Podcasts about GRC

  • 510PODCASTS
  • 1,978EPISODES
  • 47mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 25, 2025LATEST

POPULARITY

20172018201920202021202220232024

Categories



Best podcasts about GRC

Show all podcasts related to grc

Latest podcast episodes about GRC

AI in Action Podcast
ServiceNow Series E206: 'Redefining Security Solutions' with Alert Enterprise's Yogesh Ailawadi

AI in Action Podcast

Play Episode Listen Later Aug 25, 2025 17:20


Today's guest is Yogesh Ailawadi, Head of Products & Innovation - Identity, Safety and Security at Alert Enterprise. Founded in 2007, Alert Enterprise's mission is the seamless convergence of advanced physical access control, identity management and workspace automation. Their solutions are designed to empower businesses with secure, flexible and efficient work environments, catering to the dynamic needs of today's workforce. They understand that in the digital era, the security of physical and digital assets is paramount.Yogesh leads Alert Enterprise's global product management and solutions engineering teams and brings over 15 years of experience in information security, identity and access governance across IT, Physical and OT systems. He has led global deployments of PIAM/IAM solutions for Fortune 100/500 customers across various industries. Yogesh is well versed in industry regulatory standards with a deep understanding of engineering concepts and technologies, and their usage in the security domain.In the episode, Yogesh discusses:0:00 An insight into his 20-year career in security, product and innovation3:10 Pioneering physical security governance across critical industries at Alert Enterprise5:27 Expanding physical GRC by integrating with the ServiceNow platform8:04 Seeing a high-demand from large, regulated industries using ServiceNow workflows10:07 Product live on ServiceNow with focus on AI-driven access solutions11:39 Focusing on product innovation, scaling through global partners13:42 Bringing physical security workflows and AI use cases to ServiceNow

Business of Tech
Navigating SaaS Management and AI: Key Trends for MSPs from ChannelCon 2025 with John Harden

Business of Tech

Play Episode Listen Later Aug 23, 2025 15:41


Dave Sobel interviews John Harden, the director of strategy and technology evangelism at Auvik, discussing the evolution of SaaS management and its growing adoption in the industry. Since Auvik's acquisition of SaaSlio in 2022, the company has invested significantly in engineering efforts to enhance its SaaS management capabilities. Harden highlights the increasing need for visibility into SaaS applications due to rising cybersecurity threats and the growing importance of AI in business environments. He emphasizes that many organizations are now recognizing the necessity of understanding their SaaS assets, particularly in light of the proliferation of AI tools.The conversation delves into the different ways organizations are consuming AI, with smaller companies typically using AI through SaaS applications, while larger organizations may develop their own models via APIs. Harden explains how Auvik's SaaS management platform provides visibility into both categories, allowing businesses to monitor AI usage and manage potential risks associated with shadow IT. He also discusses the recent release of SaaSOps, which enhances visibility and integrates with popular tools to provide deeper insights into API usage and license management.As organizations begin to shift back to on-premises servers due to the high costs associated with AI workloads, Auvik has responded by introducing server management capabilities. Harden notes that this new feature allows for comprehensive monitoring of on-premises infrastructure, ensuring that businesses can effectively manage their IT assets regardless of where they are hosted. This adaptability is crucial as companies navigate the complexities of their IT environments, whether they are utilizing cloud services or traditional on-premises solutions.Looking ahead, Harden expresses optimism about the growth of compliance and governance, risk, and compliance (GRC) solutions, which he believes will foster stronger relationships between managed service providers (MSPs) and their clients. He emphasizes the importance of asset visibility in achieving compliance and cybersecurity goals, as well as in developing AI strategies. By continuing to expand its asset visibility portfolio, Auvik aims to support MSPs in meeting the evolving needs of their customers in a rapidly changing technological landscape. All our Sponsors: https://businessof.tech/sponsors/ Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/ Support the show on Patreon: https://patreon.com/mspradio/ Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com Follow us on:LinkedIn: https://www.linkedin.com/company/28908079/YouTube: https://youtube.com/mspradio/Facebook: https://www.facebook.com/mspradionews/Instagram: https://www.instagram.com/mspradio/TikTok: https://www.tiktok.com/@businessoftechBluesky: https://bsky.app/profile/businessof.tech

Innovation in Compliance with Tom Fox
Operationalizing Trust at Scale: Evolving Compliance: Neta Meidav on the Diligent Acquisition and AI Integration

Innovation in Compliance with Tom Fox

Play Episode Listen Later Aug 21, 2025 15:29


Innovation comes in many areas, and compliance professionals must be ready for and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. Today, we conclude our 3-part podcast series sponsored by Diligent with Jessica Czeczuga, Amanda Carty and Neta Meidav In this Part 3, Tom is joined by Neta Meidav, Managing Director of Ethics & Compliance at Diligent for a dive into technology innovations at Diligent.     In this episode, Tom visits with Neta about her recent transition to Diligent following its acquisition of her GRC entity Vault. Neta discusses the strategic reorganization at Diligent that underscores their commitment to compliance technology, and how this alignment bodes well for the future of their technology. She also sheds light on the integration of AI within compliance solutions, exploring its transformative impact on risk prediction, investigation processes, and operational efficiency, while emphasizing the enduring importance of human expertise in ethical decision-making.   Key Highlights   ·      The Acquisition Journey ·      Role and Responsibilities at Diligent ·      AI and Compliance Technology ·      Predictive Risk and Future of AI in Compliance   Resources: ⁠Neta Meidav on LinkedIn ⁠⁠Diligent⁠   Tom Fox ⁠Instagram⁠ ⁠Facebook⁠ ⁠YouTube⁠ ⁠Twitter⁠ ⁠LinkedIn

CISO-Security Vendor Relationship Podcast
I Just Can't Communicate With the Business. I've Tried Condescension AND Derision.

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Aug 19, 2025 35:44


All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Andy Ellis (@csoandy), principal of Duha. Joining us is Gary Chan, CISO, SSM Health. Be sure to check out Gary's security mentalism website: https://www.gschan2000.com. In this episode: Decision-making with incomplete information Translation beats technical expertise Influence trumps authority for CISOs Technical prowess creates adversaries Huge thanks to our sponsor, Vanta Automate, centralize, & scale your GRC program with Vanta. Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.  

