Risk in Dollars: The Future of GRC Measurement ft Ramya Subramanian, Director of GRC @ Freshworks episode artwork

EPISODE · Sep 4, 2025 · 54 MIN

Risk in Dollars: The Future of GRC Measurement ft Ramya Subramanian, Director of GRC @ Freshworks

from Security & GRC Decoded · host Raj Krishnamurthy

How does a network engineer become a GRC leader? Ramya Subramanian’s journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC & Privacy Operations at Freshworks, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down.Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing to business enabler. This episode is a playbook for anyone trying to modernize risk and compliance in fast-moving environments.5 Key TakeawaysEngineer’s edge in GRC: Why Ramya’s technical background makes her approach to governance unique.Quantifying risk with dollars: Why risk measurement needs financial context, not just “likelihood x impact.”Automation as a path forward: How Freshworks is reducing compliance toil for engineers.Simplify policies and awareness: Cutting policy docs by 90% and building bite-sized security training.GRC as PR: Storytelling and evangelism can reframe GRC as a business enabler, not a blocker.What You’ll LearnHow GRC and security complement each otherChallenges of risk quantification and continuous measurementWhy engineers perceive GRC as compliance taxHow automation and GRC engineering can reduce manual effortThe cultural perception of GRC and how to change it⏱️ (Approximate) Timestamps[00:01:43] From network engineer to GRC leader [00:03:37] How Ramya defines Governance, Risk, and Compliance [00:05:28] Quantifying risk: from controls to financial impact [00:07:41] Why continuous risk measurement is so hard [00:11:49] How others perceive GRC inside organizations [00:13:43] Changing the “policing” perception of GRC [00:17:50] Rewriting policies & security awareness at Freshworks [00:19:38] Bringing auditors along the journey [00:21:33] Reducing compliance tax with automation [00:26:10] Why GRC needs engineering skills [00:29:58] Technical vs non-technical sides of GRC [00:31:47] Skills Ramya looks for when hiring [00:33:53] Generative AI’s impact on GRC [00:37:49] Dream GRC solution: context-aware automation [00:39:32] Building a business case for automation [00:44:00] Who should tell the GRC automation story? [00:45:54] Challenges with auditors in the AI era [00:46:49] From city editor to GRC leader — storytelling roots [00:52:26] Rajinikanth’s influence at FreshworksThis podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: compliancecow.comConnect With Our Guest:Ramya Subramanian | Director of GRC & Privacy Operations | FreshworksConnect on LinkedInRate, review, and share if you enjoyed the show!Subscribe to Security & GRC Decoded wherever you get your podcasts:Spotify and Apple Podcasts

Episode metadata supplied by the publisher feed · Published Sep 4, 2025

Embed this episode

How does a network engineer become a GRC leader? Ramya Subramanian’s journey spans nearly two decades across IT, security, and governance. Now serving as Director of GRC & Privacy Operations at Freshworks, she joins Raj to unpack the evolving role of GRC: from quantifying risk and managing compliance debt to building automation that doesn’t slow engineering down. Ramya also shares how storytelling, PR-style evangelism, and simplifying policies can shift the perception of GRC from policing...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Risk in Dollars: The Future of GRC Measurement ft Ramya Subramanian, Director of GRC @ Freshworks

0:00 54:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security & GRC Decoded?

This episode is 54 minutes long.

When was this Security & GRC Decoded episode published?

This episode was published on September 4, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Security & GRC Decoded episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!