Field Notes

GRC is the only security team whose job doesn't change when a new threat actor shows up.

GRC is the only security team whose job doesn't change when a new threat actor shows up.

GRC is the only security team whose job doesn't change when a new threat actor shows up.

Mythos just found thousands of zero days across every major OS and browser. Breakout times are down to minutes. Exploit chains that used to require nation-state talent can now be run for you while you're toasting an everything bagel.

AppSec is scrambling. IR is refining playbooks and practicing rapid responses. Detection engineering is trying to figure out how to detect what didn't exist yesterday.

And GRC is... scheduling the next quarterly control test.

It's not that GRC practitioners don't care about threats. It's that the function was and still is, built around the audit cycle.

Ayoub Fandi, in addition to having impeccable taste in shirts, is a leader in the movement that's rethinking GRC. He's the GRC engineering lead at GitLab, host of the GRC Engineer podcast and newsletter and one of the people behind the GRC engineering manifesto. His take is that this disconnect is the core thing modern GRC has to fix, because if the function stays decoupled from threats, it naturally drifts toward being a sales enablement function rather than a security one.

On this next episode of the TPRM Podcast talked about rebuilding GRC workflows for the future and why risk more than compliance, is what will survive in an AI-native world.

Full episode in comments.