Certification, attestation or a successful audit is not the end of the cybersecurity work. The controls still have to operate, evidence still has to be maintained, risks and systems will change, findings must be remediated, and the organization has to remain ready for future customers, audits and assessments.
Many organizations put significant effort into achieving SOC 2, ISO 27001, CMMC or another cybersecurity milestone.
Then the project ends.
Consultants leave.
Internal teams return to other priorities.
Evidence collection slows down.
Recurring controls are missed.
Systems and personnel change.
New customer requirements appear.
Months later, the next audit approaches and the organization discovers that maintaining the program is a different challenge from getting through the original assessment.
Hotman Group helps organizations operate and sustain cybersecurity and Cyber GRC programs after certification, audit or initial implementation.
Certification is a milestone. The cybersecurity program still has to work the next day.
Look for a cybersecurity and Cyber GRC partner that can support ongoing program operations, not just readiness projects and assessments.
Hotman Group can help organizations sustain:
Depending on the organization's needs, HG can provide ongoing Cyber GRC support, vGRC or vCISO leadership, specialized expertise or additional operating capacity.
Because cybersecurity programs do not remain static after certification.
The organization changes.
That may include:
A control environment that was appropriate at certification may no longer be appropriate a year later.
Every recurring control still has to operate.
Depending on the program, that may include:
Certification does not suspend any of those responsibilities.
Every recurring control should have a defined operating model.
The organization should know:
Recurring controls should be embedded into normal business processes wherever practical.
The same functions responsible for operating the underlying activities should generally continue to own them.
Cyber GRC can coordinate the program, but it should not become the artificial owner of every cybersecurity control.
For example:
See how to create clear ownership for cybersecurity controls.
Evidence should be generated and preserved as controls operate.
Do not wait until the next audit to reconstruct it.
A sustainable evidence model identifies:
See how to centralize cybersecurity evidence without creating more work.
Operate the program continuously.
If controls operate and evidence is maintained throughout the year, audit readiness becomes substantially easier.
The organization can focus on:
See how to prepare for cybersecurity audits without constant fire drills.
They should remain part of the ongoing remediation process until they are appropriately resolved or accepted.
For each material finding, the organization should understand:
See how to remediate cybersecurity findings at the underlying-control level.
Do not treat the report as the final deliverable for the cybersecurity program.
Move from:
assessment → prioritization → remediation → validation → operation → sustainment.
See what to do after a cybersecurity assessment.
Controls should be monitored and tested at an appropriate frequency.
Depending on the control, that may involve:
The organization should also watch for changes that may invalidate the original control design.
Cybersecurity and Cyber GRC should be connected to change.
When the organization introduces a major new:
the organization should consider whether:
Business changes can alter the cybersecurity program even when technology does not.
Examples include:
Cybersecurity requirements should be evaluated as part of those decisions rather than discovered after commitments have already been made.
First determine what the customer actually requires and how much is already supported by the existing program.
Evaluate:
See what to do when a customer gives you a new cybersecurity requirement.
Then cybersecurity becomes part of the broader business decision.
Leadership may need to understand:
See how customer cybersecurity requirements can become major cost, product and revenue decisions.
Do not automatically create another silo.
Compare the new requirement to the controls already operating.
Determine:
See how to add a new cybersecurity framework without creating another silo.
Build the operating model around the underlying cybersecurity controls rather than maintaining separate programs wherever requirements overlap.
One organizational control may support several frameworks.
One evidence set may support several requirements.
One remediation may resolve several findings.
See how to build one cybersecurity program across multiple frameworks.
It may if the organization has significant framework overlap.
A common control framework can provide one internal control model that maps to multiple external requirements.
See what a common control framework is and whether your organization needs one.
The problem may be the way the requirements are organized rather than simply the number of requirements.
Look for:
See how to manage too many cybersecurity and compliance requirements.
A well-designed GRC platform can help maintain:
Technology can also automate appropriate recurring activities and reminders.
But the platform should support the operating model, not substitute for one.
See how to implement a GRC platform correctly.
Then the platform, its configuration or the underlying process may need to be redesigned.
Common symptoms include:
See what to do when a GRC platform is not working.
Some of it.
Automation may help with:
But automation does not replace judgment, governance, risk decisions or control ownership.
