Hotman Group Insights

Cybersecurity

Practical guidance on cybersecurity strategy, security programs, controls, technology, and the decisions organizations face as threats and business needs evolve.

GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
Stop Asking If AI Is Trustworthy. Start Asking If Your System Is Governable.
Cheri Hotman, Managing Partner of Hotman Group, and Diane R Jones, CISSP, CCSP, creator of the AI Admissibility Framework, explore why responsible AI governance requires a shift in perspective: instead of asking whether an AI model can be completely trusted, organizations should ask whether the system around it is designed to control what can happen […]
The Danger of the Perfect Audit
A perfect audit report can create a dangerous false sense of security. The Hotman Group team explains how to evaluate scope, evidence, control testing, automation, and risk before relying on a compliance report.
The Maturity Gap: Why GRC Programs Plateau (and How to Advance)
GRC programs often plateau when passing audits becomes the goal. Cheri Hotman and Tanya Wade explain how organizations can move from reactive compliance toward managed, risk-based, continuously improving Cyber GRC programs.
What Operationalized GRC Actually Looks Like: From Silos to Systems
Many organizations believe their GRC program is operational because audits are passing and tools are in place. In reality, operationalized GRC behaves very differently. Risk has clear ownership. Information flows across teams. Gaps surface early instead of being hidden. In this session, Cheri Hotman and Peter Spier walk through what an operationalized GRC program actually […]
The ROI of GRC: Turning Compliance Into Competitive Advantage
Too often, compliance is seen as an expense instead of an investment. But when done right, Governance, Risk, and Compliance can become a competitive advantage that drives trust, growth, and resilience. In this session, we’ll share how forward-thinking organizations are proving the ROI of GRC—quantifying risk reduction, accelerating sales, and strengthening customer confidence. Join us […]
Securing AI: Balancing Innovation, Risk, and Reality
AI adoption is exploding—but so are the risks. From data exposure and prompt injection to unregulated model training, most organizations are using AI without fully grasping where their data lives or how it’s being secured. In this session, we’ll unpack the real meaning of “securing AI,” exploring how risk, governance, and innovation must coexist. You’ll […]
Supply Chain Security: Managing Risk Beyond Your Vendors
When it comes to third-party supply chain security, there’s a big difference between doing it and doing it right. Every vendor you work with brings their own vendors into the mix—so who truly owns the risk? In this session, we’ll explore how to identify, assess, and mitigate supply chain risks at every level without overburdening […]
Where Compliance Meets Security: Doing Both the Right Way
Compliance and cybersecurity are often seen as separate priorities—but the truth is, good compliance reduces risk when done right. So how do you effectively integrate both for a stronger security posture? In this session, we’ll break down the intersection of compliance and cybersecurity, share best practices, and walk through real-world examples of organizations that have […]
  • 1
  • 2