Couverture de GRC Academy

GRC Academy

GRC Academy

De : Jacob Hill
Écouter gratuitement

À propos de cette écoute

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!Copyright GRC Academy
Les membres Amazon Prime bénéficient automatiquement de 2 livres audio offerts chez Audible.

Vous êtes membre Amazon Prime ?

Bénéficiez automatiquement de 2 livres audio offerts.
Bonne écoute !
    Épisodes
    • The Business Case for CMMC - Surviving DOGE
      Jun 19 2025

      CMMC certification could be the key to surviving DOGE cuts! 👀

      In this episode, I’m joined by Derek Kernus of Aethon Security to discuss the business case for CMMC!

      This episode was really refreshing to me. Yes, our discussions about deep CMMC topics are important, but learning how to convince your company leadership to make the CMMC investment is even more critical.

      Here are some takeaways:

      • How CMMC early adopters can shape contracts and limit competition
      • How to frame the CMMC investment to internal leadership
      • The impending CMMC bottleneck of doom 👻
      • What mock assessments are and how they can help you prepare
      • Why choosing the wrong MSP could actually kill your chances at certification

      After being impacted by DOGE myself, I've put a lot of thought into how small businesses will be impacted by DOGE + CMMC.

      Most of my concern is for SMBs that haven't started preparing for CMMC. That costs a lot of money, and if SMBs lose revenue due to DOGE cuts before they prepare for CMMC, I'm not sure they'll be able to survive in the defense contracting space.

      But there is great opportunity for CMMC early adopters to be part a small cadre of CMMC certified companies and operate in a much smaller competitive space.

      It turns out CMMC actually could be your business's savior. Who knew!?!

      I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

      Follow Derek on LinkedIn: https://www.linkedin.com/in/derekkernus/

      Aethon Security Website: https://www.aethonsecurity.com/

      -----------

      Thanks to our sponsor Vanta!

      Get back time to focus on strengthening security and scaling your business.

      Discover the new way to GRC here: https://vanta.com/grcacademy

      -----------

      Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

      Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-10&utm_campaign=courses

      #cmmc

      Afficher plus Afficher moins
      53 min
    • The Compliance Playbook to Cybersecurity
      Jun 5 2025

      "Compliance is the security referee - frameworks are the playbooks."

      In this episode, I’m joined by Tim Golden, Founder of Compliance Scorecard, to unpack the misunderstood, and mission-critical world of cyber GRC.

      Tim shares what he’s learned from decades of hands-on work - from implementing NIST frameworks before “GRC” was even a term, to helping teams understand why writing policies is just as important as patching vulnerabilities.

      Here are some highlights from the episode:

      • What GRC actually means - and why governance is the most misunderstood part
      • Why people who say "compliance isn't security" are missing the point
      • How explaining the "why" of cybersecurity controls aids in acceptance
      • Why data retention policies can protect you from major legal headaches
      • And yes… a story about how Tim accidentally ransomwared himself 🙃

      This is a must-listen for anyone navigating compliance, cybersecurity, or just trying to understand how it all fits together!

      I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

      Follow Tim on LinkedIn: https://www.linkedin.com/in/timothygolden/

      Compliance Scorecard Website: https://compliancescorecard.com/

      -----------

      Thanks to our sponsor Vanta!

      Get back time to focus on strengthening security and scaling your business.

      Discover the new way to GRC here: https://vanta.com/grcacademy

      -----------

      Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

      Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e9&utm_campaign=courses

      #cybersecurity

      Afficher plus Afficher moins
      32 min
    • How HITRUST Fixes What’s Broken in Cybersecurity Compliance
      May 27 2025

      Cybersecurity frameworks can learn a lot from HITRUST.

      In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.

      I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.

      Here’s what stood out to me:

      • HITRUST reviews its security controls quarterly based on threat intel and control effectiveness
      • There are three distinct assessment levels (like CMMC)
      • HITRUST itself issues a certification after the 3rd party assessment and running the assessment results through two stages of QA
      • Every 3rd assessment gets reviewed. Every. Single. One.

      The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.

      HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.

      I personally think that commercial cybersecurity frameworks should take a look at HITRUST.

      What were your biggest takeaways? Let me know in the comments.

      Follow Ryan on LinkedIn: https://www.linkedin.com/in/ryan-patrick-3699117a/

      HITRUST Website: https://hitrustalliance.net/

      -----------

      Thanks to our sponsor Vanta!

      Get back time to focus on strengthening security and scaling your business.

      Discover the new way to GRC here: https://vanta.com/grcacademy

      -----------

      Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

      Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e8&utm_campaign=courses

      #hitrust

      Afficher plus Afficher moins
      56 min
    Aucun commentaire pour le moment