The Hitchhiker’s Guide to the GRC Technology Galaxy
Welcome, interstellar travelers, to the Hitchhiker’s Guide to the GRC Technology Galaxy, your improbable companion through the expanding universe of governance, risk, and compliance.
In a cosmos where regulations multiply faster than Tribbles, cyber incidents drop like falling whales, and third parties sprout surprises with Vogon-level timing, this podcast is your towel, your Babel Fish, and your improbability drive rolled into one.
Each episode, Michael Rasmussen and guests explore the constellation of GRC technology, from digital twins and AI copilots to compliance nebulae and audit wormholes. We chart the domains, decode the jargon, and help you survive vendor poetry that promises everything and delivers nothing.
Whether you’re a compliance officer, risk manager, or just someone trying to make sense of improbable business realities, this guide offers clarity, humor, and a reminder of the most important rule of all, don’t panic.
End of transmission. Prepare for the next hyperspace jump.
Episodes

Thursday Dec 04, 2025
Thursday Dec 04, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen is joined by iluminr to confront a hard truth: business continuity is dying, and resilience must take its place. Organizations today aren’t just facing power outages and weather events, they’re also preparing for ransomware, geopolitical escalation, misinformation, deepfakes, and a threat landscape evolving faster than any static plan can keep up with.
They discuss how iluminr’s Microsimulations deliver a modern approach to readiness, replacing binder-based optimism with data-driven capability intelligence. From 15-minute learning reps to immersive crisis scenarios, iluminr helps teams strengthen instinct, accelerate decisions under pressure, and produce tangible evidence for regulators, auditors, and boards.
The conversation also uncovers how iluminr is expanding simulations into boardrooms, and how AI plays a dual role of powering new exercises and preparing organizations for AI-driven threats. And with large-scale events like Gameday Ready London, iluminr is bringing a risk and resilience Holodeck to life, giving organizations a glimpse of tomorrow’s crisis before it arrives.
In a galaxy where uncertainty is inevitable, iluminr offers a powerful promise: resilience you can prove.

Thursday Nov 20, 2025
Thursday Nov 20, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with apexanalytix to chart a course through the sprawling universe of third-party and vendor relationships—where complexity multiplies, risks hide in plain sight, and organizations often panic at the wrong end of the lifecycle.
Unlike many in the space, apexanalytix begins not with risk, but with supplier governance, the foundational understanding of who a supplier is, what they do, and the context of the relationship. From there, they layer on a full constellation of risk domains, such as cybersecurity and IT, anti-bribery and corruption, financial viability, fraud, sanctions, politically exposed persons, negative media, ESG factors, and more. They explore how apexanalytix blends its own proprietary intelligence with external data sources to give organizations a richer, more accurate view of their supply base.
The conversation also examines some of the big challenges facing organizations today, from survey and questionnaire fatigue to redundancy across assurance processes, and how apexanalytix is working to make these steps smarter, lighter, and less painful. They dive into the often-neglected universe of offboarding, where many organizations unintentionally create exposure, and how a true lifecycle approach prevents risk from slipping through the cracks.
Michael and the team also unpack who apexanalytix is ideal for, why large enterprises and smaller organizations alike choose them, and how AI fits into their roadmap as they continue to expand automation, insight, and intelligent action across the supplier ecosystem.
As the conversation wraps, apexanalytix looks ahead to a future where supplier governance, risk intelligence, and AI-driven automation converge to give organizations greater clarity, stronger relationships, and fewer unpleasant surprises in the extended enterprise. In a universe crowded with unknowns, apexanalytix makes the case that the smartest path forward begins not with panic, but with a complete understanding of who your suppliers are, and what they mean to your mission.

Thursday Nov 13, 2025
Thursday Nov 13, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Cura Software Solutions to explore how a platform that began as a focused risk tool has evolved into a global, end-to-end GRC ecosystem. From enterprise risk to operational resilience, audit, compliance, legal, analytics, and more, Cura now spans an entire constellation of capabilities used by organizations across Africa, the UK, the US, India, Australia, Malaysia, and beyond.
The conversation dives into the timing of South Africa’s newly released King V corporate governance code, how it reshapes expectations for accountability and transparency, and how Cura is helping organizations operationalize these principles in practice. They also explore the types of clients where Cura is gaining the most traction, the reasons those organizations choose Cura, and what truly sets the platform apart.
Cura shares its vision for the next few years, from deeper globalization to expanding solution breadth, and the emerging role of agentic AI, including what the company is delivering today and what customers can expect tomorrow.
In a galaxy crowded with tools that overcomplicate the basics, Cura’s story is one of evolution, clarity, and continuous reinvention, an ever-expanding guide to governance in an improbable universe.

Thursday Nov 06, 2025
Thursday Nov 06, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with the team at Decision Focus to explore why the future of GRC isn’t about more features, it’s about better decisions. They discuss how culture, values, and the people building and using the technology shape outcomes far more than checklists or templates ever could.
The conversation examines how Decision Focus’s platform is designed not to simply enforce compliance, but to support judgment, clarity, and meaningful collaboration across the business. They break down how the company’s culture informs its product philosophy, how that philosophy encourages a culture of risk awareness and accountability, and how naming the company “Decision Focus” wasn’t branding, it was intention.
The team also reflects on how the company and product will evolve in the coming years, and how the next era of GRC will be defined less by box-ticking and more by confident, evidence-backed choices made at every level of the organization.
In a galaxy full of complexity, noise, and endless dashboards, Decision Focus makes the case for clarity, culture, and decisions that matter.