Innovation in Compliance with Tom Fox
Gaurav Kapoor on Risk Management and the Role of AI in GRC

Innovation in Compliance with Tom Fox

Play Episode Listen Later Aug 19, 2025 27:43


Innovation comes in many areas, and compliance professionals need to be ready for it and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, Tom Fox interviews Gaurav Kapoor, Vice Chairman, Co-Founder and Board Member of MetricStream, discussing his extensive professional background, from co-founding MetricStream to his current focus on customer intimacy amid AI market disruptions. Kapoor delves into the evolving landscape of risk management, emphasizing the importance of midyear reviews and integration of various risk themes like operational risk, audit compliance, and cybersecurity. He elaborates on the role of AI in GRC, stating how generative and agent AI can streamline compliance processes and enhance risk management strategies. The conversation also touches on the increasing significance of cybersecurity, geopolitical instability, and climate impact on risk assessment. Kapoor highlights the shift from compliance to a more resilient and risk-aware culture within organizations. Key highlights: Gaurav Kapoor's Professional Journey The Importance of July in Risk Management AI's Role in GRC Emerging Risks and AI Applications Counseling Boards on Risk Management Top Concerns for the Second Half of 2025 Evolving Role of Compliance and Risk Officers Resources: MetricStream Website and on LinkedIn Gaurav Kapoor on LinkedIn Tom Fox Instagram Facebook YouTube Twitter LinkedIn

Cyber Security Headlines
NFC fraud reappears, Canada government breach, Zoom's critical flaw

Cyber Security Headlines

Play Episode Listen Later Aug 15, 2025 8:08


New wave of NFC relay fraud, call hijacking, and root exploits in banking sector Canada's House of Commons suffers cyberattack Zoom fixes critical Windows client flaw that could enable privilege escalation Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

Cyber Security Headlines
Week in Review: ShinyHunters-Scattered Spider merge, DARPA AI prize, Water infrastructure volunteers

Cyber Security Headlines

Play Episode Listen Later Aug 15, 2025 30:29


Link to episode page This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Zalewski, co-host, Defense in Depth Thanks to our show sponsor, Vanta Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines All links and the video of this episode can be found on CISO Series.com    

Cyber Security Headlines
Court filing system hack explained, PA AG weighs in on attack, Fortinet attacks raise concerns

Cyber Security Headlines

Play Episode Listen Later Aug 14, 2025 7:22


Hack of federal court filing system exploited security flaws known since 2020 Pennsylvania attorney general says cyberattack knocked phone, email systems offline Spike in Fortinet VPN brute-force attacks raises zero-day concerns Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

Cyber Security Headlines
Fortinet SSL VPNs getting hammered, The Netherlands critical infrastructure compromise, Africa the most targeted for cyber attacks

Cyber Security Headlines

Play Episode Listen Later Aug 13, 2025 7:26


The hits just keep on coming Where's the Little Dutch Boy when you need him? I felt the ransomware down in Africa Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines Find the stories behind the headlines at CISOseries.com

Cyber Security Headlines
North Korean crypto theft, Microsoft rolls out back up, four charged in global scheme

Cyber Security Headlines

Play Episode Listen Later Aug 12, 2025 9:07


North Korean crypto theft Microsoft rolls out PC back up during attack U.S. charges four in $100M global fraud scheme Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

Cyber Security Headlines
DARPA code prize, ScarCruft adds ransomware, Columbia breach tally

Cyber Security Headlines

Play Episode Listen Later Aug 11, 2025 8:21


DARPA awards $4 million prize for AI code review at DEF CON North Korea ScarCruft group adds ransomware to its activities Columbia University hack affects over 860,000 Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines Find the stories behind the headlines at CISOseries.com.  

La Commission Normandeau-Ferrandez
Le Midi avec Denis Lévesque Vendredi 8 août 2025

La Commission Normandeau-Ferrandez

Play Episode Listen Later Aug 8, 2025 43:20


Voici l’essentiel de l’épisode du vendredi 8 août 2025 pour l’émission Le midi: Montée spectaculaire du souverainisme chez les 18 à 34 ans, entrevue avec Pascal Bérubé; La ministre Guilbault met en place une «cellule de restructuration» de la Société de l'assurance automobile du Québec (SAAQ); Analyse de la scène politique provinciale avec Christian Dufour; À Havelock: «Les patrouilleurs de la GRC nous suivent» -Michel Ménard; Pierre Moreau devient le représentant du gouvernement au Sénat. Voir https://www.cogecomedia.com/vie-privee pour notre politique de vie privée

Innovation in Compliance with Tom Fox
Operationalizing Trust at Scale: A Conversation with Amanda Carty on Compliance and AI

Innovation in Compliance with Tom Fox

Play Episode Listen Later Aug 7, 2025 15:29


Innovation comes in many areas, and compliance professionals must be ready for and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. Today, we begin a 3-part podcast series sponsored by Diligent with Jessica Czeczuga, Amanda Carty and Neta Meidav In Part 2, Tom is joined by Amanda Carty, GM Compliance Solutions at Diligent.    Carty shares insights from her decade-long experience in the GRC field and offers detailed perspectives on how leaders can model ethical behavior within their organizations. The conversation dives into how Diligent helps companies assess and document leadership effectiveness and the role of AI in enhancing compliance initiatives. Carty emphasizes the necessity of leaders acting as ambassadors of culture and the impact of measurable outcomes in compliance programs. The episode also explores the integration of AI and chatbots to provide real-time compliance support to employees, ensuring efficiency and ease of access to crucial information.  Key Highlights  ·      Importance of Tone at the Top ·      Leadership and Ethical Culture ·      AI in Compliance ·      Employee Engagement and Technology ·      Actionable Takeaways for Compliance Professionals  Resources: ⁠Amanda Carty on LinkedIn ⁠⁠Diligent⁠  Tom Fox ⁠Instagram⁠ ⁠Facebook⁠ ⁠YouTube⁠ ⁠Twitter⁠ ⁠LinkedIn

