
Security & GRC Decoded · 2025-12-30 · 59 min
Audits are often misunderstood, frequently disliked, and almost always viewed as a necessary evil - but what if that mindset is holding security teams back? In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Varun Prasad to unpack what audits are actually designed to do: provide reasonable assurance, not absolute security. Drawing on more than two decades of experience across internal and external audits, Varun explains why “auditable controls” are the missing link between fast-moving engineering teams and slow, annual audit cycles - and how organizations can stop treating audits as an afterthought and start using them as a trust-building mechanism.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.