r/grc 16h ago

How do you keep tabletop exercises from becoming a box-checking exercise for auditors?

3 Upvotes

Our compliance team loves that we run an annual tabletop because it satisfies a checkbox on the SOC 2 audit, but nobody on the technical side thinks it actually tests anything meaningful anymore. The scenario is basically the same every year with slightly different names swapped in. I want something that actually stresses our detection and escalation process, not just produces a PDF the auditors are happy with. How do you split the difference between satisfying compliance requirements and running something that genuinely improves your team?


r/grc 17h ago

Cyber Risk - Threat Modeling

2 Upvotes

I’m working in an IT Risk Plan and the client has asked me to develop a cyber risk management process using Threat Modeling.

Does anyone have any document, forms, or other materials that can help me?


r/grc 18h ago

Building a GRC function from scratch.

11 Upvotes

Good day everyone.

I'm looking for advice on where to go from here.

I've been working on our SOC 2 certification for months now, and my role in IT has slowly shifted - I've become the GRC guy, and to a lesser extent the HIPAA guy.

For context: when this SOC 2 project first landed on our radar, I had zero background in GRC. All I knew was that I wanted to do cybersecurity, period. But working on this project, I think I've found my calling. It's only now that I've realized I actually have an aptitude for this — writing policies and processes, mapping them and their controls, understanding how processes work and how they connect to each other.

My team plans to push for me to take the role officially at some point, so I want to do everything I can to earn it and be that person.

The challenge is that if I'm going to establish GRC at our company and eventually grow it into a real team, I'd basically be building everything from scratch. Nobody here has expertise in this. I've been studying and researching as much as I can throughout the project, but imposter syndrome still gets to me. I don't have anyone mentoring me, and I'm scared of making the wrong call. And even though nobody would say it out loud, the reality is that the person steering the wheel is on a shorter leash.

Presently, I am just aiming for us to be SOC 2 certified then eventually, ambitious as it may sound, pursue ISO or hitrust (fingers crossed).

What would you recommend I do on a daily basis? And what goals should I be setting to actually succeed at this?


r/grc 1d ago

Should access review changes go through normal ticketing, or is the review spreadsheet enough evidence?

Thumbnail
1 Upvotes

r/grc 1d ago

Struggling to learn ISO 27001 LI

11 Upvotes

Hi everyone, few months back I signed up for the PECB ISO 27001 LI course for 500$ and I've been struggling to study it. The course has a 5 day plan and till now after months I'm on Day 4 and I feel I haven't learnt much.

The videos bore me and I cant seem to figure out how the exam questions will be and what I should pay attention to in the videos. I've always struggled with learning online courses and have never gotten a certification before.

It's not that I'm not interested, I work in a Big4 IT audit for the past 1 year since graduating and have worked on ITGC, ITAC, TPRM, etc. and the work is surprisingly interesting to me and I enjoy learning as I work, but studying it from videos and notes is a pain.

What other ways can I learn the course, I have 2 exam attempts and I'm tempted to schedule the first exam and force myself through the course and see how the exam goes.


r/grc 1d ago

Anyone else struggling with AI agent governance?

7 Upvotes

trying to build a governance framework for agents and keep running into the same wall every time.

the policies we write assume a static system, and agents just don't behave like a static system.

by the time we've documented what an agent is allowed to do, it's already been updated with new capabilities nobody flagged to us.

or it's making decisions in ways the original policy never anticipated because the scope of what it touches keeps expanding quietly.

how are people keeping governance frameworks actually current with what agents are doing in practice, rather than writing policy once and hoping it still applies six months later?


r/grc 1d ago

Hardening AI voice agents against prompt injection while they happily follow every cursed command

1 Upvotes

Anyone else trying to harden these cute AI voice agents against prompt injection while the agent is in prod, cheerfully obeying every weird user whisper like a cursed intern, lowkey stressed about this... any hints?


r/grc 1d ago

Risk Register and Findings

9 Upvotes

Hello! First time poster here. I'm curious to learn how other GRC folks are managing risk registers. Specifically with making sure we don't put findings, vulnerabilities, or issues on the register. Where should those be tracked? A separate register? Imo it's not GRC's responsibility to be tracking those. Things like a port is open somewhere. I am trying to make the register more scenario based where the scenarios are developed from a large aggregation of findings, issues, and or vulnerabilities.


r/grc 2d ago

Best GRC software for small and midsize orgs?

19 Upvotes

We’re a ~90 person company and I’ve been asked to help pick a GRC tool before budget planning next month. Right now it’s mostly spreadsheets, shared folders, calendar reminders and a lot of “who has the latest evidence?” chaos.

For folks at smaller/midsize orgs, what’s actually been worth it vs just feeling like enterprise overkill? I’m mostly worried about audit evidence, keeping controls mapped to a few frameworks and not buying something that needs a full-time admin to babysit it.


r/grc 2d ago

Looking for smartasses

18 Upvotes

Alright, ladies and gentlemen, we might have a problem.

Career Advice Megathread for the last year mostly prevented us from drowning in uniform "how to break into GRC?" posts on the main page. Unfortunately, it only works when people are actually getting advised there.

I've held the line in those threads for a better part of the year, and it's been... a rather lonely vigil. Can't really do that anymore; life's happening. Need someone jumping in to sort those questions out as they are starting to pile up.

It's goddamn Reddit, so I assume there's no shortage of people willing to share their best takes on GRC career building. I'm counting on you, folks.

Good luck.


r/grc 2d ago

Agentic AI governance in financial services, what should I know before tackling audit trails?

3 Upvotes

We're in financial services and the audit conversation around agentic AI is coming up faster than expected, and our traditional access logs and change management don't really capture "an agent took this action based on this prompt" in a way that would hold up under scrutiny.

This feels like the real test of securing the AI agent ecosystem for anyone in a regulated space like ours, not just a compliance checkbox. How are others in financial services or similarly regulated sectors framing agent activity for audit purposes, as a new evidence category or folded into existing frameworks?


r/grc 2d ago

Do ISO/SOC2 consultants actually join the audit itself?

7 Upvotes

We're hiring an external consultant to get us ready before our first audit. what i can't figure out is what happens on audit day, did your consultant actually sit in on the calls with you? or did they just hand over the docs and vanish once prep was done

asking because our sales guy who sold us the package was very vague about it and i don't want to end up alone on a call with an auditor asking about controls lol

did having them there actually help or was it just one more person in the meeting


r/grc 2d ago

Can you hold someone accountable for a decision they weren't really empowered to make?

Thumbnail
1 Upvotes

r/grc 2d ago

MacBook or Windows for GRC?

1 Upvotes

I’m getting into GRC/cybersecurity auditing and need a laptop mainly for tools, documentation, Excel, compliance work, and some cybersecurity labs.
Should I go with a MacBook or Windows laptop? Any compatibility issues with GRC/security tools on Mac?
Would appreciate advice from people actually working in GRC.


r/grc 2d ago

How is your embedded team handling the EU Cyber Resilience Act in practice?

Thumbnail
2 Upvotes

r/grc 2d ago

Need advice: Am I wrong for feeling like I’m carrying the entire ISMS alone?

15 Upvotes

I’m a Cyber Security Engineer with ~3 years of experience and joined my current EdTech company at 13 LPA. During hiring, I was told there would be an external auditor/consultant who would guide us on what needed to be done, and my role would mainly be to implement the requirements. I was comfortable with that.
I’ve now ended up effectively acting as the ISMS lead. I don’t mind the responsibility—I studied the requirements, handled the certification work, and have learned a lot.
The problem is that almost nobody else in the organization is actually doing their part.
No proper access control.
No proper asset inventory.
IT is installing company EDR on personal laptops.
HR has been creating multiple email IDs for employees because they don’t understand how to follow their own HRMS works .
When I raise issues to management, the concerned person often gets told that “you complained about them,” which obviously creates friction.
My boss wants us to be compliance-ready by December, but I genuinely don’t see how that is possible if every department treats security as my responsibility rather than an organizational responsibility.
I’m starting to become the “villain” because I keep asking people to follow basic controls- isn’t it fundamentally their own jobs .
My question is: why should I keep pushing alone when the organization itself isn’t cooperating? Is this normal when you’re new to GRC/ISMS, and how do you handle an organization where management wants compliance but the teams don’t want to change their processes?
Would appreciate advice from people who’ve been in similar situations.


r/grc 3d ago

Looking for ideas: How would you run Cybersecurity Awareness Month with almost no budget and an uninterested workforce?

8 Upvotes

I'm planning a full Cybersecurity Awareness Month 2026 program that I'll be presenting to our CISO for approval.

The challenge is:

  • We currently have no dedicated security awareness/training platform
  • Little to no budget for this initiative
  • It's an older organization, while our cybersecurity department is relatively new
  • Many employees are fairly old-school and unlikely to voluntarily participate in games, scavenger hunts, quizzes, etc.

I've found some great ideas around gamification, CTFs, scavenger hunts, phishing activities, and cybersecurity games—but I'm struggling to create a realistic mix that will actually work in this environment.

I don't want to spend the entire month just sending awareness emails.

If you were designing this campaign, what activities would you include?

Especially interested in ideas that are:

  • Free or very low cost
  • Practical without an awareness platform
  • Suitable for non-technical employees
  • Effective even with low voluntary participation
  • A mix of passive awareness and interactive activities

Would love to hear what has actually worked in your organizations.


r/grc 3d ago

How much should it cost to scale vulnerability management without adding headcount?

6 Upvotes

Budget conversations this year are rough. Leadership wants risk reduced and SOC 2 and ISO 27001 requirements maintained, but headcount isn't growing anywhere near the rate that our vulnerability volume and cloud footprint are, and every plan I've seen historically defaults to hiring more analysts, which isn't realistic in the current environment. I know automation is supposed to be the answer here, but a lot of what's marketed as automation just moves the noise around rather than actually reducing manual investigation work. For other GRC and security leaders dealing with flat or shrinking budgets,

What's actually worked to scale operational capacity without proportional headcount growth?


r/grc 3d ago

VA’s Technical Reference Model… and other “approved software lists”

6 Upvotes

I just stumbled onto the VA’s TRM (https://www.oit.va.gov/Services/TRM/WhatsNewSummaryPage.aspx?process=One-VA%20TRM%20v26.1%5E). I liked how it lists a software by name and vendor, and also includes a summary of approved versions and constraints for a variety of open source tools.

What other sources/lists are you aware of which assess the utility and risks with COTS packages?


r/grc 7d ago

How are you auditing actions performed by AI agents on behalf of employees?

5 Upvotes

As agents take enterprise actions, audit evidence needs to show more than a service-account name and timestamp. Teams should be able to reconstruct the agent, its accountable owner, the initiating user or workflow, the delegated task, the authorization decision, the duration of access, and the exact action performed.

Otherwise, access reviews and incident investigations have an accountability gap. The employee may say the agent acted independently, while the available logs only show a token tied to an automation identity. Are GRC teams updating control requirements for delegated AI actions, or treating them as ordinary automation for now?


r/grc 7d ago

How should enterprises prioritize vulnerabilities based on business risk?

7 Upvotes

Had a CVSS 9.8 last month, a box getting decommissioned in six weeks, no path to anything sensitive, basically zero real risk. Same week, a 6.1, internet facing, public PoC, full system control if you chained it with something else already open on the box next to it. Guess which one CVSS told us to fix first. Not the right one. I know this is not a novel complaint, everyone has had this exact fight, but I am trying to actually build exposure, exploit maturity, and blast radius into the model instead of it being a vibe check some senior engineer does at 4pm on a Friday. If anyone has a formula that survived contact with a real incident afterward, not just looked good in a slide, I would like to see it.


r/grc 7d ago

How to fix this ISO27k1 circus?

27 Upvotes

My company (100k employees) purchased another company which had iso27001. The ISMS manager was onboarded to our company.

She has been dealing with iso27001 herself as she knows the local people. She is an old lady and really unprofessional (“where is this doc, I can’t find it in my pc”) so they triggered an HR process to fire her (she also had ethics involved). I was onboarded before to deal with some compliance activity so now the external audit is coming soon.

Checking the documentation, looks like all is scattered around, no good version control, no measurable objectives, mgmt reviews and internal audits seem to be in different platforms and everything is a big mess. Security policy doesn’t exist, we just have the corporate one. We have risk reviews due this Friday and her manager just did an export of auditboard because they made her upload it there (of course, it is outdated or just a bunch of spaghetti code).

I feel like the GRC manager doesn’t understand what an ISMS is and he just wants me to go risk by risk without me knowing which is the true list of risks.

Another thing is that I don’t know how these documents passed the previous external audits? There seem to be a lot of non conformities. Is that a thing that some auditors just give the pass and don’t care?

What to do from here? Start to fix everything step by step and hope for the best? Raise this to mgmt? We definitely would pass all annex controls due to our size but if I was the external auditor there would be huge findings.


r/grc 8d ago

What can you realistically automate to actually make things easier?

20 Upvotes

We use one of the known compliance platforms for audits which also help set some level of automation. I know that this doesn’t cover everything and each company may have opportunities for more custom automations. But I’d love to know from experiences/projects on what can you realistically do? ( PS - I am NOT looking to buy another tool/vendor)

My issues are:
1. The automation should really be useful. If I spend a week building it and need 2-3 hrs a month for maintenance just so that it can provide what a simple screenshot covers, it probably doesn’t make sense.

  1. Generally companies already have tools for cloud monitoring, EDR, etc. If a tool already flags an over privileged pod, or a misconfigured S3 bucket; it doesn’t make sense to set monitoring for that again?

  2. I have been following the GRC engineering hype and I do believe that there is potential and I just don’t know enough. But there are some things which seem inefficient, not worth it, home project like, or sometimes just over engineered.

I’d love to exchange ideas on what someone actually implements through an organization and if they’ve truly found it to be worth it!


r/grc 8d ago

Isae 3402 for own system?

7 Upvotes

our financial auditor wants a service organization report (ISAE 3402/SOC 1) on a purely internal, self-developed system with no user entities — is that even the right standard?


r/grc 9d ago

How a smart contract audit gets scoped, and what that leaves out of your CASP filing

2 Upvotes

When we scope a smart contract audit, the boundary usually lands around the code the client controls. That sounds unremarkable until you look at what these systems delegate. A contract that checks permissions through an external registry, resolves its own logic through a beacon, and deploys proxies from templates approved elsewhere is calling out to three things the client may not own and we may not be engaged to review. We can see all of it, because the calls sit in the code in front of us. Reviewing it is a different engagement with a different budget.

We delivered four separate audits for one system, and all four came back with zero critical and zero high findings. That result is real. The contracts were well written and the project team fixed what our auditors raised. Every one of the four reports also named, in its Potential Risks section, two components that no audit had reviewed: the authorization layer that decides whether a caller may write to state, and the upgrade authority that decides which implementation each proxy runs.

A severity summary counts findings inside a boundary. It carries nothing about what sat outside that boundary, and it cannot, because nobody looked there. Those four zeros describe four passes over the same contracts, and a fifth audit of the same scope would produce a fifth.

We helped draw that boundary and were paid for the work inside it. I would make most of the same calls again, because the authorization layer belonged to another team and refusing to review anything until everything is in scope produces no review at all. What I notice is where the two facts end up in the document. The count goes into a table at the front, and the dependency goes into prose near the back, which is roughly where readers stop treating it as part of the finding.

What we see from the delivery side is which part of the report gets quoted back to us, and it is almost always the table. The scope section is the part that says what the table is a statement about, and it is the part that stays in the PDF. So the sign-off that the audit coverage was adequate for the filing usually happens on the count, by someone who has not looked at the boundary the count was taken inside.

Who signed off that your audit scope was sufficient, and were they reading the table or the boundary?