creating composable building blocks of identity, catering to diverse users, enhancing user experiences, and leveraging emerging artificial intelligence technologies. Guiding us through ConductorOne's approach to these emerging challenges, Alex illuminates how companies can better navigate this critical, ever-evolving field of digital security.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Join Ariel Shin, Twilio's Product Security Team Lead, as she simplifies the complex topic of vulnerability management in governance, risk, and compliance (GRC). In this podcast, Ariel helps us grasp the various roles that stakeholders play, the essentials of policy and standards documents, and how vulnerabilities, risks, and incidents are connected. She clarifies technical terms like 'zero-day' and 'exploitability' and discusses why it's crucial for companies to be open about their security practices.

We also tackle the tricky subject of meeting compliance and security standards across different industries. Ariel uses the OWASP mobile checklist to highlight the challenges of applying one set of rules to all kinds of organizations and talks about the 'NIST peanut butter' approach in security discussions. We emphasize the need to communicate compliance requirements effectively to various audiences.

In the concluding part, Ariel and I discuss how GRC and developers can work together more effectively to manage vulnerabilities. We look at the obstacles in compliance and the importance of clear communication and influence in prompting developers to fix security issues. Ariel gives valuable advice on automated reporting and the best ways to report security matters to management.

So, tune in to get a clearer picture of vulnerability management, learn strategies for engaging with stakeholders, and gain insights into building a straightforward program that connects vulnerability management, security risk, and incident response.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Want to discover the key to bridging the gap between Governance, Risk, and Ever wondered about the bridge between Governance, Risk, and Compliance (GRC) and security engineering? Enter Jeevan Singh, Senior Staff Security Engineer at Rippling. Through his journey, Jeevan highlights the pivotal roles of active listening, clear communication, and mentorship. These are the tools that harmonize the objectives of GRC and security engineering, facets of the same coin that can occasionally clash within organizations.

Our conversation emphasizes the essence of collaboration in molding a unified culture. Drawing from Jeevan's successes, understand the depth of his rotational programs. They're not just about letting engineers touch various security domains but about teaching them to empathize, not just understand. As we venture further, Jeevan shares his perspective on the evolving landscape of GRC, especially with the emergence of workflow engineers adept at bridging team divides. A moment of reflection is also essential; we turn the lens inward, recognizing the unintentional challenges we might pose for our peers and exploring pathways to alleviate them with enhanced communication and clear documentation.

We end the conversation with Jeevan guiding us through the nuances of vendor security assessments comparing the roles of GRC and Security Engineers in the process, discussing the pivotal role of threat modeling, and the undeniable importance of diversity in sculpting a resilient security culture.

Join us on this enlightening exploration.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Join us for a conversation with Leif Dreizler, a dynamic figure and avid organizer in the InfoSec industry. While Leif is a skilled practitioner, his roles as a seasoned conference organizer, insightful blogger, and engaging podcast host allow his influence to extend well beyond the traditional workspace. In this episode, he generously unpacks his extensive knowledge on brand building and community engagement, underscoring the crucial participation of everyone, from novices to seasoned experts.

Leif takes us through his unique journey, emphasizing that there isn’t a one-size-fits-all approach to career development in the industry. With a myriad of options available, professionals can carve out their own paths, selecting the avenues that align best with their individual needs and aspirations. He shares insights from his experience organizing prominent conferences, including AppSec California, BSides SF, and Loco Moco Sec, and reflects on how these endeavors have been instrumental in shaping his career.

The episode dives into the significance of community engagement and networking for security professionals. Leif shares personal anecdotes and highlights the importance of active participation in diverse community initiatives, ranging from public speaking and conference proposals to blogging and podcasting. He offers practical tips for maximizing efficiency in your work, sharing strategies for smart blogging and effective repurposing of content across talks, presentations, and podcast appearances.

However, Leif’s narrative isn’t solely about personal brand cultivation. It’s also a testament to the myriad ways individuals can contribute to and engage with the larger community. He outlines the tangible benefits of active involvement, such as network expansion and the discovery of new job opportunities, and prompts listeners to reflect on how they, too, can contribute to and glean valuable insights from the community.

