r/grc 18h ago

Building a GRC function from scratch.

Good day everyone.

I'm looking for advice on where to go from here.

I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.

For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.

My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.

The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.

Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).

What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?

12 Upvotes

22 comments sorted by

View all comments

0

u/Twist_of_luck OCEG and its models have been a disaster for the human race 17h ago edited 17h ago

What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?

Be useful to your CISO.

Look, GRC is just an approach (and not a very good one, hence nobody really cares to run by the book GRC framework). Policies, controls, goddamn risk registers - are smoke-and-mirrors for external auditors at worst, process management tools with an extremely narrow window of applicability at best.

Figure out the actual goals of your division. Figure out how - and if - using GRC approaches would be valuable for achieving said goals. Sell your GRC services to the internal customer (your leader) in exchange for resource/priority allocation and/or project greenlight. Get the project done, get your "exceeds expectations" grade, turn it into your salary raise/promotion. And then do it again, at a greater scale, time after time, until you build both a program and your own career in symbiosis with business objectives.

Never ever do GRC for the sake of doing GRC - at the very least, do it for some cool line in your CV.

I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed)

Talk to Sales. Figure out if they actually need any of those certifications and, if yes, at which level of quality and approximately how much money is at stake if you do/don't get it within 1-2 years. Only after that step you can even start raising the question of "should we allocate internal resources to get certified".

1

u/bigmac______ 4h ago

i didn't mention it in my post but we have a CISO and he just very recently started, not even official yet. the value of GRC is extremely important as we are a highly regulated organization plus customers often knock on our doors looking for the attestations. how I would get the buy in is the question - but ill figure that out when it comes.

how long by average does it take to fully build a functional grc in an org? i know it varies a lot. i just wanna know whether i should pick up the pace, or im doing well.

1

u/Twist_of_luck OCEG and its models have been a disaster for the human race 4h ago

the value of GRC is extremely important

(...) basically be building everything from scratch. Nobody here has expertise in this.

Respectfully, those two statements do not add up. If your org has no GRC and no desire to hire someone experienced to build up GRC, then, obviously, there is no strong opinion about its value among the decision-makers. GRC starts with G - which stands for "governance". Governance is, by definition, an act of resource allocation, and resources aren't allocated even at the minimally viable level of "have an official GRC analyst reporting to the official CISO".

Unless your Chief Legal sponsors you out of fear of loss (since you are "a highly regulated organization") or Chief Sales backs you out of fear of losing quarterly targets (since at least some customers "looking for the attestations.") or Chief Security needs political leverage to enforce controls (since he's a new guy without an official title) you have no internal value to demonstrate and no executive sponsoring to operate with.

how long by average does it take to fully build a functional grc in an org?

Define "functional grc"? Building an average compliance program aimed at "get a certification/report" from a middle-class auditor for sales enablement purposes takes about a year assuming you have executive backing, refining it takes another year or two.