EPISODE · Apr 21, 2026 · 55 MIN
The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Val Dobrushkin, Director of GRC at Tricentis, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers.This conversation dives into the disconnect between frameworks and reality, the limits of SOC 2, the role of GRC in revenue and M&A outcomes, and why solving for today while building for the future is the key to long-term success.Key Takeaways:Third-party risk management is fundamentally broken due to over-reliance on questionnaires and weak enforcement of meaningful controls.SOC 2 is too flexible and inconsistent to be relied on as a true indicator of security maturity.GRC has a unique advantage over security in directly demonstrating business value and revenue impact.“Solve for now, build for later” is critical for startups and fast-growing companies preparing for IPO or acquisition.Strong GRC programs can directly influence company valuation by identifying contractual and compliance gaps early.What You’ll Learn:Why questionnaires and annual vendor reviews fail to capture real third-party riskHow GRC teams can prove revenue impact through customer trust and assuranceThe hidden role of GRC in M&A, IPO readiness, and contract validationWhy most GRC metrics fail and what meaningful measurement should look likeHow to implement a “solve now, build for future” strategy in fast-growing companiesThis podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.comWatch more episodes: https://www.compliancecow.com/podcastConnect With Our Guest:Val Dobrushkin | Director of GRC | TricentisConnect on LinkedIn: https://www.linkedin.com/in/dobrushkin/Rate, review, and share if you enjoyed the show!Subscribe to Security & GRC Decoded wherever you get your podcasts:Spotify: https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683Apple Podcasts: https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450
Embed this episode
What this episode covers
In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Val Dobrushkin, Director of GRC at Tricentis, to challenge one of the most overlooked failures in modern security programs: third-party risk management. Drawing from his experience building GRC programs at ForgeRock, NoName Security, and beyond, Val explains why most organizations are still stuck in compliance theater and how GRC teams can evolve into true business enablers. This conversation dives into the discon...
NOW PLAYING
The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.