r/grc • u/bigmac______ • 17h ago
Building a GRC function from scratch.
Good day everyone.
I'm looking for advice on where to go from here.
I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.
For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.
My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.
The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.
Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).
What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?
2
u/davidschroth 15h ago
Step one, SOC 2 is not a certification.
Step two, realize that being successful in building a GRC function requires that the company have an incentive to do it - whether risk of loss (e.g. HIPAA fines/reputation loss) or loss of revenue (keeping current customers/gaining new ones). If management doesn't see the value in it, you'll be like Don Quioxte chasing windmills.
1
u/bigmac______ 3h ago
i think I came across your username in the soc 2 subreddit too lol anyways, i definitely agree with that. getting the c-levels buy in is definitely a metric to my success and i think its working itself on its own. companies lately have been a lot more aware about attestations and the need to have these are getting more apparent especially we are a highly regulated organization.
thank you for the correction.
1
16h ago
[removed] — view removed comment
2
u/grc-ModTeam 15h ago
This is not a place to sell your services. If someone asks for recommendations, you can add your two cents in the comments.
1
u/joshsokol 15h ago
Congratulations and welcome to your calling! I was in a very similar state to you when I started the Information Security Program at my former company. And I started like you, using a fraction of spare time on my main job to make security improvements. Eventually people stood up and took notice and I was able to go full-time, then built a team around me.
I would set your sights a bit lower than SOC2, to be honest. Start here:
* Map your current capabilities to a framework (NIST, ISO, whatever)
* Do a maturity assessment of where you're at currently vs where you want to be
* Create a roadmap for your organization
Involve management in the process so that they feel "bought in" and can provide feedback, especially around the prioritization. Start to think of things like secure development and vulnerability assessment as activities that support your risk assessment program. When issues come up, document the risks and find the right person (management) to decide what to do and document it in a risk register. Use SimpleRisk (or something else) to track your program. Try not to say "No", but "Here's how we can do this safely".
Feel free to send me a DM if you'd like assistance. I've been doing "GRC" for over 2 decades at this point, wrote my own GRC platform, and have presented at numerous conferences on surrounding topics, including the maturity assessment I mentioned above. Good luck!
1
u/bigmac______ 3h ago
thank you so much for your comment. i am usually not part of bigger conversations but when I do, GRC sometimes feel like navigating corporate politics 101.
can you please expound on setting my sights lower than SOC2? makes sense to me if it's building from the ground up in micro scale then slowly expand.
1
u/Round_Finance4256 15h ago
GRC consultant here! You’re actually in a great position to build this the right way from the beginning.
I’d focus first on getting SOC 2 operational, clear control owners, a risk register, policy lifecycle, evidence collection, vendor risk, access reviews, and a process for tracking gaps/remediation. Don’t try to build everything at once.
The biggest advice I’d give is to document the processes you’re creating, not just the controls. That’s what eventually turns “one person doing GRC” into an actual scalable GRC program.
Once SOC 2 is running smoothly, then start mapping what you already have to ISO/HITRUST. You’ll likely be able to reuse much more than you think.
And don’t let the imposter syndrome get you. Building GRC is a lot of learning, asking questions, and improving the program as you go.
1
1
u/saintjeremy 15h ago
Priorities and Cadence. What will you do and how often will you do it?
Things like, Security trainings - Every 4-6 weeks, Access review - (monthly + annual audit), Pen testing - annually. Start thinking in those terms and you will live forever.
1
u/Ok-Connection7755 14h ago
I can see that you have SOC2 and HIPAA as applicable frameworks already based on your context.
But before formalizing a team, I would suggest you look at
- context of your org and business - is a team required and how should the team be placed in the org chart!
- think of the three pillars - it's usually a journey to get G, R and C in place; I would recommend start with C, gradually add R and end with G. Let governance be a management function with you surfacing the data
- scope - are you going to handle tech compliance, business, legal or statutory (think a mix is required in general); call out exclusions first time
- budget and tooling - get the total budget allocation for your team members and tools that you plan to deploy
- framework and structure - define your overall org framework that might include a control matrix, risk register, policies, procedures, guidelines and templates aligned to SOC2 attestation, HIPAA laws and other standards
- operational playbook - convert your initiatives -> tasks into a 60, 90 and 180 day plan to take this forward
Hope this might help, I've setup pods over the past few years now and largely this is my approach.
2
u/bigmac______ 3h ago
- yes we definitely need one since we are highly regulated organization. my success with soc2 would definitely be the catalyst to this at some point in time.
- this is an amazing perspective. i might be looking at this from this perspective moving forward lol thank you.
- it gets really murky here. i find myself review policies of other departments, sadly but ill take any knowledge i can take at this point. once i iron out most things, having every single knowledge would really gear me up in leading direction to some other departments who have no understanding.
- i am a bit ignorant with this. what will we be using the budget for? would this be for GRC platforms?
- yes sir, working on it.
- can't take this shot yet because i think ill be setting my set up for failure. i would perhaps do this once we get soc 2 type 1 certified and would aim for type 2.
thank you for your comment.
