CISO Tradecraft®

#236 - Build a World Class GRC Program (with Matt Hillary)

Jun 9, 2025
Matt Hillary, Chief Information Security Officer at Drata, shares his expertise in governance, risk, and compliance. He discusses the evolution of GRC from spreadsheets to automated platforms, emphasizing compliance as code. Matt highlights leveraging AI for faster responses in compliance processes and the importance of effective risk management. He also touches on common pitfalls in GRC programs and the significance of mental health for cybersecurity leaders, underscoring the challenges and opportunities in today’s compliance landscape.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Common Controls Reduce Audit Blind Spots

  • Common control frameworks let organizations map one set of controls to many standards and reduce blind spots.
  • Underlying processes and data are the true shared elements across frameworks, not just wording of controls.
ADVICE

Shift To Continuous Compliance

  • Use GRC platforms to automate evidence collection and run control tests continuously instead of sampling manually.
  • Treat auditors as customers and provide a self-service audit hub to streamline assessments.
ADVICE

Embed Compliance In CI/CD Pipelines

  • Integrate compliance-as-code into CI/CD to detect compliance failures before deployment.
  • Surface noncompliant infrastructure in pull requests so developers fix issues once and get it right the first time.
Get the Snipd Podcast app to discover more snips from this episode
Get the app