Practical guidance on building, operating, and maturing governance, risk, and compliance programs that reduce complexity and support the business.
GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
Stop Asking If AI Is Trustworthy. Start Asking If Your System Is Governable.
Cheri Hotman, Managing Partner of Hotman Group, and Diane R Jones, CISSP, CCSP, creator of the AI Admissibility Framework, explore why responsible AI governance requires a shift in perspective: instead of asking whether an AI model can be completely trusted, organizations should ask whether the system around it is designed to control what can happen […]
A perfect audit report can create a dangerous false sense of security. The Hotman Group team explains how to evaluate scope, evidence, control testing, automation, and risk before relying on a compliance report.
The Maturity Gap: Why GRC Programs Plateau (and How to Advance)
GRC programs often plateau when passing audits becomes the goal. Cheri Hotman and Tanya Wade explain how organizations can move from reactive compliance toward managed, risk-based, continuously improving Cyber GRC programs.
What Operationalized GRC Actually Looks Like: From Silos to Systems
Operationalized GRC is more than audits, tools, and green dashboards. Cheri Hotman and Peter Spier explain how governance, risk, ownership, automation, and business alignment create a GRC operating model that actually works.
The ROI of GRC: How Governance, Risk and Compliance Creates Business Value
GRC is more than a compliance expense. Cheri Hotman and Joe Kodali explain how governance, risk, and compliance can support revenue, customer trust, efficiency, risk reduction, resilience, and better business decisions.
Securing AI: How to Manage AI Risk Without Slowing Innovation
AI adoption is moving faster than many organizations can govern it. Cheri Hotman and Ranbir B. discuss how to manage AI security, data, third-party risk, employee use, monitoring, and human oversight without unnecessarily slowing innovation.
Real-Life GRC Horror Stories: What Checkbox Compliance Can Cost You
Real-life GRC failures often begin with shortcuts: overreliance on tools, weak ownership, under-resourcing, poor third-party oversight, cheap audits, and treating compliance as the finish line. Cheri Hotman and Tanya Wade explain what organizations can learn from these GRC horror stories.
Supply Chain Security: Managing Risk Beyond Your Vendors
When it comes to third-party supply chain security, there’s a big difference between doing it and doing it right. Every vendor you work with brings their own vendors into the mix—so who truly owns the risk? In this session, we’ll explore how to identify, assess, and mitigate supply chain risks at every level without overburdening […]