
Sign up to save your podcasts
Or


Risk management isn't all crunchy and rigid - GRC teams and individuals deal with several professional difficulties, fears, and uncertainties that impact their risk decisions. But what is being done about it?
Oftentimes, GRC professionals on the crunchy side have to carry out softer tasks that require things like behavior changes across teams, which in turn require steps to be taken. What does the bridge between this gap look like?
Join us as we learn about what the soft and squishy side of GRC entails with Jason and also understand the impact his organization - kinkou.org has been having on bringing this soft side to a new light.
In this episode, Jason offers practical insights highlighting the importance of skills like communication and relationship-building in strengthening risk management. Tune in now!
About Jason
Joining us on the eighth episode of Risk Grustlers is Jason Leuenberger, a Leadership and Team Coach whose journey in GRC speaks for itself. Jason has been immersed in the crunchy approach towards GRC for the past 20 years, deep into technical domains, and now he’s sharing why the softer side of GRC may be the hidden gold mine no one’s paying attention to.
With over twenty years of experience in the industry, Jason is the perfect guide to help you master the often-overlooked softer side of GRC.
You can reach out to Jason directly at [email protected] to learn more about his services.
Highlights from the episode
Quotes
“The human side of risk is what I like to call the softer side. We often assume that people are either naturally born with talents like communication and relationship-building or they’re not. But the truth is, these are skills that we can learn, understand, and actually develop over time.”
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
Renae Martin, whose love for information security developed in a rather unorthodox way, is joining us for our seventh episode of Risk Grustlers! Her journey as a journalist turned senior technical program manager is one full of interesting pathways, anecdotes, and challenges.
Tune in as Renae shares the inside stories from her years of experience tackling several security projects!
About Renae
Drawn by the excitement of the early 2000s tech landscape, Renae chose to transition from an entirely different field - journalism to the cybersecurity industry. In this episode, we are uncovering her experience of starting in this industry as a very beginner to what she feels now as an experienced professional.
GRC often faces perceptions of being unexciting and undervalued compared to development teams - and Renae is no stranger to this conception.
However, as a project manager who’s lead several security projects - she has seen the role evolve and is sharing how the real value lies in understanding optimal solutions and collaborating closely with teams to innovate.
That’s not it though, we are going deep and hitting Renae with just the right questions - who wins in GRC - a pushover or a hard ass? What are the implications of assertiveness and empathy in long-term GRC success?
If you’re interested in learning her thoughts on these topics, then don’t forget to tune in to our seventh episode of Risk Grustlers!
Highlights from the episode
Quotes
“I've learned from past experiences that when flashy tools were brought in without the necessary structure and support, it often led to issues. There's no magic solution in a tool alone; it requires knowledge and effort to work effectively. Establishing a strong foundational risk program comes first.”
"While checklist-based approaches can be dull, the real value lies in understanding optimal solutions and collaborating closely with teams to innovate."
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
Building a security team, let alone scaling it, is no small feat; there are several layers and factors to consider. In this episode, Satya shares with us his experience of building teams across different environments and some core concerns he makes sure to address.
Moving along, the conversation also tackles the question of how much growth-stage companies should invest in security, with special attention on the kind of messaging that they should be focusing on first.
There is a sharp distinction between feeling secure and being secure - an approach that Satya uses to determine which side of the coin a company wishes to fall into.
If you’re interested in learning the key strategies from an esteemed security professional on how to get your security budget approved, how to keep up with the attackers in the present threat landscape, as well as the know-how on staying up-to-date with the new frameworks, then tune in right now!
About Satya
Satya Nayak, Head of Security Engineering & Operations at Outreach, is joining us for the sixth episode of Risk Grustlers to share what sparked his passion for cybersecurity and give solid advice on leading security teams with finesse.
Being one of the fastest-growing professionals in the industry, Satya has some incredible tips up his sleeve that will have you see GRC in an entirely new light.
Highlights from the episode
Quotes
“Operating from the sidelines won’t cut it. You’ve got to be in the know about what’s happening out there. That’s how you back up your team, manage projects, and make those smart moves.”
"It is important to not smother your team's passion for security under a pile of processes and organizational rules."
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
Join us as Ross Haleliuk, Head of Product at LimaCharlie breaks down the notion of complexity that surrounds cybersecurity.
