Security, Compliance & Customer Trust: The Evolution of GRC at Scale | feat. Abhay Kshirsagar from Salesforce
Release Date: 02/06/2025
Security & GRC Decoded
In this episode, Raj Krishnamurthy sits down with , GRC & Security at , and a former security, risk and compliance leader at Cruise and Dropbox, to explore fresh perspectives on Security & GRC. Kieran opens with a bold stance: data breaches, while critical, aren't the top threat they used to be. Instead, he argues, maintaining availability and service uptime is now paramount. Drawing from his unique experience building the foundational GRC program at Cruise, a pioneering self-driving car company, Kieran reveals how managing cybersecurity risks took on profound urgency—literally...
info_outlineSecurity & GRC Decoded
Ever wondered if your GRC team should be writing code? (Spoiler alert: Jeevan thinks they probably should.) In this eye-opening episode of Security & GRC Decoded, Jeevan Singh, Director of Security Engineering at Rippling, joins Raj to challenge traditional views of Governance, Risk, and Compliance (GRC). Jeevan passionately argues why GRC teams must become more technical, automated, and deeply integrated into engineering processes to truly protect and enable businesses. Drawing from his experience at Segment and Rippling, he provides actionable insights and real-world examples to...
info_outlineSecurity & GRC Decoded
In this episode, Raj Krishnamurthy interviews , Director of Security and Compliance at , to uncover valuable insights into the evolving world of Governance, Risk, and Compliance (GRC). Shobhit shares his controversial perspective on GRC teams overburdening themselves, emphasizing the need for GRC professionals to expand their technical expertise and embrace a product management mindset. The conversation dives into proactive strategies for GRC success, the importance of integrating privacy into compliance frameworks, and actionable tips for achieving High Trust certification on a budget....
info_outlineSecurity & GRC Decoded
In this episode of Security & GRC Decoded, host Raj Krishnamurthy (CEO of ComplianceCow) sits down with , a Staff Security Assurance Engineer at GitLab and co-author of the GRC Engineering Manifesto, for a deep dive into the evolution of GRC through an engineering lens. Ayoub shares how his background in consulting and cloud-native startups led him to question the traditional, checklist-heavy approach to GRC—and why embracing real-time data, automation, and developer-friendly processes is the key to building stronger security and compliance programs. He also reveals his controversial...
info_outlineSecurity & GRC Decoded
In this episode of Security & GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with —former CISO and AWS Security Engineering Leader—to explore the evolving landscape of security, governance, and risk management. Carlos shares his journey from leading security in highly regulated industries like banking and energy to championing large-scale security engineering at AWS. Together, they discuss how effective GRC programs can move beyond “checkbox” compliance to become true business enablers—accelerating growth, deepening customer trust, and supporting innovation...
info_outlineSecurity & GRC Decoded
In this episode of Security & GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Abhay Kshirsagar, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of security, compliance, and customer assurance. Abhay shares his journey from IT audit and risk advisory to leading compliance automation, continuous monitoring, and customer assurance at industry giants like Cisco and now Salesforce. They discuss how compliance programs can move beyond checkboxes to become strategic enablers of business growth, unlocking new markets,...
info_outlineSecurity & GRC Decoded
In this episode of Security & GRC Decoded, Raj Krishnamurthy, CEO of ComplianceCow, sits down with Walter Haydock, CEO of StackAware, to discuss the evolving landscape of AI security, governance, risk, and compliance (GRC). Walter shares insights on emerging AI threats, the importance of ISO 42001 certification, and the challenges organizations face when integrating AI into their security and compliance programs. Key topics include: DeepSeek and AI Privacy Risks Regulatory Challenges in AI Security & Compliance The Intersection of AI Governance and GRC Building a Business Case for AI...
info_outlineSecurity & GRC Decoded
In the premiere episode of Security & GRC Decoded, host Raj Krishnamurthy sits down with Mosi Platt, Senior Security Compliance Engineer at Netflix, to explore his unconventional journey into security and governance, risk, and compliance (GRC). From his first exposure to computers in his aunt’s home lab to becoming a leader in IT audits and compliance, Mosi shares the pivotal moments that shaped his career. Together, they unpack the realities vs. myths of security governance, why risk quantification is still an unresolved debate, and how security and GRC teams can move from reactive...
info_outlineIn this episode of Security & GRC Decoded, host Raj Krishnamurthy, CEO of ComplianceCow, sits down with Abhay Kshirsagar, Director of Security Services and Tools at Salesforce, to explore the evolving landscape of security, compliance, and customer assurance.