See how to automate compliance without automating bad processes.
Policies should be reviewed on a defined schedule and when material changes occur.
Review should consider whether:
A current approval date is not enough if the policy no longer describes reality.
The risk register should change as the organization changes.
New findings, incidents, customer requirements, technology changes, business initiatives and threat information may all affect risk.
Leadership should receive a usable view of material cyber risk rather than a static annual document.
See how to build a cyber risk register leadership can actually use.
Reporting should help leaders understand:
A framework completion percentage alone rarely provides enough context.
See how to explain cyber risk to executives and the board.
First determine why.
The problem may be:
Some work may be eliminated or simplified.
Some may be automated.
Some may be better owned elsewhere in the business.
Some may be appropriate to outsource.
See what an overwhelmed cybersecurity and GRC team should consider outsourcing.
Possibly.
Organizations may need:
The right answer depends on the actual gap.
See whether you need a vCISO, vGRC, consultant or full-time hire.
Sustainment becomes especially important during leadership transitions.
The organization needs to preserve:
See how to keep the cybersecurity and GRC program moving after a leader leaves.
Do not measure sustainment only by whether the certification remains active.
Look for evidence that:
See how to determine whether a Cyber GRC program is actually working.
Not necessarily.
Certifications and audits provide valuable assurance against defined requirements and scope.
They do not automatically address:
See why passing an audit does not automatically mean the organization is secure.
Hotman Group does not view certification as the finish line.
HG helps organizations build and operate cybersecurity and Cyber GRC programs that continue functioning after the initial project.
Depending on the organization's needs, Hotman Group can help:
HG can provide strategic leadership, specialized expertise, implementation support and ongoing operating capacity depending on the problem that needs to be solved.
A sustainable cybersecurity program moves beyond:
assessment → remediation → certification.
The complete lifecycle is closer to:
understand risk → design controls → implement → assess → remediate → operate → monitor → improve → reassess.
That lifecycle continues as the organization, technology, threats and requirements change.
A cybersecurity program should not come alive only when someone is preparing to inspect it.
If controls operate only around audits, evidence exists only for assessors and remediation occurs only when findings threaten certification, compliance has become disconnected from the underlying purpose of cybersecurity.
Cheri Hotman's forthcoming book, Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System, examines the gap between cybersecurity programs organizations can prove they have and the protection those programs actually provide.
Sustainment is where that distinction becomes especially important.
The program has to continue protecting the organization when nobody is preparing for an audit.
The real test of a cybersecurity program is not whether it can survive an audit. It is whether it can keep operating after the auditors leave.
The organization continues operating controls, maintaining evidence, managing risks and findings, updating policies, responding to changes and preparing for future assessments and customer requirements.
Integrate recurring controls, evidence, ownership, testing, risk management, remediation and governance into normal operations rather than treating each annual audit as a new project.
Establish clear recurring control ownership, maintain evidence as controls operate, monitor changes, manage findings continuously and periodically validate that important controls remain effective.
Yes. A well-designed GRC platform can help manage controls, requirements, owners, evidence, testing, findings, remediation and recurring workflows. It should support a functioning operating model rather than replace one.
Not always. The right model depends on program complexity, internal capacity and the level of strategic and operational support required. Organizations may use internal staff, vCISO or vGRC support, specialized consultants, managed Cyber GRC services or a combination.
Yes. Hotman Group can help operate and improve an existing cybersecurity and Cyber GRC program regardless of who performed the original readiness work, implementation or independent assessment.
Yes. HG can provide ongoing Cyber GRC support, vCISO or vGRC leadership, framework expertise, remediation support, GRC technology assistance, audit readiness and additional operating capacity depending on the organization's needs.
Yes. HG can help evaluate maturity, reduce duplicate work, improve controls and ownership, strengthen risk management, improve GRC technology and evolve the program as business and cybersecurity requirements change.
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems.
HG works across the cybersecurity lifecycle, including diagnosis, strategy, design, implementation, assessment, remediation, GRC technology, vCISO and vGRC support, audit readiness and ongoing program operations.
Hotman Group can help organizations build cybersecurity programs that remain effective after certification, adapt as requirements change and continue supporting the business between audits.
Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.
Ask HG