ITSPmagazine | Technology. Cybersecurity. Society
Solving GRC Fatigue: How AI Is Helping Compliance Teams Do More With Less | An E-V-E GRC Brand Origin Story with Anders Søborg, Co-Founder of Eve, and Mark Humphrey

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 5, 2025 41:47


Governance, risk, and compliance (GRC) has long been burdened by heavy manual processes, slow assessments, and limited visibility. In this Brand Story episode, Sean Martin and Marco Ciappelli are joined by Anders Søborg, Co-Founder of Eve, and Mark Humphrey, who brings two decades of fraud and cybersecurity experience to the team. Together, they unpack how Eve is challenging traditional GRC tools by offering something entirely different: automation with evidence-based intelligence at its core.Anders shares how his experience as Chief Risk Officer and partner at major firms like Ernst & Young and PwC shaped Eve's mission. He describes a world where compliance doesn't have to mean complexity. Eve's AI engine evaluates more than a thousand controls in under 15 minutes—surpassing manual reviews that could take weeks—and goes a step further by offering recommendations, not just red flags.This isn't about replacing people. It's about helping overwhelmed compliance, risk, and audit teams regain control. Mark emphasizes how Eve operates like a true partner, delivering support with no ego and full transparency. Their approach combines deep regulatory knowledge, contextual AI agents trained on real-world frameworks, and a clear respect for data sovereignty and privacy—an essential requirement for global pharma, financial, and consulting clients already relying on the platform.More than a dashboard, Eve acts as an intelligent engine embedded into existing workflows via API, making it a natural complement—not a competitor—to existing GRC platforms. The platform is customizable, evidence-driven, and built with firsthand knowledge of what compliance professionals actually need: clear guidance, real-time answers, and fewer repetitive tasks.The episode leaves listeners with a compelling question: what if your compliance program could coach your team, reduce audit costs, and provide instant visibility—without sacrificing accuracy or control?Learn more about E-V-E GRC: https://itspm.ag/eve-grc-99Note: This story contains promotional content. Learn more.Guests:Anders Søborg, Co-founder, Director at E-V-E GRC | On LinkedIn: https://www.linkedin.com/in/anders-s%C3%B8borg-3826702/Mark Humphrey, Senior Sales and Channel Director EMEA at E-V-E GRC | On LinkedIn: https://www.linkedin.com/in/m-humphrey-mba-0020192b1/ResourcesRedefine Compliance. Unleash Your Potential with E-V-E GRC. Command Compliance: https://itspm.ag/e-v-e-i1mlLearn more and catch more stories from E-V-E GRC: https://www.itspmagazine.com/directory/evegrcLearn more about ITSPmagazine Brand Story Podcasts: https://www.itspmagazine.com/purchase-programsNewsletter Archive: https://www.linkedin.com/newsletters/tune-into-the-latest-podcasts-7109347022809309184/Business Newsletter Signup: https://www.itspmagazine.com/itspmagazine-business-updates-sign-upAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

Paul's Security Weekly
Weekly Enterprise Security News and Tips on Building Security From Day 1 - Guillaume Ross - ESW #418

Paul's Security Weekly

Play Episode Listen Later Aug 4, 2025 105:52


The Weekly Enterprise News (segments 1 and 2) This week, we've had to make some last minute adjustments, so we're going to do the news first, split into two segments. This week, we're discussing: Some interesting funding Two acquisitions - one picked up for $250M, the other slightly larger, at $25 BILLION Interesting new companies! On the 1 year anniversary of that thing that happened, Crowdstrike would like to assure you that they're REALLY making sure that thing never happens again Flipping the script How researchers rooted Copilot, but not really talks to check out at Hacker Summer Camp detection engineering tips the Cloud Security Alliance has a new AI Controls Matrix sending in the National Guard to handle a breach! and how to read an AI press release Interview: Guillaume Ross on Building Security from Scratch Guillaume shares his experiences building security from scratch at Canadian FinTech, Finaptic. Imagine the situation: you're CISO, and literally NOTHING is in place yet. No policies, no controls, no GRC processes. Where do you start? What do you do first? Are there things you can get away with that would be impossible in older, well-established financial firms? Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-418

Enterprise Security Weekly (Audio)
Weekly Enterprise Security News and Tips on Building Security From Day 1 - Guillaume Ross - ESW #418

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 4, 2025 105:52


The Weekly Enterprise News (segments 1 and 2) This week, we've had to make some last minute adjustments, so we're going to do the news first, split into two segments. This week, we're discussing: Some interesting funding Two acquisitions - one picked up for $250M, the other slightly larger, at $25 BILLION Interesting new companies! On the 1 year anniversary of that thing that happened, Crowdstrike would like to assure you that they're REALLY making sure that thing never happens again Flipping the script How researchers rooted Copilot, but not really talks to check out at Hacker Summer Camp detection engineering tips the Cloud Security Alliance has a new AI Controls Matrix sending in the National Guard to handle a breach! and how to read an AI press release Interview: Guillaume Ross on Building Security from Scratch Guillaume shares his experiences building security from scratch at Canadian FinTech, Finaptic. Imagine the situation: you're CISO, and literally NOTHING is in place yet. No policies, no controls, no GRC processes. Where do you start? What do you do first? Are there things you can get away with that would be impossible in older, well-established financial firms? Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-418

Paul's Security Weekly TV
Weekly Enterprise Security News and Tips on Building Security From Day 1 - Guillaume Ross - ESW #418

Paul's Security Weekly TV

Play Episode Listen Later Aug 4, 2025 105:52


The Weekly Enterprise News (segments 1 and 2) This week, we've had to make some last minute adjustments, so we're going to do the news first, split into two segments. This week, we're discussing: Some interesting funding Two acquisitions - one picked up for $250M, the other slightly larger, at $25 BILLION Interesting new companies! On the 1 year anniversary of that thing that happened, Crowdstrike would like to assure you that they're REALLY making sure that thing never happens again Flipping the script How researchers rooted Copilot, but not really talks to check out at Hacker Summer Camp detection engineering tips the Cloud Security Alliance has a new AI Controls Matrix sending in the National Guard to handle a breach! and how to read an AI press release Interview: Guillaume Ross on Building Security from Scratch Guillaume shares his experiences building security from scratch at Canadian FinTech, Finaptic. Imagine the situation: you're CISO, and literally NOTHING is in place yet. No policies, no controls, no GRC processes. Where do you start? What do you do first? Are there things you can get away with that would be impossible in older, well-established financial firms? Show Notes: https://securityweekly.com/esw-418

Enterprise Security Weekly (Video)
Weekly Enterprise Security News and Tips on Building Security From Day 1 - Guillaume Ross - ESW #418

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 4, 2025 105:52


The Weekly Enterprise News (segments 1 and 2) This week, we've had to make some last minute adjustments, so we're going to do the news first, split into two segments. This week, we're discussing: Some interesting funding Two acquisitions - one picked up for $250M, the other slightly larger, at $25 BILLION Interesting new companies! On the 1 year anniversary of that thing that happened, Crowdstrike would like to assure you that they're REALLY making sure that thing never happens again Flipping the script How researchers rooted Copilot, but not really talks to check out at Hacker Summer Camp detection engineering tips the Cloud Security Alliance has a new AI Controls Matrix sending in the National Guard to handle a breach! and how to read an AI press release Interview: Guillaume Ross on Building Security from Scratch Guillaume shares his experiences building security from scratch at Canadian FinTech, Finaptic. Imagine the situation: you're CISO, and literally NOTHING is in place yet. No policies, no controls, no GRC processes. Where do you start? What do you do first? Are there things you can get away with that would be impossible in older, well-established financial firms? Show Notes: https://securityweekly.com/esw-418

CXOInsights by CXOCIETY
PodChats for FutureCIO: Strategies for LCNC audit workflow builders in 2026

CXOInsights by CXOCIETY

Play Episode Listen Later Aug 4, 2025 22:33


Gartner predicts that by 2026, developers outside formal IT departments will account for at least 80% of the user base for low-code development tools.While citizen developers boost agility, decentralised creation brings new risks in the form of shadow IT, fragmented systems, data silo sprawl and data exposure, and compliance gaps.But with proper leadership, LCNC can empower audit and other teams to innovate quickly while staying aligned with enterprise goals.In this PodChats for FutureCIO, Leonard Tan, regional director for Singapore, Malaysia, Brunei and Greater China at OutSystems shares his observations and perspective on the essentials for LCNC audit workflow builders.Leonard, welcome to PodChats for FutureCIO.1.       Briefly give us a state of the low-code/no-code (LCNC) adoption in Asia in 2025. 2.       What are LCNC Audit Workflow Builders? What are the strategic objectives for adopting these? 3.       What governance model and policies must be enforced to effectively manage decentralised citizen development of audit workflows? 4.       How do these LCNC platforms ensure compliance with diverse regional data privacy regulations and regulatory frameworks across Asia? 5.       How do organisations maintain an up-to-date inventory and ensure consistent oversight of all LCNC audit workflows developed centrally and departmentally? Who should be in-charge of this?6.       List one proven way LCNC audit tools are adequately integrated with core enterprise systems (ERP, GRC, data lakes) for seamless data sharing, reporting, and end-to-end auditability of critical processes? 7.       What specific training, support frameworks, and guardrails must be provided to non-IT users to empower them to build compliant and effective audit workflows? 8.       How can leaders regularly assess and mitigate risks (including auditing the audit workflows themselves for integrity and accuracy) stemming from rapid, decentralised development, and ensure automated compliance reporting? Who should be leading/doing this?9.       Closing off our PodChats, what key metrics and KPIs will organisations use to track/measure the effectiveness, efficiency, compliance, and overall success of their LCNC audit workflow initiatives? 

Great Lakes Fishing Podcast
GRC Trolling Flies with Patrick Yohon - Great Lakes Fishing Podcast Episode #265

Great Lakes Fishing Podcast

Play Episode Listen Later Jul 28, 2025 19:43


We're talking fishing with Patrick Yohon from GRC Trolling Flies in New York. Patrick started GRC while truck driving and has built it into one of the most popular lure manufacturers in Great Lakes fishing. Patrick makes trolling flies, laker bells, meat rigs, and much more. Today's conversation is from the Greater Niagara Fishing Expo back in February. For more Great Lakes fishing information, visit https://fishhawkelectronics.com/blog/

State of Play: Summer Games
Bonus Episode 3: Summer, Soccer, and Saudi

State of Play: Summer Games

Play Episode Listen Later Jul 28, 2025 23:03


Summer, Soccer, and SaudiFor credits and this episode's transcript, visit globalreportingcentre.org/state-of-play/bonus-episode-3-summer-soccer-and-saudi/State of Play is produced by the Global Reporting Centre (GRC) and distributed by PRX. The GRC is an editorially independent journalism organization based at the UBC School of Journalism, Writing, and Media. Founded in 2016, we are leaders in doing global journalism differently. We innovate industry practice, educate the next generation, and promote greater equity in journalism.Learn more about the GRC: globalreportingcentre.org | Make a tax-deductible donation: globalreportingcentre.org/donate

Risk Management Show
AI Risk Management: Guardrails You Must Implement Now with Aayush Choudhury

Risk Management Show

Play Episode Listen Later Jul 24, 2025 11:32


AI Risk Management is essential, and in this episode, we discussed the critical guardrails you must implement now to keep your AI applications secure and trustworthy. Featuring Aayush Choudhury, CEO of Strut Automation, this conversation delves into key strategies for dependability in AI systems, tackling challenges like data leaks, unauthorized access, and prompt injection.  Aayush brings deep expertise in GRC automation, sharing insights on ISO 42001, NIST AI RMF, and OWASP's top 10 for AI security. If you're navigating AI risk management in customer-facing or internal applications, this episode offers valuable guidance on designing robust frameworks and controls from the start. Learn how to safeguard sensitive information and ensure responsible AI use while staying ahead in an evolving digital landscape. If you want to be our guest or suggest someone, send your email to info@globalriskconsult.com with "Guest Suggestion" in the subject line.

