All Episodes

March 24, 2026 59 mins

In this episode of Security & GRC Decoded, Raj Krishnamurthy sits down with Steven Asifo, Director of Security & GRC at Yahoo, for one of the most refreshing conversations the show has had on communication, influence, and the human side of security. Drawing on his unusual dual life as both a cybersecurity leader and a stand-up comedian, Steven makes the case that security and GRC are not just technical disciplines — they are fundamentally communication disciplines. From using analogies to explain vulnerabilities, to reframing GRC as the “Draymond Green” of cybersecurity, Steven shows how the best security leaders translate complexity into clarity, help the business make better decisions, and meet people where they are instead of overwhelming them with jargon.

Key Takeaways:

  • Security and GRC succeed when they communicate clearly to humans, not when they simply present more technical detail.
  • The best GRC teams act as guides that help the business make reasonable, compliant, cyber-conscious decisions.
  • Metrics only matter when they drive a clear outcome or decision, not when they exist for their own sake.
  • Strong GRC teams build trust by doing the hard, cross-functional work that others often avoid.
  • Storytelling is a core security skill because people act on messages they understand, remember, and relate to.

What You’ll Learn:

  • Why Steven believes security is ultimately a human communication problem.
  • How to tailor security messaging for engineering leaders, CISOs, and business stakeholders.
  • What “guardrails not gates” looks like in a practical GRC program.
  • How to think about data, metrics, and reporting without overwhelming your audience.
  • Why AI may change the consumption layer of GRC, but not eliminate the human need for storytelling.

This podcast is brought to you by ComplianceCow — the smarter way to manage compliance. Automate evidence collection, eliminate screenshots, and scale your program with confidence. Learn more: https://www.compliancecow.com

Watch more episodes: https://www.compliancecow.com/podcast

Connect With Our Guest:
Steven Asifo | Director of Security & GRC | Yahoo
Connect on LinkedIn:
https://www.linkedin.com/in/asifosays/

Rate, review, and share if you enjoyed the show!

Subscribe to Security & GRC Decoded wherever you get your podcasts:

Spotify: 
https://open.spotify.com/show/5pigcMwOrYIA6d9OOOsxqr?si=416b82ab5c474683


Apple Podcasts:
https://podcasts.apple.com/us/podcast/security-grc-decoded/id1795144450

Listen
Watch
Mark as Played

Advertise With Us

Popular Podcasts

Hey Jonas!

Hey Jonas!

Hey Jonas! The official Jonas Brothers podcast. Hosted by Kevin, Joe, and Nick Jonas. It’s the Jonas Brothers you know... musicians, actors, and well, yes, brothers. Now, they’re sharing another side of themselves in the playful, intimate, and irreverent way only they can. Spend time with the Jonas Brothers here and stay a little bit longer for deep conversations like never before.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Stuff You Should Know

Stuff You Should Know

If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices