GRC Engineer

Deep-dive on Cyber Risk Quantification and GRC w/ Tony Martin-Vegue from Netflix

Jul 29, 2025
Tony Martin-Vegue, an expert in risk quantification and GRC engineering at Netflix, shares his insights on navigating the complex world of cyber risk. He discusses his journey from IT to risk management and highlights the transformative power of the FAIR framework. The conversation delves into the critical role of AI in speeding up risk assessments, effective communication for decision-makers, and the importance of viewing GRC as a business enabler. Tony also introduces his new Substack and upcoming book aimed at simplifying cyber risk quantification for all.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

FAIR vs CRQ Explained

  • FAIR is a methodology tool, while cyber risk quantification (CRQ) is the broader philosophy.
  • One can do CRQ without FAIR, but FAIR provides a ready-to-use framework to start quickly.
ADVICE

Everyone Benefits from Risk Quantification

  • Quantified risk assessments benefit everyone from executives to legal and operational teams.
  • They enable richer conversations about trade-offs, investments, and prioritization tailored to each stakeholder.
ADVICE

Rethink Bias Towards Remediation

  • Avoid bias towards remediation; risk management should enable better decisions about accepting, transferring, or even increasing risk.
  • Focus on ROI and business objectives rather than simply turning red risks to green.
Get the Snipd Podcast app to discover more snips from this episode
Get the app