The Ethics Experts
Episode 223 - Anitha Vittal

The Ethics Experts

Play Episode Listen Later Jul 21, 2025 47:18


In this episode of The Ethics Experts, Nick welcomes Anitha Vittal.Anitha is recognised as a global ethics, risk, compliance and internal audit leader with proven experience and expertise in establishing Centres of Excellence at GCCs across industry verticals.A passionate professional, she has over 23 years of service in leading and developing high performing teams across India, Europe and US markets. Her engagements include - internal audit, risk management, compliance, business process and financial compliance, data privacy, SoX, GRC program management, digitisation.

Cyber Work
From security audits to privacy consulting: Building a GRC practice | Will Sweeney

Cyber Work

Play Episode Listen Later Jul 21, 2025 42:20 Transcription Available


Get your FREE Cybersecurity Salary Guide: https://www.infosecinstitute.com/form/cybersecurity-salary-guide-podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcastWill Sweeney, founding and managing partner of Zaviant, joins the Cyber Work Podcast to discuss the evolving landscape of data privacy and GRC (governance, risk and compliance). With experience overseeing complex information security audits for Fortune 100 companies, Will shares insights on everything from the key differences between security auditing and implementation to whether privacy regulatory frameworks will continue multiplying or begin consolidating. He offers practical advice for GRC aspirants, emphasizing the importance of understanding core security processes rather than getting lost in framework structures. Will also discusses the challenges of starting a consultancy practice and provides valuable career guidance for those looking to transition into the data privacy and compliance space.0:00 - Intro1:15 - Cybersecurity Salary Guide promo2:30 - Will Sweeney and his early tech background6:45 - Building his first high school website9:20 - Career pivot from IT to data privacy and GRC12:15 - Audit vs. implementation: Understanding the difference16:30 - Starting Zaviant and the GDPR opportunity20:45 - Current challenges in data privacy compliance24:10 - Common security gaps companies overlook28:30 - Breaking into GRC: Skills and career advice32:45 - Starting a consultancy: Hidden challenges36:20 - The future of privacy regulations and AI impact40:15 - Career advice for help desk professionals41:30 - Closing thoughtsView Cyber Work Podcast transcripts and additional episodes: https://www.infosecinstitute.com/podcast/?utm_source=youtube&utm_medium=podcast&utm_campaign=podcastAbout InfosecInfosec's mission is to put people at the center of cybersecurity. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and phishing training to stay cyber-safe at work and home. More than 70% of the Fortune 500 have relied on Infosec to develop their security talent, and more than 5 million learners worldwide are more cyber-resilient from Infosec IQ's security awareness training. Learn more at infosecinstitute.com.

State of Play: Summer Games
Bonus Episode 2: FIFA's Club World Cup Circus

State of Play: Summer Games

Play Episode Listen Later Jul 16, 2025 23:07


FIFA's Club World Cup CircusFor credits and this episode's transcript, visit globalreportingcentre.org/state-of-play/bonus-episode-2-fifas-club-world-cup-circus/State of Play is produced by the Global Reporting Centre (GRC) and distributed by PRX. The GRC is an editorially independent journalism organization based at the UBC School of Journalism, Writing, and Media. Founded in 2016, we are leaders in doing global journalism differently. We innovate industry practice, educate the next generation, and promote greater equity in journalism.Learn more about the GRC: globalreportingcentre.org | Make a tax-deductible donation: globalreportingcentre.org/donate

Resilient Cyber
Resilient Cyber w/ Jim Manico - Enhancing Software Security in the Era of AI

Resilient Cyber

Play Episode Listen Later Jul 14, 2025 20:06


In this episode, we sit down with Jim Manico, a longtime industry AppSec Leader, Educator, and Innovator, to discuss enhancing software security in the era of AI.This includes covering recent talks Jim has given about using AI as a force multiplier for software development, the importance of security-centric prompting, and the overall impact of AI on the field of AppSec.We discussed:A recent talk Jim gave where he discussed transforming secure software creation with AI, doing the work of teams of people on his own, and what used to take tens of thousands of hours through the use of agents and various frontier models and offerings.The importance of security-centric prompting and guidance for models to produce secure code and the impact on vulnerability velocity by doing so.The risks of the broader developer community leaning into these tools without adding security-centric prompts and guidance, but the opportunity for prompt libraries and enterprise controls to lead to systemic secure software development within the enterprise.The workforce implications of AI-driven development and the need to upskill to stay relevant (and employable).Where Jim sees opportunity beyond just AppSec when it comes to AI and Cybersecurity, in other areas such as GRC and SecOps as well.

Cyber Security Headlines
Outlook outage continues, Iranian APT activity, Russian ransomware arrest

Cyber Security Headlines

Play Episode Listen Later Jul 11, 2025 9:47


Look Out! Another Outlook Outage Iranian APTs increased activity against U.S. industries in late spring Russian basketball player arrested in France over alleged ransomware ties Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

Cyber Security Headlines
Week in Review: ChatGPT URL vulnerability, McDonald's password problem, Perfekt Bluetooth blunder

Cyber Security Headlines

Play Episode Listen Later Jul 11, 2025 25:21


Link to episode page This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jim Bowie, vp, CISO, Tampa General Hospital Thanks to our show sponsor, Vanta Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines All links and the video of this episode can be found on CISO Series.com  

Cyber Security Headlines
AMD has CPU meltdown, Mozilla Thunderbird has vulnerabilities, Indian defense sector attacked

Cyber Security Headlines

Play Episode Listen Later Jul 10, 2025 7:46


AMD warns of new Meltdown, Spectre-like bugs affecting CPUs Multiple vulnerabilities in Mozilla Thunderbird could allow for arbitrary code execution Bitcoin Depot breach exposes data of nearly 27,000 crypto users, More than $40 million stolen from GMX crypto platform Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

Cyber Security Headlines
Rubio Spoofed, RondoDox Botnet, Batavia Spyware

Cyber Security Headlines

Play Episode Listen Later Jul 9, 2025 8:43


Four members of President Trump's cabinet impersonated Is this some kind of a game? Batavia attacks Russian industrial companies Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

CISO-Security Vendor Relationship Podcast
Not Enough Hallucinations? Let's Outfit Your LLM with Another LLM

