Risk Grustlers EP 8 | A scoop of risk, squishy not crunchy!

Get ready to explore the crunchy and soft side of GRC in the eighth episode of our podcast Risk Grustlers, with Jason Leuenberger, a Leadership and Team Coach, who specializes in GRC.
With over twenty years of experience in the industry, Jason is the perfect guide to help you master the often overlooked softer side of GRC. He emphasizes the importance of skills like communication and relationship-building in strengthening risk management.
Jason also offers insights into how GRC professionals dealing with a crunchy mindset can transition to softer tasks requiring behavior changes across teams.
The insightful conversation ends with him discussing his unique practice called Kinkou and its benefits for GRC leaders with our CEO Aayush Ghosh Choudhury.
Watch the complete podcast here
Here are some highlights from the engaging episode.
Aayush: Could you discuss some insights you gained during your long GRC journey?
Jason: I've been chewing on this idea for about a decade now – that risk management isn't all crunchy and rigid. It's not just about frameworks, tools, and giving directives. What's been largely overlooked is the softer, more human side of risk.
You know, how company culture, teams, and systems within an organization play into risk management. Especially if you're approaching it from a very crunchy perspective. I've been quite immersed in that crunchy approach for the past 20 years, deep into technical domains. I'm really into the technical aspects, the nitty-gritty of GRC. I find the innovative ways to simplify things intriguing, trying to make it less crunchy, more people-friendly. But even though I've been in that crunchy mindset, I've been wondering, how can we make risk management more data-driven?
How can we quantify everything, back it up with numbers? How can we use data to clearly show when we're in a crunchy situation and need to step back? But you know what? In the process of all this technical focus, I realized I was missing a crucial piece – understanding people's perspectives. Those teams and individuals dealing with difficulties, fears, and uncertainties that impact their risk decisions.
Aayush: Can you let us in on what the soft and squishy side of GRC entails?
Jason: The human side of risk is what I like to call the softer side. You've probably heard of “soft skills,†but honestly, that term doesn't do them justice. These skills are anything but soft – they're pretty tough.
You know, when it comes to these so-called “soft skills,†many struggle because they involve our human aspects. We often assume that people are either naturally born with talents like communication and relationship-building or they're not. But the truth is, these are skills that we can learn, understand, and actually develop over time.
And regarding your question about the key components of this softer side and the patterns I've observed, well, there are definitely some strong trends. I've even given presentations on this topic, and I'm in the process of crafting a manifesto that covers several of these key ideas.
I also touch on these concepts in my work with GRC assessments. While I don't do a ton of that these days, I still occasionally get involved in more substantial GRC assessments, depending on the specific situation, project, and client. So, when we find ourselves favoring a sense of knowing over learning, it's often a signal that we might be leaning too heavily toward the rigid side of things.
Aayush: What would be some examples of situations where there was a trade-off between knowing and learning and what were the interventions that you made?
Jason: I've run into CISOs and risk pros at the executive level who are just plain frustrated. They're like, “Why is no one listening? Why do I have to keep saying the same thing over and over?â€Â
So, diving into this, when we really unpack it, a big part of this frustration comes from our personal fears. As risk professionals, we often fear not being right. People look to us for solutions to those potential risks, those worst-case scenarios we're trying to prevent.
Sometimes, we come in thinking we've got it all figured out. We have a framework, analysis methods, the whole shebang. We're confident that we know the controls to tell people, where the failures are, the problems, everything. But what we miss is asking questions to truly understand the deeper issues. Like, why is this a challenge for that team? Or how does the company culture play into certain risk decisions?
You know, they might be facing common or ongoing risks that they just can't seem to tackle, despite staring them in the face for years. It's about getting under the surface and understanding what's holding them back.
Aayush: Risk management often doesn't get a dedicated team until companies reach a certain size and scale. The CISO or VP of Information Security ends up handling it as a side task and when an incident happens, they end up taking the fall. It's also tough for them to drive change across the organization because they need buy-ins from different teams. What are your thoughts on this?
Jason: Totally get what you're saying – it's the defender's dilemma. CISOs and risk folks carry this concern with them every day. They're haunted by the thought that attackers just need to be right once, while they feel they have to be right all the time.
I hear this often too – the term “buy-in.†It's like, “I just need these people to buy in. Why won't they?†But here's the twist, what does buy-in really mean? Do you want them to just nod along or robotically follow your instructions?
Here's the thing: buy-in usually sounds like an ultimatum. It's like, “Agree or else.†But there's a difference between buy-in and weigh-in. Weigh-in should always come before buy-in. See, if we don't take the time to ask questions, understand their viewpoint, and give them the chance to weigh in, they feel like they're being told what to do, without any say.
