Hotman Group Perspectives

Risk

Practical guidance on identifying, evaluating, prioritizing, and communicating cybersecurity risk so organizations can make better business decisions.

Defending Your Cybersecurity Budget Without Sacrificing Protection
A flat cybersecurity budget forces difficult decisions. But cutting every expense by the same percentage can weaken the controls your business depends on while leaving inefficient spending untouched. In a video published by Help Net Security on September 17, 2026, Cheri Hotman, Managing Partner of Hotman Group and a practicing vCISO and vGRC leader, discusses […]
GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
Supply Chain Security: Managing Risk Beyond Your Vendors
When it comes to third-party supply chain security, there’s a big difference between doing it and doing it right. Every vendor you work with brings their own vendors into the mix—so who truly owns the risk? In this session, we’ll explore how to identify, assess, and mitigate supply chain risks at every level without overburdening […]
Security Awareness Training – Artificial Intelligence & Emerging Security Risks
Join us for an essential Security Awareness Training session focused on the evolving landscape of Artificial Intelligence (AI) and the emerging security risks that come with it. In this session, we explore how AI is being used in everyday tools—and how it’s also creating new opportunities for threat actors. This training emphasizes awareness, responsible usage, […]
The Audit Trap: Why Passing isn’t Protection
Think passing an audit means your cybersecurity program is solid? Think again. Many organizations unknowingly expose themselves to greater risk by relying on compliance checkmarks rather than a true security strategy. In this session, we’ll uncover the hidden dangers of audit-driven security, why “passing” may leave you more vulnerable, and the real steps leaders must […]
Security Awareness Training – Social Engineering
Join us for an essential Security Awareness Training session focused on Social Engineering. In this session, we delve into the critical importance of cybersecurity awareness and how you, as an individual, serve as the first line of defense against cyber threats.   Key Topics Covered:   Why This Matters: Remember: Technology alone cannot protect you. […]
Security Questionnaires: You Can’t Just Blame the Intern
Let’s face it—no one enjoys security questionnaires. They are tedious and time-consuming, and it’s easy to question their real effectiveness in mitigating security risks, especially since they’re often a check-the-box exercise. However, in today’s digital landscape, they are unavoidable for building and maintaining trust with customers. Join us as we confront this harsh reality: despite […]