Practical guidance on identifying, evaluating, prioritizing, and communicating cybersecurity risk so organizations can make better business decisions.
Defending Your Cybersecurity Budget Without Sacrificing Protection
A flat cybersecurity budget forces difficult decisions. But cutting every expense by the same percentage can weaken the controls your business depends on while leaving inefficient spending untouched. In a video published by Help Net Security on September 17, 2026, Cheri Hotman, Managing Partner of Hotman Group and a practicing vCISO and vGRC leader, discusses […]
GRC Is Cybersecurity: Why Compliance Alone Doesn’t Make an Organization Secure
GRC is more than compliance documentation. Cheri Hotman and Mea Clift explain how risk-based GRC helps organizations build stronger cybersecurity programs, prioritize investment, and move beyond checkbox security.
What Operationalized GRC Actually Looks Like: From Silos to Systems
Operationalized GRC is more than audits, tools, and green dashboards. Cheri Hotman and Peter Spier explain how governance, risk, ownership, automation, and business alignment create a GRC operating model that actually works.
The ROI of GRC: How Governance, Risk and Compliance Creates Business Value
GRC is more than a compliance expense. Cheri Hotman and Joe Kodali explain how governance, risk, and compliance can support revenue, customer trust, efficiency, risk reduction, resilience, and better business decisions.
Securing AI: How to Manage AI Risk Without Slowing Innovation
AI adoption is moving faster than many organizations can govern it. Cheri Hotman and Ranbir B. discuss how to manage AI security, data, third-party risk, employee use, monitoring, and human oversight without unnecessarily slowing innovation.
Real-Life GRC Horror Stories: What Checkbox Compliance Can Cost You
Real-life GRC failures often begin with shortcuts: overreliance on tools, weak ownership, under-resourcing, poor third-party oversight, cheap audits, and treating compliance as the finish line. Cheri Hotman and Tanya Wade explain what organizations can learn from these GRC horror stories.
Supply Chain Security: How to Build a Risk-Based Third-Party Risk Management Program
Every vendor relationship introduces risk. In this Hotman Group session, Cheri Hotman explains how organizations can move beyond questionnaires and annual compliance exercises to build a sustainable, risk-based approach to supply chain security and third-party risk management. Watch the Session Cheri walks through third-party risk, fourth-party dependencies, vendor tiering, inherent and residual risk, questionnaires, shared […]
Multi-Framework Compliance: How to Build One GRC Program for Many Frameworks
Managing multiple compliance frameworks does not require separate programs for each one. Cheri Hotman and Ravi Kant explain how organizations can rationalize overlapping requirements, build a common control environment, reuse evidence, support business growth, and operate one scalable Cyber GRC program.
Security Awareness Training – Artificial Intelligence & Emerging Security Risks
Join us for an essential Security Awareness Training session focused on the evolving landscape of Artificial Intelligence (AI) and the emerging security risks that come with it. In this session, we explore how AI is being used in everyday tools—and how it’s also creating new opportunities for threat actors. This training emphasizes awareness, responsible usage, […]