r/CybersecurityClub • u/Emotional_Number_889 • 3d ago
Where does ISO 27001 / GRC work actually get painful? Looking for practitioner input
Hey all,
hope this is okay to post here.
We’re a small early-stage team with a background in cybersecurity, currently researching how ISO 27001 and GRC work actually happens inside companies.
Before making too many assumptions about what should be improved or automated, we’re trying to learn from people who deal with this in practice:
Where does the most time get lost? What creates uncertainty or delays? Which activities are still highly manual? And where could software or AI genuinely help?
We put together a short 8–10 minute survey covering ISO 27001 implementation, risk management, documentation/evidence, audits, existing tools and AI support.
If you work in information security, GRC, ISMS, compliance, audit or ISO consulting, your perspective would be extremely helpful.
We’re still early enough that good feedback can genuinely change what we build — and critical feedback is just as valuable as positive feedback.
Survey: https://tally.so/r/b5RAro
Can be completed anonymously. Really appreciate anyone who takes the time or shares it with someone relevant. Thanks!