Defense in Depth: Should Risk Lead GRC?

Defining risk for the business. Is that where a governance, risk, and compliance effort should begin? How does risk inform the other two, or does calculating risk take too long that you can’t start with it?


Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Allan Alford (@AllanAlfordinTX). Our guest is Marnie Wilking (@mhwilking), global head of security & technology risk management, Wayfair.

Thanks to this week’s podcast sponsor, Qualys

Qualys is a pioneer and leading provider of cloud-based security and compliance solutions.

Got feedback? Join the conversation on LinkedIn.

On this episode of Defense in Depth, you’ll learn:

  • The model of risk = likelihood x impact doesn’t take into account the value of assets. Assets have to be valued first before you calculate risk.
  • Is the reason risk isn’t used to lead governance, risk, and compliance (GRC) because it’s so darn hard to calculate? Many CISOs say their toughest job starting out is trying to understand what the crown jewels are and what the board’s risk tolerance is.
  • Risk management allows the board to know when you have enough security. Some assets may require eight layers where others may only require one or two.
  • Determining likelihood of an attack involves a good amount of guesswork. We’ve discussed on a previous episode of CISO/Security Vendor Relationship Podcastthat we don’t go back to see how good our risk predictions were. If you want to get better at it, you should. Otherwise, it will always be guesswork.
  • Even if you can get someone to agree what their risk tolerance is, or what asset is of importance, trying to get agreement among a group can be a blocker. Keep in mind that each person is going to have a different viewpoint and concerns.
  • Knowing risk appetite is critical. You can apply security controls without knowing it, but that’s providing a unified security layer across all data, people, and applications when they are all not equal when it comes to asset valuation.

Defense in Depth

David Spark
David Spark is the founder of CISO Series where he produces and co-hosts many of the shows. Spark is a veteran tech journalist having appeared in dozens of media outlets for almost three decades.