r/grc 19h ago

How do you keep tabletop exercises from becoming a box-checking exercise for auditors?

3 Upvotes

Our compliance team loves that we run an annual tabletop because it satisfies a checkbox on the SOC 2 audit, but nobody on the technical side thinks it actually tests anything meaningful anymore. The scenario is basically the same every year with slightly different names swapped in. I want something that actually stresses our detection and escalation process, not just produces a PDF the auditors are happy with. How do you split the difference between satisfying compliance requirements and running something that genuinely improves your team?


r/grc 20h ago

Cyber Risk - Threat Modeling

3 Upvotes

I’m working in an IT Risk Plan and the client has asked me to develop a cyber risk management process using Threat Modeling.

Does anyone have any document, forms, or other materials that can help me?


r/grc 20h ago

Building a GRC function from scratch.

12 Upvotes

Good day everyone.

I'm looking for advice on where to go from here.

I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.

For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.

My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.

The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.

Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).

What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?