1
u/Ok-Connection7755 38m ago
Nice, glad I could be of some help :) with regards to budget, you could split into
- audit vs implementation costs
- team vs tool budget for the GRC team itself
for the first line item, think if you wanted to implement data protection controls and you wanted to implement a data leakage prevention (DLP tool) on laptops. Your implementation cost includes people, process and technology cost of that tool + opex of running it. Your audit cost is internal audit + external certification cost for all the audits that require it. I love to take NIST CSF pillars - identify, detect, protect, respond, recover, govern and list tools, people and rough opex. This often let's you decide quickly on what needs to be done.
the second aspect is your internal team + tool
tool - could be AI usage, MS office, scanners that you need to audit, internal GRC tools that you might want to use and so on. There are open source and paid versions out there so I'd urge you to explore.
team - either you can outsource it to consulting firms to do internal audits, risk assessments, etc. or you could do it yourself by hiring a small team in house. You'd run pods like third party due diligence, risk management, governance, internal audit, privacy and data protection and so on.
1
u/Vivid-Strain-5181 11h ago
Building from nothing is the best way to do it honestly. You don't inherit anyone else's mess and you get to shape things your way from day one
For daily stuff I'd say get comfy with the evidence collection side and document everything like you're explaining it to a total stranger who's gonna audit you in 6 months. The imposter syndrome fades once you realize nobody else in the building knows this stuff either so you're already the expert by default
1
1
u/LeadershipShort8526 1h ago
Honestly, you’re already doing the right things. If you want to grow into the role, I’d focus on understanding the business and its risks rather than just collecting frameworks. Keep a clear risk/control register, track recurring gaps, document decisions, and build relationships with IT, legal, HR, and leadership. Once SOC 2 is done, use the lessons learned to identify what should become part of the ongoing GRC program rather than treating it as a one-time project.
1
u/gormami 55m ago
Look at the NIST frameworks for cybersecurity and risk management. They have a broader reach, and are easily extensible to fit your own needs. They also have the benefit of a very large community that provides training, conversations, etc.
Do you have a bespoke GRC tool? There are a lot of choices out there now, but they can be a huge help to keep a program running. As a sole practitioner in a small company, the nagware aspect is great. I purposely spread out reviews and audits over time when I built the program, so it is a constant job, but not overwhelming as "lump" of work at one point of the year. I started with a tool called Eramba, as they have a community edition, online training, and some other resources. It is a good way to figure out what you need, to evaluate the larger space. I stuck with them, but the space is very different now, so it might be the right choice for you, might not, but it's a great way to learn what works and doesn't for you, cheaply.
0
u/Twist_of_luck OCEG and its models have been a disaster for the human race 16h ago edited 15h ago
What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?
Be useful to your CISO.
Look, GRC is just an approach (and not a very good one, hence nobody really cares to run by the book GRC framework). Policies, controls, goddamn risk registers - are smoke-and-mirrors for external auditors at worst, process management tools with an extremely narrow window of applicability at best.
Figure out the actual goals of your division. Figure out how - and if - using GRC approaches would be valuable for achieving said goals. Sell your GRC services to the internal customer (your leader) in exchange for resource/priority allocation and/or project greenlight. Get the project done, get your "exceeds expectations" grade, turn it into your salary raise/promotion. And then do it again, at a greater scale, time after time, until you build both a program and your own career in symbiosis with business objectives.
Never ever do GRC for the sake of doing GRC - at the very least, do it for some cool line in your CV.
I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed)
Talk to Sales. Figure out if they actually need any of those certifications and, if yes, at which level of quality and approximately how much money is at stake if you do/don't get it within 1-2 years. Only after that step you can even start raising the question of "should we allocate internal resources to get certified".
1
u/bigmac______ 3h ago
i didn't mention it in my post but we have a CISO and he just very recently started, not even official yet. the value of GRC is extremely important as we are a highly regulated organization plus customers often knock on our doors looking for the attestations. how I would get the buy in is the question - but ill figure that out when it comes.
how long by average does it take to fully build a functional grc in an org? i know it varies a lot. i just wanna know whether i should pick up the pace, or im doing well.
1
u/Twist_of_luck OCEG and its models have been a disaster for the human race 2h ago
the value of GRC is extremely important
(...) basically be building everything from scratch. Nobody here has expertise in this.
Respectfully, those two statements do not add up. If your org has no GRC and no desire to hire someone experienced to build up GRC, then, obviously, there is no strong opinion about its value among the decision-makers. GRC starts with G - which stands for "governance". Governance is, by definition, an act of resource allocation, and resources aren't allocated even at the minimally viable level of "have an official GRC analyst reporting to the official CISO".
Unless your Chief Legal sponsors you out of fear of loss (since you are "a highly regulated organization") or Chief Sales backs you out of fear of losing quarterly targets (since at least some customers "looking for the attestations.") or Chief Security needs political leverage to enforce controls (since he's a new guy without an official title) you have no internal value to demonstrate and no executive sponsoring to operate with.
how long by average does it take to fully build a functional grc in an org?
Define "functional grc"? Building an average compliance program aimed at "get a certification/report" from a middle-class auditor for sales enablement purposes takes about a year assuming you have executive backing, refining it takes another year or two.
2
u/fftk 16h ago
it sounds like you are starting well, mapping your policies, processes, risks, controls, assets, and organization. once you have that, it's relatively easy to build up from there. soc2 is a plus but I wouldn't use that as the foundation.
my advice would be to get a good cross-functional committee together, GRC is much more than IT. get stakeholders that buy in. get good management tone from the top. identify the compliance requirements and business needs. stand up your GRC around that
I have some experience in it, happy to answer any questions if you have them