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jul 8, 2025 35:54


All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark, producer of CISO Series and Edward Contreras, senior evp and CISO, Frost Bank. Joining us is Anthony Candeias, CISO, Weight Watchers. In this episode: AI agents require structured supervision, not autonomy Hiring for potential over credentials in cybersecurity AppSec training effectiveness depends on organizational relevance AI oversight requires purpose-built models, not general solutions A huge thanks to our sponsor, Vanta Vanta's Trust Management Platform helps 10k+ companies—like Atlassian, Quora, and Chili Piper—start and scale their security programs and build trust with buyers. Vanta saves security teams time and improves program visibility by automating 35+ compliance frameworks, such as SOC 2 and ISO 27001, and GRC workflows, like risk management. Get started at Vanta.com/CISO

Cyber Security Headlines
Call of Duty game pulled, U.S. military gets cybersecurity boost, Bank employee helped hackers

Cyber Security Headlines

Play Episode Listen Later Jul 8, 2025 8:33


Call of Duty game pulled from PC store after reported exploit U.S. military gets cybersecurity boost Bank employee helped hackers steal $100M Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

Cyber Security Headlines
Ingram Micro cyberattack, Telefonica possible breach, LLM URL recommendation problem

Cyber Security Headlines

Play Episode Listen Later Jul 7, 2025 8:08


Ingram Micro suffers ransomware attack Hacker leaks Telefónica data allegedly from new breach ChatGPT prone to recommending wrong URLs, creating a new phishing opportunity Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines Find the stories behind the headlines at CISOseries.com.    

Joey Pinz Discipline Conversations
#652 ITN Secure-Ozzie Saeed : ⚙️ Compliance Isn't Optional—It's Opportunity

Joey Pinz Discipline Conversations

Play Episode Listen Later Jul 2, 2025 28:01 Transcription Available


Send us a textWhy fear compliance when it can fuel your growth? In this rich and revealing episode from IT Nation Secure 2025, Joey Pinz sits down with Ozzie Saeed, founder of IntelliGRC, to unpack why MSPs should stop dreading cybersecurity frameworks like CMMC—and start seeing them as strategic advantages.

State of Play: Summer Games
Bonus Episode 1: Is Los Angeles Ready?

State of Play: Summer Games

Play Episode Listen Later Jul 2, 2025 22:29


Is Los Angeles Ready? For credits and this episode's transcript, visit globalreportingcentre.org/state-of-play/s01be01-losangeles/State of Play is produced by the Global Reporting Centre (GRC) and distributed by PRX. The GRC is an editorially independent journalism organization based at the UBC School of Journalism, Writing, and Media. Founded in 2016, we are leaders in doing global journalism differently. We innovate industry practice, educate the next generation, and promote greater equity in journalism.Learn more about the GRC: globalreportingcentre.org | Make a tax-deductible donation: globalreportingcentre.org/donate

Resilient Cyber
Resilient Cyber w/ AJ Yawn - Transforming Compliance Through GRC Engineering

Resilient Cyber

Play Episode Listen Later Jun 30, 2025 35:53


In this episode, we sat down with AJ Yawn, Author of the upcoming book GRC Engineering for AWS and Director of GRC Engineering at Aquia, to discuss how GRC engineering can transform compliance.We discussed the current pain points and challenges in Governance, Risk, and Compliance (GRC), how GRC has failed to keep up with software development and the threat landscape, and how to leverage cloud-native services, AI, and automation to bring GRC into the digital era.We dove into:What the phrase “GRC Engineering” means and how it differs from traditional Governance, Risk and ComplianceWhat some of the major issues are with traditional compliance in the age of DevSecOps, Cloud, API's, Automation and now AISpecific examples of GRC Engineering, including the use of automation, API's and cloud-native services to streamline security control implementation, assessment and reportingThe promise and potential of AI in GRC, and how AJ is using various models for control assessments, artifact creation and more, and how GRC practitioners should be leveraging AI as a force multiplierAJ's new book “GRC Engineering For AWS: A Hands-On Guide to Governance, Risk and Compliance Engineering”

The Tech Blog Writer Podcast
3327: MetricStream - How AI Is Reshaping Governance, Risk and Compliance (GRC)

The Tech Blog Writer Podcast

Play Episode Listen Later Jun 26, 2025 32:39


When I last spoke with Gaurav Kapoor five years ago, we were in the thick of a global pandemic. Remote work was still a novelty for many, AI was a distant concept for most businesses, and regulatory frameworks were trying to keep pace with the speed of technological change. Fast forward to today, and the conversation around AI and governance, risk, and compliance (GRC) has shifted dramatically. This made it the perfect time for a long-overdue catch-up. In this episode, I welcomed back Gaurav, Vice Chairman and Co-founder of MetricStream, to discuss the changing face of GRC in an AI-driven world. AI has now reached a level of ubiquity that places it alongside electricity and Wi-Fi as a foundational layer of both business and everyday life. But with that integration comes risk, and with risk comes the need for smarter, more adaptive governance. Gaurav shared how AI is no longer just about efficiency gains. It is becoming embedded into the fabric of enterprise risk frameworks, from real-time regulatory monitoring to predictive analytics and risk forecasting. We talked about the impact of the current political climate, including policy shifts following President Trump's return to office and how deregulation narratives are colliding with the complexity of global compliance expectations. This was not just a theoretical discussion. Gaurav broke down real-world use cases that show how large enterprises are navigating everything from redundant compliance testing to emerging threats discovered through AI-driven analysis. He also spoke candidly about the challenges ahead, how companies can fall behind if they wait too long to modernize their frameworks, and what is at stake when they fail to build trust into their AI systems. So how do you evolve GRC in an age where the pace of change is relentless? What role does AI really play in risk leadership today? And how can companies move from reactive to proactive without losing control? Join me as we explore the next chapter of GRC with one of its leading voices.

The Tech Trek
Her Journey: Sales Leader to Cybersecurity CEO

The Tech Trek

Play Episode Listen Later Jun 24, 2025 20:58


In this episode, Amir sits down with Brooke Motta, CEO and co-founder of RAD Security, to unpack her career pivot from sales leadership to becoming a founder in the cybersecurity space. Brooke shares how her go-to-market background shaped her approach to building RAD, the challenge of stepping into technical leadership, how she's managing growth through hiring, and what's ahead for security and AI. Whether you're a technical founder or commercial operator, this one's packed with practical insight.

