The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

Compliance ≠ Security: It Sets the Foundation ft Evan Millman, Security GRC Manager @ Abnormal AI

Security & GRC Decoded · 2025-08-21 · 1h 14m

0:00--:--

Topics in this episode

SOC 2compliance vs. securitysecurity GRCGRC strategydecentralized security

Episode notes

What’s the true relationship between compliance and security? According to Evan Millman , compliance may not be security - but it’s the necessary starting point for building it. In this episode, Raj sits down with Evan to explore how organizations can shift their GRC approach from reactive checkbox checking to a proactive and risk-informed security practice. Evan shares stories from his work at Abnormal.AI , lessons from scaling GRC in fast-moving environments, and practical advice for anyone trying to align controls with business objectives. 5 Key Takeaways: Compliance is not the destination - but it is the framework for real security conversations. Say no to overkill - Right-size controls based on business needs, not frameworks. Decentralized GRC works - but only if there’s shared ownership and trust. “GRC therapy” is real - and it starts with building internal relationships. Metrics matter - but only when they tell a story that drives action.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Justin Greis: AI Meets CybersecurityKitecast · on SOC 285 / 100
  • Compliance Isn’t Security: The Biggest Cybersecurity Myth in Healthcare (HITRUST Explained)Cybersecurity at ViVE Podcast · on SOC 278 / 100
  • Building Trust with AI Compliance FrameworksCherry Bekaert: Risk & Cybersecurity · on SOC 267 / 100
  • ISACA Podcast: Why You Should Use the F Word MoreISACA Podcast · on SOC 264 / 100
  • Why Neofin Killed Its Niche and Rebuilt From Scratch. And What They're Launching Next | Svitlanka Sergiichuka, CEO & Co-Founder, NeofinPurpose Driven FinTech · on SOC 256 / 100
  • Establishing and Measuring TrustLock it Down Podcast · on SOC 255 / 100

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →