Jun 18, 2026 · 37 min · 8 segments
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, answer some of the niche and unusual questions around governance, risk and compliance (GRC). Jack and George…
Jack WoodsGuestGeorge RyanGuestAnnieHostSo, first question for you guys is, what is one thing your clients rarely ask but should?
Yeah, so I think one thing we often see with kind of the GRC is we'll really heavily focus on the C, which is obviously the compliance, but actually the governance and the risk can be kind of skipped over.
So, What we see is some certifications such as with ISO 27001 or cyber essentials, you can tell a big difference between who's doing it just to get compliant to it and actually who's looking at this kind of maintenance of it and continue improvement.
If we take cyber essentials, for example, where that's a snapshot at that time, some people may fall into that kind of area where actually the other 364 days of the year, once they're compliant, They kind of forget about it and then comes up with this for renewal and suddenly compliance is back on.
So from my perspective, it's clients not really focusing on the actual enablement of GRC and just focus on that kind of box ticking as such.

And I think something to focus on of that kind of GRC triad, if you will, is that compliance is largely just the baseline.

You're meeting the requirements, but that doesn't mean that you're reducing risk to your organisation.

If you're meeting requirements of a standard, that doesn't necessarily mean you're reducing risk.

If you're not taking other actions implementing controls around that, making sure that you're having the governance forums to discuss those controls and make sure that you're hitting the kpis that you might need to be hitting for those controls so if vulnerabilities are being scanned who's who's reviewing those are they being triaged correctly that kind of aspect of it and that's the yeah the risk and governance part that we need to focus on you don't want it to be like george has just mentioned that kind of tick box exercise and i think an area that a lot of organizations tend to kind of fall down is kind of what George was alluding to earlier about the fact that passing an audit kind of gives them a false sense of assurance.

It means that, oh, yeah, well, we passed that audit, so we don't have to bother with this for another year.

But that doesn't mean that in 12 months time there won't be any non-conformities because we didn't potentially look at something.

So it may be that passing audits can sometimes mask unresolved issues as well or it can be hiding those issues because you feel that like i said that false sense of assurance that oh yeah well we've got the certificate now so there clearly weren't any issues where actually there might be we just didn't didn't cover them during that audit
if we're not going for certification then we're not going to bother governing it at all

yeah and obviously there's a there's a danger involved in that um that is quite an obvious one to point out it's the potential misuse of those ai tools is going to potentially cause serious issues and not even necessarily misuse but we've seen it um in the news recently there's been an organization that their entire database was deleted by the AI kind of tool that they were using within a few minutes of using that tool.

So there are things that are happening and so you need to make sure that you've got controls in place.

But the other point to make around that is that often there's a focus on do we have controls rather than would they actually stop an incident? I've been into lots of organisations where they've got policies and procedures for the sake of policies and procedures, and they're not really worth the weight of the paper they're written on because they're not actually protecting anything.
So, first question for you guys is, what is one thing your clients rarely ask but should?
Yeah, so I think one thing we often see with kind of the GRC is we'll really heavily focus on the C, which is obviously the compliance, but actually the governance and the risk can be kind of skipped over.
So, What we see is some certifications such as with ISO 27001 or cyber essentials, you can tell a big difference between who's doing it just to get compliant to it and actually who's looking at this kind of maintenance of it and continue improvement.
If we take cyber essentials, for example, where that's a snapshot at that time, some people may fall into that kind of area where actually the other 364 days of the year, once they're compliant, They kind of forget about it and then comes up with this for renewal and suddenly compliance is back on.
So from my perspective, it's clients not really focusing on the actual enablement of GRC and just focus on that kind of box ticking as such.

And I think something to focus on of that kind of GRC triad, if you will, is that compliance is largely just the baseline.

You're meeting the requirements, but that doesn't mean that you're reducing risk to your organisation.

If you're meeting requirements of a standard, that doesn't necessarily mean you're reducing risk.

If you're not taking other actions implementing controls around that, making sure that you're having the governance forums to discuss those controls and make sure that you're hitting the kpis that you might need to be hitting for those controls so if vulnerabilities are being scanned who's who's reviewing those are they being triaged correctly that kind of aspect of it and that's the yeah the risk and governance part that we need to focus on you don't want it to be like george has just mentioned that kind of tick box exercise and i think an area that a lot of organizations tend to kind of fall down is kind of what George was alluding to earlier about the fact that passing an audit kind of gives them a false sense of assurance.

It means that, oh, yeah, well, we passed that audit, so we don't have to bother with this for another year.

But that doesn't mean that in 12 months time there won't be any non-conformities because we didn't potentially look at something.

So it may be that passing audits can sometimes mask unresolved issues as well or it can be hiding those issues because you feel that like i said that false sense of assurance that oh yeah well we've got the certificate now so there clearly weren't any issues where actually there might be we just didn't didn't cover them during that audit
if we're not going for certification then we're not going to bother governing it at all

yeah and obviously there's a there's a danger involved in that um that is quite an obvious one to point out it's the potential misuse of those ai tools is going to potentially cause serious issues and not even necessarily misuse but we've seen it um in the news recently there's been an organization that their entire database was deleted by the AI kind of tool that they were using within a few minutes of using that tool.

So there are things that are happening and so you need to make sure that you've got controls in place.

But the other point to make around that is that often there's a focus on do we have controls rather than would they actually stop an incident? I've been into lots of organisations where they've got policies and procedures for the sake of policies and procedures, and they're not really worth the weight of the paper they're written on because they're not actually protecting anything.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.