A conversation with Nidhi Luthra – cybersecurity, risk, and resilience executive and multi-time healthcare CISO. Hosted by Jane Totaro.
“GRC is still, unfortunately, largely synonymous with compliance. That’s a mistake.”
That’s how Nidhi Luthra frames the shift at the center of this episode. Over a career spanning cybersecurity, enterprise infrastructure, large-scale transformations, M&A, and AI governance, she’s learned that meeting regulations and passing audits is the foundation of a risk program, not the goal.
In the latest episode of GRC & Me, host Jane Totaro sits down with Nidhi to unpack what it really takes to move GRC past the checklist and into its most valuable role: helping leaders make better, faster, more confident decisions. As Nidhi puts it, at its best GRC “gives leaders the information and the confidence to take smart risks, not just avoid them.”
Episode Highlights You Won’t Want to Miss:
- The myth that you must be a deep technical expert to become an effective CISO and why an unconventional path can be your biggest strength
- Why boards aren’t asking “Are we compliant?” They’re asking “Are we resilient?” And how to present risk as a decision document, not a status update
- The question that cuts through compliance noise: “If I could only fix five things this year, what would actually make this organization more resilient?”
- What Nidhi looked for as a GRC buyer, and why fit beats a feature checklist
- A practitioner’s playbook for building, or leveling up, a modern risk program
Drawing on 15 years in healthcare and earlier roles across financial services, insurance, and manufacturing, Nidhi is candid, practical, and refreshingly honest about the realities of the job. Whether you’re a GRC practitioner with your sights set on the CISO seat or a leader rethinking what your risk program should deliver, this one’s for you.
Watch the Full Episode
Subscribe to GRC & Me for new conversations with the leaders shaping the future of governance, risk, and compliance.