
Security & GRC Decoded · 2025-10-16 · 1h 0m
In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue , seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix , Gap , and other major enterprises - showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions. He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk - all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned. Key Takeaways CRQ doesn’t require perfection - start with what you have and refine over time. The most effective risk programs focus on directionally correct data, not precision. Good risk scenarios clearly define asset, threat, and effect to avoid misalignment. Generative AI accelerates scenario development, data research, and model creation. CISOs should demand more from risk teams - move beyond “pick a color” heat maps.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.