The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

Controls Are Promises: Rethinking GRC for Modern Security ft Sergio Alonso @ Rapid7

Security & GRC Decoded · 2025-12-02 · 56 min

0:00--:--

Topics in this episode

Rapid7Raj KrishnamurthySecurityAndGRCDecodedSergio AlonsoRapid7 Automation

Episode notes

In this episode of Security & GRC Decoded , host Raj Krishnamurthy sits down with Sergio Alonso , a seasoned GRC and information security leader at Rapid7 , whose 17 - year career spans auditing, high-regulation banking, blockchain innovation at Akamai, privacy GRC at Twitter, and now trust and governance in cybersecurity. Sergio breaks down how to translate legacy compliance thinking into modern engineering-aligned practices, why automation is the only scalable path forward, and how controls should be treated as “promises” that teams must honor every day. This conversation explores scaling GRC in high-velocity environments, reducing compliance fatigue, applying zero-knowledge principles to trust, and building the next generation of context-driven risk programs. Key Takeaways Automation is the only sustainable path to scaling GRC without increasing friction. Controls should be viewed as “promises,” and audits as the consequence of keeping or breaking them. Context - technical, business, and risk - is the primary driver of effective triage and prioritization. GRC must evolve from a legacy function into a trust-driven, engineering-aligned discipline.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom LangfordSecure & Simple · on Rapid778 / 100
  • #155: The Art of AI Content Creation with Cybersecurity Expert David MundyTea Time With Tech Marketing Leaders · on Rapid767 / 100

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →