Hotman Group

Insights & Perspectives

Practical thinking on cybersecurity, GRC, risk, technology, compliance, and the business decisions behind them.

Defending Your Cybersecurity Budget Without Sacrificing Protection
A flat cybersecurity budget forces difficult decisions. But cutting every expense by the same percentage can weaken the controls your business depends on while leaving inefficient spending untouched. In a video published by Help Net Security on September 17, 2026, Cheri Hotman, Managing Partner of Hotman Group and a practicing vCISO and vGRC leader, discusses […]
GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
Stop Asking If AI Is Trustworthy. Start Asking If Your System Is Governable.
Cheri Hotman, Managing Partner of Hotman Group, and Diane R Jones, CISSP, CCSP, creator of the AI Admissibility Framework, explore why responsible AI governance requires a shift in perspective: instead of asking whether an AI model can be completely trusted, organizations should ask whether the system around it is designed to control what can happen […]
The Danger of the Perfect Audit
A perfect audit report can create a dangerous false sense of security. The Hotman Group team explains how to evaluate scope, evidence, control testing, automation, and risk before relying on a compliance report.
The Maturity Gap: Why GRC Programs Plateau (and How to Advance)
GRC programs often plateau when passing audits becomes the goal. Cheri Hotman and Tanya Wade explain how organizations can move from reactive compliance toward managed, risk-based, continuously improving Cyber GRC programs.
What Operationalized GRC Actually Looks Like: From Silos to Systems
Many organizations believe their GRC program is operational because audits are passing and tools are in place. In reality, operationalized GRC behaves very differently. Risk has clear ownership. Information flows across teams. Gaps surface early instead of being hidden. In this session, Cheri Hotman and Peter Spier walk through what an operationalized GRC program actually […]
The ROI of GRC: Turning Compliance Into Competitive Advantage
Too often, compliance is seen as an expense instead of an investment. But when done right, Governance, Risk, and Compliance can become a competitive advantage that drives trust, growth, and resilience. In this session, we’ll share how forward-thinking organizations are proving the ROI of GRC—quantifying risk reduction, accelerating sales, and strengthening customer confidence. Join us […]
Securing AI: Balancing Innovation, Risk, and Reality
AI adoption is exploding—but so are the risks. From data exposure and prompt injection to unregulated model training, most organizations are using AI without fully grasping where their data lives or how it’s being secured. In this session, we’ll unpack the real meaning of “securing AI,” exploring how risk, governance, and innovation must coexist. You’ll […]
Real Life GRC Horror Stories: Top Mistakes Haunting Your Program
Just in time for Halloween, we’re pulling back the curtain on the Top 10 GRC Nightmares plaguing organizations today. From programs that only exist to “pass the audit,” to treating compliance as a checkbox exercise, these haunting mistakes can leave your organization more vulnerable than you realize. In this session, we’ll identify the most common […]