Ross's journey into cybersecurity began with a unique path. He had been involved in various tech fields for over a decade, including e-commerce, retail, and financial technology.
He joined a cybersecurity startup as a product leader despite his initial hesitation due to the complexity and jargon associated with the field.
And this episode uncovers exactly that. With a rather refreshing take on the cybersecurity landscape today, Ross is de-romanticizing the complexity, one day at a time.
We also touch upon Ross's perspective as an angel investor and industry insider, emphasizing the importance of balance in cybersecurity startup founders. (along with some incredible advice for teams who are trying to sell to CISOs)
So grab a snack, get cozy, and dive straight in!
About Ross Haleliuk
With a personality that rivals Taylor Swift, Ross Haleliuk is the Head of Product at LimaCharlie and the esteemed author of the famous cybersecurity blog, Venture in Security. He is joining us for the fifth episode of Risk Grustlers, to break down the notion of complexity that surrounds cybersecurity.
Tune in to listen to Ross share his anecdotes as a non-tech background professional who’s had to unlearn and see beyond the acronyms and jargon.
Highlights from the episode
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
There are a bowlful of acronyms that have entered the cybersecurity industry in the last few years, and in this episode, Gary expands on why exactly it is important to identify the most critical things first: the BASICS.
Are you doing the basics correctly? Or are you simply on a barrage of vendors to help you identify the risk areas? Do you have data lying around in a sweet nest bucket for attackers?
Join us as we interview Gary Hunter, the Executive Director and Deputy Information Security Officer of Cybersecurity at The Walt Disney Company where he discusses how to strike a balance between deploying the latest AI systems while maintaining the proper processes in-house. Tune in right now!
About Gary Hunter
Switching fields into cybersecurity can be a whole lot of scary, especially in the current landscape but there’s no better example than Gary Hunter, who joins us in our fourth episode of Risk Grustlers to teach us how to break the imposter syndrome and find your feet in this wild jungle of data security!
Coming from a non-tech background and building his portfolio as a ‘security guy’ from scratch, Gary has accumulated the perfect balance to act as the bridge between complex technical problems and non-technical audiences.
Highlights from the episode
Quotes
“Start with strong security basics. Prioritize clean security hygiene before advanced measures. Use technology to spot issues, but prioritize, understand, and remediate findings through proper processes.”
“Instead of costly site visits, focus on training. Vendor breaches often stem from email compromise, phishing, ransomware. Training on spotting fake emails matters more than fortress-like data centers.”
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
Taking a slight departure from our regular themes of exploring the journeys of Risk Grustlers, we’re here with an on-demand podcast with the one and only, Walter Haydock, Founder and CEO of StackAware, to demystify and dig into the role of responsibility in today’s AI threat landscape.
In this episode, Walter gives us a crash course on all things LLM – from listing the differences between using a self-hosted LLM and a third-party LLM to explaining the top five risks to watch out for while using them.
Application developers are often overwhelmed with the bundle of resources out there, especially when working with LLM-based applications. The OWASP Top 10 and the NIST AI RMF framework, to name just a few - so what should be the key concerns?
That’s exactly what we’re solving here. Tune in to listen to the top 5 concerns that, according to Walter, should be on the top of your list when creating a tool on top of a LLM!
Last but not least, as promised, we are linking the FREE resources down below, so don’t forget to take a look and sharpen your AI security knowledge.
About Walter
Walter Haydock is the Founder and Chief Executive Officer of StackAware, which helps organizations manage the cybersecurity, compliance, and privacy risks from artificial intelligence systems while harnessing their benefits.
Walter is a true trailblazer when it comes to solving for AI security. With a profound understanding of AI’s inner workings, he’s the ultimate demystifier of Language Models’ core applications.
He was previously a Director of Product Management at Privacera - a data governance startup backed by Accel and Insight Partners - as well as PTC - where he helped to secure the company’s industrial IoT product lines.
Before entering the private sector, he served as a professional staff member for the Homeland Security Committee of the U.S. House of Representatives, as an analyst at the National Counterterrorism Center, and as a reconnaissance and intelligence officer in the Marine Corps.
Walter is a graduate of the United States Naval Academy, Georgetown University’s School of Foreign Service, and Harvard Business School.