Abhay shares his journey from IT audit and risk advisory to leading compliance automation, continuous monitoring, and customer assurance at industry giants like Cisco and now Salesforce. They discuss how compliance programs can move beyond checkboxes to become strategic enablers of business growth, unlocking new markets, influencing revenue, and strengthening customer trust.
Key takeaways include:
✅ Compliance Automation & Risk Reduction: How automation is transforming GRC processes and reducing engineering burdens.
✅ Customer Assurance as a Competitive Advantage: Why transparency and trust are becoming business differentiators.
✅ Metrics That Matter: How compliance teams can track and demonstrate their impact beyond regulatory requirements.
✅ Future of GRC: The shift towards predictive security, self-service platforms, and risk-driven compliance models.
Tune in to hear practical insights, real-world strategies, and a fresh perspective on the intersection of security, compliance, and business success in today's fast-changing regulatory landscape.
🎙️ Security & GRC Decoded is brought to you by ComplianceCow. Subscribe now for expert insights from industry leaders shaping the future of security & compliance.
Learn More About How ComplianceCow Can Help Your GRC Team Today!
📌 Episode Timestamps
00:00 - Introduction
- Host Raj Krishnamurthy introduces the episode and guest Abhay Kshirsagar, Director of Security Services & Tools at Salesforce.
02:15 - Abhay’s Background & Journey into Security & GRC
- From Temple University to IT Audit & Cybersecurity.
- Early career in risk advisory and SOX ITGC.
- Transition to Silicon Valley and working on SOC 2 & ISO 27001.
08:45 - Joining Cisco & Building the Cloud Controls Framework (CCF)
- Creating Cisco’s CCF and open-sourcing it.
- Moving from compliance into product security and automation.
13:30 - Defining Security, Compliance & Customer Assurance
- Security = Protection, Compliance = Following Rules, Assurance = Transparency.
- How these functions overlap and why customer assurance is critical.
18:50 - GRC & Its Role in Business Growth
- How compliance unlocks market access & revenue growth.
- The real value of security & compliance programs beyond checkboxes.
23:20 - Customer Assurance & Measuring Customer Trust
- “What makes customers sad” – tracking gaps in compliance programs.
- Why SOC 2 isn’t enough for modern supply chain security.
28:00 - Industry Trends: Automation, Transparency & Supply Chain Security
- The rise of compliance automation and reducing engineering burdens.
- The role of SBOM (Software Bill of Materials) & SSDF in supply chain security.
34:10 - The Challenge of Security Transparency
- How to balance transparency with protecting sensitive data.
- The need for industry-wide frameworks for disclosure.
38:30 - Building a Business Case for GRC with Leadership
- The 4 key areas of GRC impact:
✅ Unlocking market access
✅ Staying regulatory compliant
✅ Managing security risks
✅ Improving customer trust - Why compliance isn’t just about cutting costs – it’s about business enablement.
45:00 - Starting & Scaling a Security GRC Program
- Step 1: Asset Management – Know your crown jewels.
- Step 2: Risk Assessment – Prioritize real threats.
- Step 3: Certification Strategy – Reduce compliance fatigue.
- Step 4: Automation – Continuous monitoring & control checks.
52:20 - Compliance Automation: What’s Next?
- How to move beyond traditional automation to predictive security models.
- Using historical data for proactive risk management.
58:40 - The Future of GRC: AI, Self-Service, and Security as a Business Enabler
- Building trust centers with AI-driven self-service.
- Reducing the burden on engineering with chatbots & automation.
1:03:15 - Book & Podcast Recommendations
- How to Measure Anything in Cybersecurity Risk 📖
- Why staying connected with industry peers is critical for solving GRC challenges.
1:06:30 - Closing Thoughts & Takeaways
- Final advice for security & GRC teams:
✅ Build strong relationships with engineering & leadership.
✅ Focus on risk-driven compliance, not just regulatory checklists.
✅ Leverage metrics & automation for better decision-making.
1:09:15 - Outro
- Where to follow Abhay Kshirsagar and ComplianceCow for more insights.