So, when we skip the weigh-in part and leap straight to “achieved buy-in,†they feel sidelined in deciding their risk journey. This contributes to the rigid side – we're not letting them have a voice in their risk choices.
And this mismatch can lead to defensive behavior, signals that they're disinterested or shut down. They don't feel heard or involved. They might even resist by going completely against what we're suggesting. It's a dynamic that adds to that crunchy side.
Aayush: What happens when GRC professionals on the crunchy side have to carry out softer tasks that require things like behavior changes across teams? What steps have you taken to help such people bridge this gap?
Jason: It's all about their choice – the clients decide which intervention works best for them. It boils down to what's personally tough for them. I mean, what's challenging specifically for them, not for someone else. Changing people and teams? Well, that's quite the task, you know, we can't reshape them as much as we wish we could.
It just doesn't work that way. So, here's the deal: how are you playing into this scenario? How's the difficulty or challenge showing up for you? Often, leaders are looking for some common shifts in themselves. Like, they're becoming more at ease with asking questions to grasp viewpoints from the other side. You know, from across the table or different teams or audiences.
Maybe it's about talking to someone who's just not vibing with the risk management program as it's been pitched so far. Or perhaps they don't quite get their role in risk management as a whole. It's about being open to learning about people rather than already having all the answers on what they need to do. Because thinking you've got it all figured out can really narrow your path and isolate others.
So, one change leaders often strive for is transitioning from a rigid control mindset to a more open, adaptable one. And then they wonder, what small practices can help them shift from rigid to flexible, from fixed to expansive? You know, from being all about control to collaborating intelligently with diverse people and teams.
Aayush: Can you talk about the three most common interventions that you see yourself having to do over and over again to promote the softer side of risk management?
Jason: So, if I had to pick three key changes, the first one that immediately pops up is starting small. This applies not just to us getting a better grip on ourselves through increased self-awareness – which is a superpower for leaders – but also to any change we want to make, whether it's personal or for our organization's culture. I often advocate aiming for 1% gains – tiny improvements that can add up big.
Next up, there's the balance between listening and talking. It's kind of like the earlier point about learning versus knowing. How often are we really listening, grasping the reality of control owners or performers? What's their day-to-day like? Their struggles, their exceptions – really diving into their world. It's crucial to shift from control exercises to meaningful engagement.
And last but not least, there's the dance between empathy and collusion. It's essential to understand someone's shoes without actually wearing them. Building rapport and understanding doesn't mean we're compromising integrity; after all, risk management is about assistance, not cheating. With empathy, we're tapping into the human side, recognizing that everyone's job is tough and they're just trying to do their best. So, embracing empathy paves the way for meaningful change in the long run.
Aayush: Can you tell us about your practice?
Jason: I started a practice called Kinkou. I'm all about partnering with leaders who are up for the challenge of change. Change isn't a walk in the park, but it's where the real growth happens. It's the game-changer that can make a leader or any professional step up and make a meaningful impact, unlike the traditional crunchy approach that's been around for years in this industry.
We've been sticking to the crunchy side for far too long, overlooking the human and emotional aspect of our work. And let's face it, risk and fear aren't anyone's favorite topics. So, how can we adjust ourselves to create a warmer, more productive collaboration where we can make real progress together? That's what I explore in my sessions.
You can learn more about Jason's practice at kinkou.org. Feel free to contact him at jason@kinkou.org.
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
See what a real security- first GRC platform looks like
Ready to see what security-first GRC really looks like?
Focus on the traveler experience. We’ll handle the regulations.
Get Scrut. Achieve and maintain compliance without the busywork.
Choose risk-first compliance that’s always on, built for you, and never in your way.
Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?
Join the thousands of companies automating their compliance with Scrut.
The right partner makes all the difference. Let’s grow together.
Make your business easy to trust, put security transparency front and center.
Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.
Your GRC team, multiplied and AI-backed.
Modern compliance for the evolving education landscape.
Ready to simplify healthcare compliance?
Don’t let compliance turn into a bottleneck in your SaaS growth.
Find the right compliance frameworks for your business in minutes
Ready to see what security-first GRC really looks like?
Real-time visibility into every asset
Ready to simplify fintech compliance?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Tag, classify, and monitor assets in real time—without the manual overhead.
Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.
Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.
Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.
Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.
Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.
Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.
Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.
Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.
Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.
Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.
Scrut ensures access permissions are correct, up-to-date, and fully compliant.
Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?
Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.
Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.
Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.
Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!
Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.
Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!
Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.
Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.
Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.
Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.
Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.



