Practical thinking on cybersecurity, GRC, risk, technology, compliance, and the business decisions behind them.
Defending Your Cybersecurity Budget Without Sacrificing Protection
A flat cybersecurity budget forces difficult decisions. But cutting every expense by the same percentage can weaken the controls your business depends on while leaving inefficient spending untouched. In a video published by Help Net Security on September 17, 2026, Cheri Hotman, Managing Partner of Hotman Group and a practicing vCISO and vGRC leader, discusses […]
GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
Stop Asking If AI Is Trustworthy. Start Asking If Your System Is Governable.
Cheri Hotman, Managing Partner of Hotman Group, and Diane R Jones, CISSP, CCSP, creator of the AI Admissibility Framework, explore why responsible AI governance requires a shift in perspective: instead of asking whether an AI model can be completely trusted, organizations should ask whether the system around it is designed to control what can happen […]
A perfect audit report can create a dangerous false sense of security. The Hotman Group team explains how to evaluate scope, evidence, control testing, automation, and risk before relying on a compliance report.
The Maturity Gap: Why GRC Programs Plateau (and How to Advance)
GRC programs often plateau when passing audits becomes the goal. Cheri Hotman and Tanya Wade explain how organizations can move from reactive compliance toward managed, risk-based, continuously improving Cyber GRC programs.
What Operationalized GRC Actually Looks Like: From Silos to Systems
Operationalized GRC is more than audits, tools, and green dashboards. Cheri Hotman and Peter Spier explain how governance, risk, ownership, automation, and business alignment create a GRC operating model that actually works.
The ROI of GRC: How Governance, Risk and Compliance Creates Business Value
GRC is more than a compliance expense. Cheri Hotman and Joe Kodali explain how governance, risk, and compliance can support revenue, customer trust, efficiency, risk reduction, resilience, and better business decisions.
Securing AI: How to Manage AI Risk Without Slowing Innovation
AI adoption is moving faster than many organizations can govern it. Cheri Hotman and Ranbir B. discuss how to manage AI security, data, third-party risk, employee use, monitoring, and human oversight without unnecessarily slowing innovation.
Real-Life GRC Horror Stories: What Checkbox Compliance Can Cost You
Real-life GRC failures often begin with shortcuts: overreliance on tools, weak ownership, under-resourcing, poor third-party oversight, cheap audits, and treating compliance as the finish line. Cheri Hotman and Tanya Wade explain what organizations can learn from these GRC horror stories.