LinkedIn | Twitter | Blog
Highlights from the episode
Quotes
“Using AI inherently involves a degree of risk. To tread wisely, especially in terms of privacy, the smart approach would be to limit the data you collect and process."
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
Welcome to Episode 2 of Risk Grustlers! In this episode, we walk through the journey of Vignesh Kumar, who leads the internal audit teams at Microsoft. He talks about his unorthodox journey to the GRC world, what makes GRC sexy, and why relationships are pivotal in the GRC world.
He offers a peek into the world of audits, explaining how internal and external audits vary and emphasizes the need for regular internal audits.
There are also some sneaky tips on how GRC teams can establish a rapport with other teams to make the whole process, much easier.
Whether you’re a GRC professional or an employee who is vary of it, Vignesh will make you gain a new respect for it. Get ready to see GRC in a new light!
Tune in as he recounts amusing anecdotes of his experiences as an internal auditor and learn whether auditors do have horns or are just an angel in disguise.
About Vignesh
Vignesh Kumar is the Senior Manager of Security and Privacy at Microsoft and an undeniable GRC genius.
Having started out as a project manager at one of the largest equipment manufacturers in the world, Vignesh developed an unexpected passion for GRC. Today, this passion still burns bright, as he sets about making it more palatable and appealing to the uninitiated or to those who dread it. He is the perfect advocate for all things GRC.
Highlights from the episode
Quotes
“So, the key difference is the sense of ownership. Internal auditors have that, while external auditors usually stick to compliance. It's about being risk-based versus compliance-focused.
“What I came to really appreciate about GRC was how it could positively impact my applications. Its ripple effects spread across the organization and ensure that hundreds of applications are compliant.”
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
There’s no straight-line path to growing in Risk Management. There are uncertainties and the burden of constantly avoiding obsolescence. But it’s also rewarding. How? With effective cyber risk management.
Welcome to the first episode of Risk Grustlers Podcast! Prepare to be enlightened and awakened as Davis Hake, co-founder of Resilience, unravels the dynamic evolution of the insurance domain and how its behaviour-changing nature can influence risk management.
Learn the importance of early buyer engagement, how you can strike a balance between listening to ‘users’ as well as understanding the requirements of ‘buyers’ and acknowledging why it is necessary to make a connection with clients.
Still thinking of how to navigate the intense acronym soup, mate? This goldmine of insightful industry information is yours for the taking! Tune in now.
About Davis
Davis Hake is the co-founder of Resilience - a pioneering cyber risk solution company based in New York City, which is redefining how companies think of the ‘economics’ of risk management.
Davis has earned his stripes as a true innovator in the realm of cyber risk combat, seamlessly merging cutting-edge analytics with actionable wisdom. With his unparalleled grasp on risk management, he is the perfect sensei for cyber risk warfare.
Highlights from the episode
Quotes
"Today, we tend to take a compliance-driven risk approach. But what we really need is risk-driven compliance. So, for companies to think about what’s core, what’s most impactful to their ability to deliver value to their clients and then working from that set of security measures, investments and understanding how well you’re implementing that sort of blocking and tackling can then layer up to these different compliance frameworks"
About Scrut Automation
Scrut Automation is a risk observability and compliance automation platform built to simplify information security monitoring for cloud-native companies. We help early-stage and growth-stage companies across the globe, establish enterprise-grade information security processes through an easy-to-use GRC platform.
To watch more of our episodes and learn more about us, visit us at https://www.scrut.io/podcasts
About Scrut Automation:
Scrut Automation empowers scaling companies to move Beyond Compliance, focusing on managing digital risk while reducing the friction of audit preparation, evidence collection, and risk monitoring.
Purpose-built for high-growth startups and mid-market businesses, Scrut simplifies the most tedious parts of compliance and risk management, keeping you audit-ready and risk-aware at all times. With seamless integration into your processes, Scrut delivers real-time insights and continuous monitoring, enabling proactive risk management to support sustainable growth. Focus on scaling your business confidently as Scrut automates compliance and strengthens your digital resilience—no more manual work or compliance chaos.
To watch more of our episodes and learn more about us, visit us at :
https://www.scrut.io/podcasts
From the publisher's feed
Welcome to 'Risk Grustlers,' where we celebrate the extraordinary journeys of modern-day Risk Leaders who embrace the art of 'Grustle'—a powerful fusion of Grind and Hustle. Our podcast dives into…