Resilient Cyber
Resilient Cyber w/ Bob Ritchie - Securing Federal & Defense Digital Modernization

Resilient Cyber

Play Episode Listen Later Jun 23, 2025 40:58


In this episode, I sit down with SAIC Chief Technology Officer (CTO) and longtime Federal/Defense leader Bob Ritchie to discuss his experience securing public sector digital modernization, including everything from large multi-cloud environments to zero trust, identity, and where things are headed with AI.Bob starts discussing SAIC and his background there. He went from intern to CTO over 20 years with this public sector industry leader, including a brief stint with Capital One on the commercial side.We covered the current state of the federal cloud community across multiple clouds (e.g., Azure, AWS, and GCP) and some of the challenges and opportunities on the security front.We often hear phrases such as “identity is the new perimeter,” but the perimeter is porous and problematic, especially in large, disparate environments such as the Federal/Defense ecosystem. Bob touched on the current state of identity security in this ecosystem, where progress is being made and what challenges still need to be tackled.The government is doing a big push towards Zero Trust, with the Cyber EO 14028, Federal/Defense ZT strategies, and more. But how much progress is being made on ZT, and where can we look for examples of innovation and success?We dove into the rise of excitement and adoption of AI, GenAI, Agentic AI, and protocols such as MCP, A2A, and where the public sector community can lean into Agentic AI for use cases ranging from SecOps, AppSec, GRC, and more.Bob explains how he balances a good business focus while staying deep in the weeds and proficient in relevant emerging technologies and nuances required as a CTO.I've known Bob for several years, and you would be hard pressed to find a more competent technology leader. This is not one to miss!

FCPA Compliance Report
#Risk New York Speaker Series – Inside Behavioral Insights: Tom Hardin on Compliance at #RiskNYC

FCPA Compliance Report

Play Episode Listen Later Jun 20, 2025 6:45


Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration. At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy, and combating misinformation. All while meeting with the country's top #Risk management professionals. In this episode, Tom Fox is joined by Tom Hardin, a former hedge fund analyst known as Tipper X, who shares his unique journey from insider trading informant to a global speaker on compliance and risk. Hardin previews his upcoming panel on applying behavioral science to design effective GRC programs at the #RiskNYC conference. He discusses topics such as cognitive biases, social norms, and rationalizations in decision-making, emphasizing the enduring nature of human behavior despite technological advancements. The episode highlights Hardin's goal of fostering deeper connections between psychology, technology, and regulation to build more proactive and resilient risk cultures. Resources: #Risk Conference Series #RiskNYC—Tickets and Information Tom Hardin on LinkedIn Visit Tipper X Website Learn more about your ad choices. Visit megaphone.fm/adchoices

FCPA Compliance Report
#Risk New York Speaker Series - Upping Your Game with Tom Fox

FCPA Compliance Report

Play Episode Listen Later Jun 19, 2025 6:09


Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration. At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy and combating misinformation. All while meeting with the country's top #Risk management professionals. In this episode of the Risk New York podcast series, Tom Fox introduces the upcoming Risk New York Conference, scheduled for July 9-10 at Fordham Law School. The conference, hosted by GRC World Forums, will focus on various aspects of risk management, including AI, tech risk, financial and crypto risk, and GRC frameworks. Tom discusses his keynote based on his book ‘Upping the Game' and highlights key speakers and exhibitors, including Robert Clark from Howard University, Bill Coffin and Erica Alburn from Ecosphere, and Michael Rasmussen, known as the father of GRC. The episode highlights the importance of the conference and provides details on discounted tickets, as well as other information available in the show notes. Resources: #Risk Conference Series #RiskNYC—Tickets and Information Compliance Podcast Network Website Tom Fox Instagram Facebook YouTube Twitter LinkedIn Learn more about your ad choices. Visit megaphone.fm/adchoices

FCPA Compliance Report
#Risk New York Speaker Series- Ethicast Reacts: Unpacking Compliance Challenges with Erica Salmon Bryne and Bill Coffin

FCPA Compliance Report

Play Episode Listen Later Jun 18, 2025 10:53


Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration. At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy and combating misinformation. All while meeting with the country's top #Risk management professionals. In this episode, Tom Fox is joined by Erica Salmon Byrne, Chief Strategy Officer and Executive Chair at Ethisphere, and Bill Coffin, Editor-in-Chief at Ethisphere. The conversation delves into their roles in the compliance community, focusing on their work with the Ethicast Reacts series. They discuss how they analyze news stories to extract compliance lessons, help organizations understand and mitigate risks, and create storytelling opportunities to advance compliance programs. They also share their excitement for their upcoming presentation at the Risk New York City conference, where they'll engage with professionals from diverse backgrounds. Resources: #Risk Conference Series #RiskNYC—Tickets and Information Erica Salmon Byrne on LinkedIn Bill Coffin on LinkedIn Ethisphere Learn more about your ad choices. Visit megaphone.fm/adchoices

CISO-Security Vendor Relationship Podcast
We Checked the “Yes” Box for Cybersecurity. What Else Do We Have to Do?

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 17, 2025 41:24


All links and images can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Alex Hall, CISO, Gensler. In this episode: Evaluating secure messaging beyond the app Reframing compliance as a business enabler Incremental security investment vs. crisis response Why culture, not punishment, drives secure behavior Huge thanks to our sponsor, Vanta Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.  

