Changing Hearts and Minding the Business: Relationship Building in GRC and Security
Relationship management and strong partnership influence is the key to a successful Governance, Risk and Compliance (GRC) program. This includes building trust among your stakeholders, understanding the business, and being honest about the benefits (and trade-offs) of prioritizing certain initiatives over others. How do we decide on that prioritization or the rank-stacked list? How do we influence rather than execute on our own? These are the questions we will ask and answer in this discussion.
During this talk, I’ll set the framework by describing current perceptions from both sides of the problem - InfoSec taking a hard stance, the business ignoring/avoiding InfoSec. I’ll use examples from prior roles - in incident response and knowing how the business runs, to risk management in entertainment and empathizing with minimal runway time for game development and release, and currently as Head of GRC in a global technology organization, prioritizing international compliance obligations and market access opportunities with strong engineering partnership. In closing, I will outline the small changes we can make in a butterfly effect that will raise the bar of security, leading to less stressful security incidents, and clear on-call weekends!
With 15+ years of experience in information security, risk management, IT and organizational leadership, Hatim is committed to fostering cross-functional collaboration and driving secure, resilient business outcomes. His expertise includes developing and growing risk management programs and GRC funcitions, translating security best practices and compliance requirements into business values and engineering objectives, implementing process improvements, while mentoring teams to enhance operational efficiency.