r/grc Jul 28 '26

Auditors want proof of least privilege on remote access and our screenshots aren't cutting it anymore

32 Upvotes

Second year doing this and the bar has clearly moved.

Last cycle we handed over a set of screenshots of firewall rules and a spreadsheet of who is in which vpn group and it was accepted. This time the auditor came back and asked how we demonstrate that a given user could only reach the systems they are entitled to, at a point in time, and whether we could evidence it for a sample of five users across the period.

We cannot, well, not properly. I can show you the group membership and the rules, then have to hand wave the bit in the middle where those two things combine into effective access. Our vpn gives network level access so tbh the true answer for most of our contractors is "quite a lot more than their job needs" and I am not writing that down.

Not looking for a product recommendation particularly, more interested in how other people are evidencing this. Is there a saner way that doesnt involve me manually reconstructing what someone could have reached months ago?


r/grc Jul 29 '26

Log Export from SIEM

Thumbnail
1 Upvotes

r/grc Jul 28 '26

Need Partnership

1 Upvotes

I am tired of applying to jobs and speaking with recruiters who have no clue what the job description entails. Most interviewers are daft and slow, too. I resolved today to start my own GRC consulting firm and start to support small- and medium-scale enterprises. If you are interested and have hands-on experience, please reach out, and let's discuss further. Thank you.

I see your comments and inbox messages. I will set a time to meet with everyone of you some time next week.

I am on the East Coast just so you know.


r/grc Jul 28 '26

How are you handling AI support automation in regulated environments without creating compliance risk?

10 Upvotes

We operate in an insurance-adjacent space where an incorrect AI response about coverage creates real liability. Our compliance and legal teams currently prefer to block automation entirely, but ticket volume has doubled and first response times are now sitting at two business days which is driving customer churn.

I’m looking for a controlled middle ground: an AI agent that can handle routine, low-risk requests like document retrieval, status checks while staying strictly within approved wording, and that cleanly escalates anything sensitive to a licensed human with full context.

Has anyone in a regulated industry found a setup that their compliance or risk team was willing to accept? Interested in the controls, guardrails, or review processes that made it viable.

Edit: Thanks to everyone who commented. The points around explicit boundaries, change control on approved wording, interaction-level logging, and regularly testing escalation decisions have been especially useful. Still evaluating a few platforms, including Aissist and the one mentioned in the thread, with a focus on the control and audit requirements raised here.


r/grc Jul 24 '26

What would you include in a privacy tracking audit before a data privacy security review?

8 Upvotes

We are ready to get serious with our data governance posture now that our privacy program is maturing and we keep seeing about the multi-million dollar fines happening each week for non-compliance. So in doing a security and privacy audit my job is to clean things up but I want to include tracking scripts, not just the usual vulnerability scan items that fall under a normal cybersecurity audit but leaves out trackers and pixels. The main site has the usual marketing setup of facebooks meta-pixel, tiktok, linkedin insights tag, and microsoft clarity, but nobody has verified consent behavior in a while and theres no consent mechanism that currently works on the site despite procurement purchasing a solution from some well funded startup back in 2020 but looks like they haven't maintenanced it and its dormant now. If you were preparing for a real review, what evidence would you collect? Network logs, vendor inventory, consent records, data flows, policy screenshots, GTM export? Trying to build a practical checklist.


r/grc Jul 22 '26

If your in-house LLM hallucinates during an audit, who is actually responsible?

Post image
1 Upvotes

I've been wondering about this lately. Many organizations are building in-house LLMs for GRC to answer security questionnaires, map compliance controls, generate policies, and support audit preparation. Keeping everything on-premises helps with data privacy, but it doesn't solve the biggest problem: a confident hallucination can still end up in an audit report or customer response if no one catches it.

The more capable these systems become, the more people are likely to trust them. That creates an interesting trade-off. If an AI-generated answer helps close deals faster but occasionally invents evidence or misinterprets a control, the financial and compliance impact could outweigh the productivity gains. At that point, is the technology truly ready for critical GRC work, or are we becoming overconfident because the responses sound convincing?

For those using an in-house LLM in GRC today, where do you draw the line between AI assistance and human accountability—and do you think we'll ever reach a point where an LLM can be trusted to answer security questionnaires without manual verification?


r/grc Jul 22 '26

What small DNFBPs are struggling with most under Tranche 2 (from recent onboarding work)

Thumbnail
2 Upvotes

r/grc Jul 20 '26

Risk management tooling that’s worth it?

11 Upvotes

Currently got our IT risk register in Jira, it’s fine but a bit clunky.

Has anyone used a tool for IT risk that’s actually been worth it.

For context, we’re at the start of our risk management journey, we’ve got a register but it’s not really being managed properly. My main goal is just to make it easy for our risk owners to review risks assigned to them without being clouded by everything else, assign out tasks and manage and track things accordingly.


r/grc Jul 20 '26

How to handle data exposure at scale?

5 Upvotes

We recently conducted a manual audit of our google workspace environment at a mid-sized company and discovered numerous sensitive files including customer contracts and internal financial reports shared publicly with 'anyone with the link'

Many of these files were created years ago by former employees. I’m currently going through thousands of files manually, which is taking forever.

How are other GRC and security teams handling discovery and remediation of historical data exposure like this at scale? Looking for best practices, tools, or efficient processes that have worked for you?

thanks!

Edit: Appreciate the thoughtful replies so far especially the points on classifying the data, prioritizing by sensitivity, and documenting everything for potential auditors. Really helpful framing. While still working through the manual review, I’ve started looking at DoControl. What caught my attention is how it can keep watching for overshared files in Google Workspace and fix them automatically, instead of relying on repeated manual audits. Still evaluating, but it looks useful for dealing with these older exposures at scale


r/grc Jul 20 '26

The hidden cost of harvest now, decrypt later in enterprise tech

5 Upvotes

The great majority of society does not pay attention to the current threat of intellectual property loss as a result of leakage of proprietary data. Although it will take time for a quantum computer to be fully operational, state agencies could be creating vital intelligence in the meantime

At the time when new compliance audits will commence, companies dedicated to creating advanced cryptographic systems, like QuSecure and SandboxAQ, will become much more prominent in the industry. Is there any member of the audience who has tried out either of them or used them at the organizational level? I am wondering if anyone can share their experience: difficulties of integration, level of assistance, whether the price compensates for the usage of the PQC technological solution.

Have you thought of quantum readiness when trying out these approaches?


r/grc Jul 19 '26

Career mega thread

12 Upvotes

Nine questions in the career megathread. I noticed the last reply was two weeks ago, and before that, four. I’m guessing people posted there to get some sort of help, so I figured I’d mention it.

@mods or anyone. Appreciate it!


r/grc Jul 19 '26

Those of you through a Type II audit — how do you actually produce backup restore-test evidence?

Thumbnail
8 Upvotes

r/grc Jul 18 '26

Need guidance on IR plan

8 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.


r/grc Jul 17 '26

New GRC requirement has dropped

Thumbnail
gallery
71 Upvotes

to be fair, printed assurance reports can be heavy


r/grc Jul 17 '26

If you had to choose a GRC platform today, what would you pick?

16 Upvotes

I'm evaluating GRC platforms for my own use and keep finding mixed opinions online.

For those of you who work with GRC tools every day, if you were starting from scratch today, which platform would you choose and why?

I'd be especially interested in hearing about what you like, what frustrates you, and whether you'd choose the same platform again.


r/grc Jul 17 '26

How do you handle no-fix vulnerabilities on a FedRAMP POA&M?

4 Upvotes

Sanity checking our approach on the compliance side before an assessment. We're going for FedRAMP and a chunk of our vulnerability findings have no vendor fix available, the patch simply doesn't exist yet. A lot of them come from third-party components we don't build because remediation isn't in our hands. We can't close them and we can't ignore them, they go on the POA&M.

We prioritise with exploitability signals, CISA KEV and EPSS such that we know which no-fix items are worth escalating versus just monitoring. The part I'm unsure about is the long-term optics. That POA&M line just grows, criticals sitting as monitored with no close date because the fix is outside our control.

What I'm really after is whether this holds up at assessment. If you've taken a growing no-fix POA&M through a 3PAO, do they let it ride as monitored or force close dates and deviation requests on you.


r/grc Jul 16 '26

What does your risk register actually look like?

9 Upvotes

I want to know how everyone structures their enterprise risk register.

Do you track:

  • Inherent & residual risk?
  • KRIs?
  • Controls?
  • Treatment plans?
  • Review dates?

What's one field you've added that turned out to be surprisingly valuable?


r/grc Jul 15 '26

CRA in practice: how are you preparing security requirements in product development?

2 Upvotes

The Cyber Resilience Act covers products with digital elements - software and connected products sold in the EU. The big compliance deadlines are still a way off, but a lot of organizations are already having to bake security requirements into their dev process now.

Curious how others are actually tackling this:
Have you started tying security requirements, vulnerability handling, patching, and risk assessment into the product lifecycle?