FCPA Compliance Report
#Risk New York Speaker Series- AI Investments and Political Uncertainty with Chris Mason

FCPA Compliance Report

Play Episode Listen Later Jun 16, 2025 6:48


Join myself and hundreds of other GRC professionals in the city that never sleeps, New York City on July 9 & 10 for one of the top conferences around #Risk New York. current US landscape – shaped by evolving policies, rapid AI advancements, and shifting global dynamics – demands adaptive strategies and cross-functional collaboration. At #RISK New York you will master the New Regulatory Reality by Getting ahead of US regulatory shifts and their impact. Conquer AI & Tech Risk by Safeguarding your organization in an AI-driven world and understand the implications of major tech investments. Navigate Financial & Crypto Volatility by Protecting assets and explore solutions in a dynamic market. Strengthen Your GRC Framework by Leverage governance, risk, and compliance for strategic advantage. Protect Digital Trust by Addressing challenges in cybersecurity, data privacy, and combating misinformation. All while meeting  In this episode, Tom Fox talks with Chris Mason, who recently launched his risk advisory practice, Woodhorn Global, focusing on due diligence investigations. Chris shares insights about his upcoming presentations at the #RiskGRC conference in July, focusing on AI investments and political uncertainty affecting the GRC (Governance, Risk, and Compliance) community. They discuss the significance of AI in the field and the importance of adapting to political changes. Chris also highlights the value of in-person events to understand best practices and navigate the evolving risk landscape. Resources #Risk Conference Series #RiskNYC-Tickets and Information Chris Mason on Linkedin Learn more about your ad choices. Visit megaphone.fm/adchoices

FCPA Compliance Report
#Risk New York Speaker Series - Exploring AI Risks in Compliance with Gwen Hassan

FCPA Compliance Report

Play Episode Listen Later Jun 13, 2025 5:47


Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration. At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy, and combating misinformation. All while meeting with the country's top #Risk management professionals. In this episode, Tom Fox talks with Gwen Hassan, the Chief Compliance Officer for Unisys Corporation, about her role and the upcoming #RiskNYC conference. Gwen shares insights into Unisys' operations, including the various technologies and services they provide, and highlights her responsibilities in managing global ethics, compliance, and trade compliance risks. She also gives a teaser about her panel presentation on the compliance and ethics risks associated with artificial intelligence, stressing the importance of understanding AI's impact on company culture and regulatory compliance. Gwen expresses her excitement about the conference, emphasizing the value of engaging with fellow risk management experts. Resources: #Risk Conference Series #RiskNYC—Tickets and Information Gwen Hassan on LinkedIn Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Headlines
Microsoft Entra attack, Thursday's Cloud outages, Mark Green retires

Cyber Security Headlines

Play Episode Listen Later Jun 13, 2025 8:10


Hackers attacks target Microsoft Entra ID accounts using pentesting tool Google Cloud and Cloudflare outages reported House Homeland Chairman Mark Green announces his departure Huge thanks to our sponsor, Vanta Is your manual GRC program slowing you down? There's something more efficient than spreadsheets, screenshots, and manual processes — Vanta. With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive. Get back time to focus on strengthening security and scaling your business. Get started at  Vanta.com/headlines. Find the stories behind the headlines at CISOseries.com.

Cyber Security Headlines
Week in Review: Google and Cloudflare outages, Copilot Zero-Click, Cloudflare's Claude flair

Cyber Security Headlines

Play Episode Listen Later Jun 13, 2025 25:20


Link to episode page This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products Thanks to our show sponsor, Vanta Is your manual GRC program slowing you down? There's something more efficient than spreadsheets, screenshots, and manual processes — Vanta. With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive. Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines. All links and the video of this episode can be found on CISO Series.com

FCPA Compliance Report
#Risk New York Speaker Series - Exploring the Future of GRC with Michael Rasmussen

FCPA Compliance Report

Play Episode Listen Later Jun 12, 2025 6:01


Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration. At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy and combating misinformation. All while meeting with the country's top #Risk management professionals. In this episode, Tom Fox welcomes Michael Rasmussen, a renowned expert in Governance, Risk Management, and Compliance (GRC), often referred to as the ‘father of GRC.' Michael shares insights into his contributions to the field, including his work with the SEG GRC Capability Model. The conversation highlights Michael's anticipated presentation on ‘The Future of GRC' at the upcoming risk conference in New York City. Drawing inspiration from Star Trek (TOS, and how can you not love that?), Michael emphasizes the importance of managing business risks effectively. The discussion also touches on the benefits of face-to-face interactions and networking opportunities at such conferences. Resources: #Risk Conference Series #RiskNYC—Tickets and Information Michael Rasmussen on LinkedIn Learn more about your ad choices. Visit megaphone.fm/adchoices

CISO-Security Vendor Relationship Podcast
AI Isn't Going to Take Your Job, It's Going to Eliminate It! (LIVE at BSidesSF)

CISO-Security Vendor Relationship Podcast

Play Episode Listen Later Jun 3, 2025 44:44


All images and links can be found on CISO Series. This week's episode is hosted by me, David Spark (@dspark), producer of CISO Series and Andy Ellis (@csoandy), partner, YL Ventures. Joining us is Alexandra Landegger, global head of cyber strategy & transformation, RTX. In this episode: A cybersecurity fast-track? When Ambition Becomes a Liability Giving the CVE Program the Credit It Deserves Elevating human cyber talent with AI Huge thanks to our sponsors, Nudge Security, SecurityScorecard, and Vanta Take control of SaaS security and AI governance with Nudge Security. Start a free trial today and get a full inventory of all SaaS and GenAI accounts in minutes along with risk insights and automation to help you quickly improve your security posture. Get started here: nudgesecurity.com/cisoseries   Third-party risk doesn't stop at monitoring. SecurityScorecard delivers real-time detection and response across your supply chain—helping you fix vulnerabilities before they become breaches. Empower your team with expert-driven remediation, continuous vendor oversight, and board-ready insights that drive results.   Automate, centralize, & scale your GRC program with Vanta Vanta's Trust Management Platform automates key areas of your GRC program—including compliance, internal and third-party risk, and customer trust—and streamlines the way you gather and manage information. And the impact is real: A recent IDC analysis found that compliance teams using Vanta are 129% more productive. Get started at Vanta.com/ciso.

Unsupervised Learning
The Future of Hacking is Context

Unsupervised Learning

Play Episode Listen Later Jun 3, 2025 33:45 Transcription Available


Sponsored by Vanta. Vanta takes the busywork out of GRC so you can focus on what actually matters—improving your security, not chasing compliance. https://ul.live/vanta This isn’t just another AI podcast. It’s about the deeper shift that’s happening in cybersecurity—away from individual tools and dashboards, and toward real-time, comprehensive world models of what we’re trying to protect or attack. I'll walk through how I came to this idea, what it means for security assessments, red teaming, vuln management, and beyond—and why context, not AI, is the actual revolution.