Friday Oct 31, 2025
Friday Oct 31, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Jason Sechrist of AuditBoard to explore how the company has transformed from an audit tool into one of the most intelligent platforms in the GRC cosmos. They discuss what makes AuditBoard distinctly improbable—a platform that’s as beautiful as it is powerful, blending a clean, intuitive UX with the analytical depth needed to quantify, automate, and orchestrate assurance at scale.
Jason dives into how AuditBoard unites Monte Carlo and bow-tie analysis for next-generation risk quantification, delivers a no-code environment built for flexibility, and uses AI not as a shortcut but as an amplifier, powering smarter assurance and accelerating insight across the enterprise.
The conversation also explores who AuditBoard is built for, where it’s growing next, and how its people and culture fuel the platform’s evolution. Three years from now, AuditBoard envisions a connected GRC universe where usability, intelligence, and human ingenuity work together, proving that even in an improbable galaxy, assurance can be both art and science.

Thursday Oct 23, 2025
Thursday Oct 23, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen connects with the Riskonnect CEO, Jim Wetekamp, to explore how the company is helping organizations see through the code of risk, from insurable exposures and geopolitical volatility to AI-driven analysis and quantified decision-making.
The discussion dives into what Riskonnect delivers across the GRC universe today, what it’s building for tomorrow, and how agentic AI is accelerating the maturity of the entire field. From risk quantification and scenario analysis to integrated insights across enterprise, compliance, and continuity, Riskonnect’s approach helps organizations understand not just individual risks, but how they interconnect and evolve in real time.
The team also shares a glimpse into Konnect 2025, Riskonnect’s annual conference, and its Matrix-inspired theme: learning to see beyond the surface and decode what’s really happening in the world of risk. In an era defined by complexity and uncertainty, this episode shows why clarity may be the most improbable superpower of all.

Thursday Oct 16, 2025
Thursday Oct 16, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Alex Hollis of SureCloud to discuss how the company is rewriting the rules of digital risk and resilience. SureCloud’s event-sourced architecture captures everything that ever happens in the system (every change, every control, every decision) allowing organizations to recreate their compliance universe at any point in time.
The conversation explores what SureCloud does best, what problems it solves most effectively, and where it fits across enterprise risk, IT, compliance, and legal functions. Alex shares how this architecture enables true evidence-based compliance, what’s next for the platform, and how SureCloud is leveraging AI to enhance intelligence and automation without losing the human partnership that defines its culture.
As most GRC platforms orbit predictably around static frameworks, SureCloud’s event-driven approach represents something rarer—a living, evolving system built for resilience, context, and confidence in an improbable universe.

Thursday Oct 09, 2025
Thursday Oct 09, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Comply to explore what sets the firm apart in the sprawling universe of financial services compliance. Serving clients across the US, UK, and more than 60 countries, Comply supports firms of every size, from global institutions to boutique shops, with solutions tailored to private funds, broker-dealers, investment banks, and wealth managers.
The conversation dives into Comply’s strengths, including policy management, culture, and a model built on partnership rather than just software. We also chart how Comply is embracing AI, not as a buzzword but as a practical tool to enhance compliance efficiency and effectiveness. Looking ahead three years, the discussion explores where Comply sees its product, solutions, and organization evolving and how it plans to keep its clients future-proofed in an industry where change is the only constant.
From differentiation and culture to AI and long-range vision, this episode shows why Comply aims to be more than just another tool in the kit, but a partner in navigating the improbable galaxy of regulatory compliance.

Thursday Oct 02, 2025
Thursday Oct 02, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Steve Scharlman of Archer to chart the platform’s evolution from its early days to its role today as a cornerstone of enterprise risk and compliance. Once a household name for CISOs, Archer has become just as essential for chief risk officers, ethics leaders, and compliance officers navigating an ever more complex universe.
The conversation explores how Archer has grown and changed over the years, what sets it apart in the crowded GRC cosmos, and the innovations that should have organizations most excited about its future. At the heart of it all is risk quantification, the shift from gut feelings to data-driven insights that inform smarter, faster decisions.
From its pioneering roots to its renewed leadership in the GRC galaxy, this episode maps Archer’s improbable journey and the new frontiers it is set to explore.

Thursday Sep 25, 2025
Thursday Sep 25, 2025
In this episode of The Hitchhiker’s Guide to the GRC Technology Galaxy, Michael Rasmussen sits down with Renee Murphy, analyst, advisor, and master storyteller, to look back at the origins of the term “GRC” and trace how the technology space has evolved since its early days.
Together they reflect on their parallel paths as analysts shaping the field, sharing what has worked, what hasn’t, and what needs to change. The conversation explores the good, the bad, and the ugly of GRC technology and implementation, from ambitious vendor promises to the realities of deployment. They also discuss what the next generation of buyers (millennials and Gen Z) expect from GRC solutions, and what providers must do to earn their trust.
Part history lesson, part candid roadmap, this episode offers practical best practices, unfiltered insights, and a reminder that the GRC galaxy is still expanding and those who adapt will chart the course forward.