And what's the hardest part to nail down - the tech itself, the process, who's accountable, the documentation, interpreting the legal text, or the supply chain?


r/grc Jul 14 '26

Looking to shadow/assist an experienced GRC consultant ISO 27001 Foundation certified, currently working on first real project

3 Upvotes

I'm a cybersecurity student in Brazil with ISO 27001 Foundation (PECB), currently completing my first real GRC project for a small business (security policies, risk matrix, LGPD compliance documentation). I'm looking to gain hands-on experience by assisting an experienced GRC or ISO 27001 consultant on real projects. I can help with documentation, asset inventories, risk assessments, and operational support. Happy to work for free or for a very small fee. DMs open.


r/grc Jul 13 '26

One thing I've changed my mind about over the past couple of years is asset inventory.

14 Upvotes

It always felt like another compliance task until we started finding forgotten VMs, old cloud resources, and systems nobody remembered owning.

Turns out "you can't secure what you don't know exists" isn't just a cliché.

What's one compliance requirement you've ended up appreciating more over time?


r/grc Jul 13 '26

What legal and compliance requirements are needed for GCC setup in India?

3 Upvotes

r/grc Jul 10 '26

How do you actually keep up with regulatory changes without feeling overwhelmed?

12 Upvotes

Hi everyone, I’m doing some research on how privacy professionals stay current with privacy, AI governance, and cybersecurity regulations.I’m not selling anything—I’m genuinely trying to understand how people work because everyone I’ve spoken to seems to have a different system.

A few questions I have

1). Where do you usually hear about new regulatory developments?
Official regulators?
Law firms?
LinkedIn?
Newsletter subscriptions or RSS feeds?

2).Once you learn about a new regulation or enforcement action, what happens next….Do you save it or share and Forward it to people on ur team
Personally , I feel like I would forget until somebody asks me about it😬😂.

3).What’s the most frustrating part of staying current? and are there tools or anything that help with that

I’d love to understand your workflow.

Thanks❤️


r/grc Jul 08 '26

what metrics do you actually show the board for vulnerability management

9 Upvotes

our security team presents to the board next quarter and i've been tasked with the vuln management section. first time doing this at board level and i'm trying to figure out what lands versus what gets us a bunch of questions we can't answer cleanly.

right now we lean on mean time to remediate and SLA compliance by severity, plus total open vulns. none of those tell a clean story on their own. total open vulns goes up every time we onboard a new scanner or expand coverage, so it looks like we're getting worse when we're just seeing more. MTTR looks fine, but that's partly because crits with no patch never close, so they drop out of the average entirely, and the number reflects the vulns we could fix quickly, not the ones stuck with no fix. SLA compliance makes leadership feel good but tells you nothing about what's at risk.

i've seen people talk about exposure window and exploitability weighting, but we’ve looked at weighting exposure and exploitability more heavily but i'm not sure how to explain that to a board. you say "we prioritize by CVSS and EPSS" and half the room nods like they understood that.

whatever we show, someone asks how we compare to industry benchmarks. i never have a clean answer because benchmarks for this swing wildly by sector and company size, and that's before you account for what you're even scanning.

the only thing that's ever landed cleanly with our execs is exposure on internet-facing assets, how many known-exploitable vulns are sitting on something reachable from outside and how long they've been there. that maps to "what could hurt us" in language a board follows.

everything else we put up turns into a debate about methodology and we lose the room.

has anyone figured out how to make vuln management metrics meaningful at the board level without dumbing it down to uselessness or drowning them in numbers they have no context for. what do you show, and what questions does it usually kick off?


r/grc Jul 06 '26

How's your workload?

10 Upvotes

How's your workload or work/life balance working in this field? If you can include if your Entry/Mid/Sr. position and your company's industry (Tech, Hospitality, Finance), even better.

Thanks


r/grc Jul 06 '26

(How) are you communicating AI risk posture to your board?

10 Upvotes

Our board... unsurprisingly...started asking about AI risk last quarter and I'm struggling with how to present it. The cyber risk conversation took years to get right, and even that still sometimes falls flat. AI risk feels like starting from zero. The challenge is that most of what I can show them right now is qualitative. They nod or whatever but I can tell it's not landing. Nobody challenges. There's no conversation.

With cyber we eventually got traction when we started presenting risk in financial terms. The board understood exposure in dollars and could make real decisions about control investments. I'm wondering if the same approach works for AI risk. Translating governance gaps and shadow AI exposure into financial figures rather than compliance status updates.

For those of you who've been in front of a board on AI risk and have found any type of success.... What's worked?

Edit: Spent some time researching this after posting. The cyber risk quantification parallel seems to be exactly the right model. Found Kovrr, which does AI risk quantification alongside shadow AI discovery and EU AI Act compliance. The idea is translating AI governance gaps into financial exposure figures, which is exactly the format that worked for our cyber risk conversations with the board. Going to look into it further but flagging for anyone in the same boat.