Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue episode artwork

EPISODE · Oct 16, 2025 · 1H

Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue

from Security & GRC Decoded · host Raj Krishnamurthy

In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions.He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through a practical, approachable lens. Tony also explores how generative AI is transforming risk quantification and what every CISO, analyst, and engineer can do today to make risk measurable, actionable, and business-aligned.Key TakeawaysCRQ doesn’t require perfection—start with what you have and refine over time.The most effective risk programs focus on directionally correct data, not precision.Good risk scenarios clearly define asset, threat, and effect to avoid misalignment.Generative AI accelerates scenario development, data research, and model creation.CISOs should demand more from risk teams—move beyond “pick a color” heat maps.Topics CoveredCyber risk quantification (CRQ)Monte Carlo simulations and modelingRisk scenario design and measurementGRC and compliance integrationGenerative AI in risk managementMoving from qualitative to quantitative riskImproving risk hygiene and maturityCISO leadership and risk cultureWhat You’ll LearnThe difference between qualitative and quantitative risk methodsHow to conduct your first risk quantification in ExcelWhy Monte Carlo simulations are simpler than most thinkHow GRC, compliance, and security teams can collaborate effectivelyThe six levers that influence risk magnitude and frequencyThis podcast is brought to you by ComplianceCow:ComplianceCow helps enterprises automate GRC, shift compliance left, and continuously monitor controls across the business. Learn more at ComplianceCow.comConnect with our guest: Tony Martin-Vegue on LinkedInCo-Chair, FAIR Institute San Francisco ChapterFormer Risk Leader at Netflix and Gap Inc.Author, From Heat Maps to Histograms (coming 2026)Subscribe to Security & GRC Decoded on your favorite platform:SpotifyApple PodcastsExplore all episodes: ComplianceCow.com/podcast

Episode metadata supplied by the publisher feed · Published Oct 16, 2025

Embed this episode

In this episode, Raj Krishnamurthy speaks with Tony Martin-Vegue, seasoned risk practitioner, speaker, and co-chair of the FAIR Institute San Francisco chapter. Tony shares decades of lessons learned from leading cyber risk management at Netflix, Gap, and other major enterprises—showing how to move from qualitative heat maps to quantitative insights that drive smarter business decisions. He breaks down Monte Carlo simulations, risk modeling, and the six levers that influence risk—all through ...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Rethinking Risk: Data-Driven Decisions for Modern CISOs ft Tony Martin-Vegue

0:00 1:00:29

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security & GRC Decoded?

This episode is 1 hour and 0 minutes long.

When was this Security & GRC Decoded episode published?

This episode was published on October 16, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Security & GRC Decoded episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!