Tune in to explore Leif’s story and consider how you might enhance your engagement with the security community, fostering both personal and professional growth.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Have you ever thought about how customer trust and security are intertwined in business? Monica Smith, Head of Security, Risk and Compliance at Asana shares insights from Asana's innovative strategies to equip you with practical tools for building unwavering customer trust and designing effective enablement programs. Monica, with her extensive experience, enlightens us about the various terminologies, processes, and programs that Asana incorporates to instill trust.

We embark on an enlightening journey exploring how customer trust can streamline the vendor risk assessment process. Monica elaborates on the significance of sculpting a trust center that resonates with a broad audience, highlighting security while also double as a marketing tool. She highlights how the roll out of such a tool can aid a GRC program in optimizing resources to minimize time spent on triaging and responding to custom questionnaires. Monica also discusses the pivotal role of metrics collection, through trackable trust center metrics, in demonstrating value, securing budget for GRC teams, while also bolstering customer trust.

This episode is a treasure trove of robust strategies to build trust and maintain strong customer relationships. Join us for this insightful conversation with Monica and redefine your approach to customer trust and enablement.

For show notes, please visit The GRC Podcast website**.

Sign up for our Bi-Weekly Newsletter**

View Details

Welcome to the first episode of the GRC Podcast! Join host Mark Graziano as he introduces himself and takes you on a journey through his career in governance, risk, and compliance (GRC) from starting at an IT help desk to creating this very podcast. In this introductory episode, Mark opens up about the ups and downs of his career and the lessons he's learned along the way.

In the first chapter, Mark reflects on his initial years in the IT industry and his transition into the GRC space. He discusses his realization of the need to contribute more effectively to the industry and how that led him to create the GRC Podcast. Mark candidly talks about the challenges he faced and how he plans to use the podcast to challenge the GRC industry stereotype.

In the next segment, Mark talks about the importance of understanding business needs in GRC and the necessity of bridging the gap between engineers and C-level executives. He emphasizes the importance of focusing on outcomes rather than processes, and gives a sneak peek into the topics that will be discussed in future episodes, such as building a successful security team and the role of AI in automating tasks.

The final chapter is an open invitation for all GRC professionals and security leaders to join the community-first podcast. Mark shares his vision of the podcast as a platform for sharing insights and experiences, addressing common issues faced by GRC professionals, and exploring ways to improve programs across different organizations.

Key Takeaways:

  • Mark's journey from IT help desk to creating the GRC Podcast.
  • The critical role of understanding businesses needs in GRC.
  • The importance of focusing on outcomes rather than the process.
  • The potential of AI in automating tasks in the GRC space.
  • Invitation to join the community-first podcast for GRC professionals and security leaders.

View Details

In this podcast episode, we unravel the intricate world of risk management, shedding light on its role in our everyday lives and its influence on GRC (Governance, Risk and Compliance). Daniel Redding guides listeners through a comprehensive understanding of risk management, exploring how to effectively navigate and control it. They break down the complex elements of risk, including the interplay of probability and severity, and introduce the often overlooked factors that can amplify risk. This discussion brings risk management back to basics, reinforcing the importance of investing effort proportionate to the potential return on investment.

The episode also focuses on determining the criticality of security incidents and how to prioritize responses effectively. Daniel emphasizes on transforming complex elements into manageable metrics, enabling listeners to compare and analyze effectively. Key factors such as system revenue, regulatory compliance requirements, data quantity, strategic priority, and availability are discussed. Daniel underscores the importance of identifying potential system hotspots to minimize future risk, fostering a proactive approach to risk management.

Finally, the episode arms listeners with effective communication strategies to present potential risks to executives in a clear and comprehensible manner. It underscores the importance of quantifying risk using a balanced blend of data and estimates. Daniel stresses the need for making specific, actionable recommendations and assigning responsibility for risk solutions. The ultimate goal is to demystify risk management, ensuring that organizations focus on what matters most and are clear in their methods of measuring and communicating risk. Tune in to this enlightening episode and start navigating the realm of risk management and GRC with increased confidence and expertise.

