
Security & GRC Decoded · 2025-08-21 · 1h 14m
What’s the true relationship between compliance and security? According to Evan Millman , compliance may not be security - but it’s the necessary starting point for building it. In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at Abnormal.AI , lessons from scaling GRC in fast-moving environments, and practical advice for anyone trying to align controls with business objectives. 5 Key Takeaways: Compliance is not the destination - but it is the framework for real security conversations. Say no to overkill - Right-size controls based on business needs, not frameworks. Decentralized GRC works - but only if there’s shared ownership and trust. “GRC therapy” is real - and it starts with building internal relationships. Metrics matter - but only when they tell a story that drives action.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.