View Details

Get ready for a dynamic conversation with our expert guest, Jake Bernardes, as we delve into the often ambiguous territory of privacy legislation. Ever considered how data collection could impact you or the younger generation? We deep-dive into this pressing topic, examining how businesses are collecting data, and the significant impact it may have on all of us. We highlight how the changing nature of data and its accessibility emphasize the vital role of privacy laws in our evolving digital landscape.

Join us as we traverse the labyrinth of privacy laws across different countries and uncover the complexities businesses navigate to avoid certain regulations. We discuss the implications of the Patriot Act in the U.S., and the hurdles faced in passing privacy laws due to lobbying and the influence of large corporations. Jake offers enlightening perspectives on protecting ourselves from not just the collection but also potential misuse of our data.

Lastly, we venture into the realm of AI and the implications it brings for personal data privacy. We consider the risks AI poses, the need for robust privacy programs, and the importance of understanding new AI security standards. What would a global privacy framework look like and how can businesses demonstrate compliance? Our conversation concludes by emphasizing the urgency for an international approach to privacy, and the necessity of businesses to build trust with consumers in this new age of data privacy. This conversation is one you won't want to miss!

View Details

Ready to reframe your perspective on team management? Join us as we chat with Patrick Ayrte, Business Security Lead at Twilio, who shares his journey from being an individual contributor (IC), to a manager. Patrick's unique philosophy of leadership, deeply rooted in empathy and recognizing individual personalities within a team, might just inspire you to rethink your own approach.

Our conversation with Patrick is not just about leadership; it's a deep dive into the essence of human connection in a professional setting. Drawing upon his cultural background from Ghana and his experience as a music director, Patrick seamlessly blends these diverse perspectives into his management style. We unpack the importance of transparency and trust in manager-employee relationships and how understanding business dynamics can bolster career growth. Patrick also shares some interesting strategies he uses to build relationships within his team.

Finally, we explore Patrick's progressive strategies for working cross-functionally with high-level executives and in tailoring requirements to the business context. Patrick emphasizes the need to understand the 'why' behind regulations and requirements. We conclude the episode with a fascinating look into Patrick's personal projects, like teaching cloud engineering and creating music as an expression. This engaging conversation with Patrick ultimately challenges leaders to focus more on people than outcomes for team success.

View Details

Vendor risk management is a crucial aspect of Governance, Risk, and Compliance (GRC) for organizations of all sizes. Mark Graziano interviews Steven Nguyen, Business Information Security Officer (BISO) for Twilio Data & Applications, who shares his valuable insights as both as a customer and as a vendor throughout the sales and procurement process.

In this episode we unpack: 

  • The real-world issues with antiquated approaches (e.g., monolithic, one-size fits all questionnaires)
  • The necessity of understanding business context when assessing vendors
  • How the quality of questions asked to vendors trumps quantity, leading to improved transparency and honesty.
  • Security contract negotiation best practices and exception considerations
  • The importance of early engagement (shifting left) of security teams in the sales process.
  • A mindset shift in viewing GRC programs as service-oriented products, catering to both internal and external customers.

Don't miss this episode packed with valuable insights and relatable stories. Tune in now to equip yourself with practical tools for your journey to GRC mastery!

View Details

Dive into the world of Governance, Risk, and Compliance (GRC) with our first podcast episode, featuring an enlightening conversation with Dustin Bailey, former Security Lead at Twilio Segment. Gain valuable insights on how to become a more proficient GRC professional, and discover the secrets to implementing a robust and impactful GRC program.

In this episode we explore:

  • The distinct roles and approaches of consultants vs. internal resources in GRC;
  • Bridging the gap between academic GRC theories and real-world application;
  • The importance of aligning GRC initiatives with your company's business objectives;
  • Adopting a collaborative approach as a true business partner, rather than an isolated function; and
  • The relevance of GRC principles in everyday life and diverse career paths.

Don't miss Dustin's personal testament to the power of GRC principles, as his home's Uninterruptible Power Supply (UPS) saves the day during our interview! Tune in now to kickstart your journey to GRC mastery.

View Details

Under Construction