Risk Grustlers EP 4 | Back to Basics: A Crash Course for Experts!

Welcome back to another episode of Risk Grustlers, the podcast aimed at demystifying risk management for newcomers. Our mission is to unravel the complexities of this field and make it accessible to everyone taking their first steps.
In this episode, Gary shares his unique journey into the world of security. Gary's story is one of transitioning from a 15-year career as a developer to finding his footing in the realm of information security and risk management. Join us as he walks us through the path that led him here.
Watch the complete podcast here.
https://www.youtube.com/watch?v=fQ5S68EHitc
Let's take a look at some important highlights from the enlightening podcast.
Ayush: Tell us about your journey into security. How did you end up in this field? What emotions and experiences shaped your path?
Gary: Sure. I spent 15 years coding, then shifted to architecture and design. 9/11 shook things up and hit the travel industry hard. I got involved in sharing data with Homeland Security to build a secure watch list after that incident. We needed to transfer data very securely. Data safety caught my interest locking it down and keeping the bad actors out.
I started designing systems with security as the base, tight controls, and limited access. Then, our company's security head moved to Expedia and wanted me on his new team. I was like, "Why me? I design, not secure." He needed someone to bridge the gap between tech and business, someone to explain why security matters. So, I made the move in 2011 from a place I'd been for 15 years.
Aayush: Did you feel nervous about it? How much of a learning curve was there when you made the transition?
It was a very difficult transition. I second guessed it multiple times, as I wasn't the principal security architect. I was a bundle of nerves, dealing with that classic imposter syndrome. Leaving behind a stable gig in Colorado for the unknown in Seattle was no easy choice, especially for my family. But I took the leap.
Seattle felt like a whole new universe. I met several genius architects. My learning curve shot through the roof. I dove deep into research and learned a lot just by being around them in meetings all day, every day. My role was to bridge the gap by making the tech lingo understandable to everyone else so they knew what was going on and what they needed to do.
Aayush: As you ventured into the unfamiliar, what were your initial steps to acclimate and identify your path? What were the primary challenges you tackled first?
Gary: I focused on simplifying concepts, especially in identity and access management. Ensured everyone understood who could access what and when. Role-based access was key defining it so only the right folks could access data and systems at the right times. Early on, I grasped this basic idea and translated it into practical solutions that people needed.
It felt great when people turned to me for answers instead of the other architects. Being that bridge helped make complex security talk understandable and actionable.
One key lesson I learned early was to admit when I didn't know something. Just saying, "Let me check on that," became my go-to. The approach saved me from diving into deep waters and helped me come back with solid answers after consulting with colleagues.
Aayush: Given the overwhelming number of security tools, the rise of new acronyms, and the pressure to meet regulatory and customer security expectations, it's challenging to discern what really holds significance. CISOs are constantly inundated with pitches; does going back to the basics help?
Gary: It's crucial to grasp the organization's risks, establish processes to address those risks, and ensure effective remediation. Often, we acquire many tools and generate numerous findings, but there's confusion due to the overwhelming number of critical findings, making it challenging to take appropriate action.
Aayush: What's truly critical? Is it about having the right data encrypted, or is it about whether the encryption algorithms are secure or compromised or how encryption keys are protected?
Gary: Encrypting data doesn't help if your encryption key is easily accessible. Basic compromises like that happen. First off, know where your data resides and who can access it. Role-based access control is key. Also, purge data when not needed. Why protect data you no longer use? Store it securely offline if required for compliance.
Supply chain worries are real. We hand off data to vendors. Instead of costly site visits, focus on training. Vendor breaches often stem from email compromise, phishing, ransomware. Training on spotting fake emails matters more than fortress-like data centers.
Aayush: When organizations aim to return to basics, where's the starting point? Is it examining frameworks like SOC 2, ISO 27001, or NIST 800? These frameworks share similar controls, so what's the initial step?
Gary: When checking out vendors, we start with SOC 2 or ISO 27001. These cover the basics. Once that's sorted, we delve into areas like data exchanges. We prioritize identity aspects single sign-on, robust authentication. Local authentication is out; access control and removal upon departure are in. This way, we streamline our focus.
Aayush: Imagine I'm a large SaaS company with $200-$300 million in ARR and a 2% revenue infosec budget. I'm just starting on security. What's the absolute worst advice you could give me?
Gary: Here's my advice talk to many vendors, listen, and gather tools. But an inbox full of vendor-driven issues isn't the way. I focus on our existing tools, collecting their findings, and then prioritizing. Resources are limited, so we fix the high-priority issues first.
We're left with two choices: Invest more resources to solve it all or accept certain risks. Either we fix all findings with more resources or accept some risk. For instance, if we find application vulnerabilities, do we have a web app firewall to mitigate them while developers address them?
Aayush: With attackers being fast and sophisticated, how do we balance basic infosec controls against evolving threats? Is there a tradeoff between simplicity and effectiveness against smart attackers?
Gary: Attackers take the easy route, so start with strong security basics. Prioritize clean security hygiene before advanced measures. Having the right processes in place is crucial. Don't invest in tech that finds the wrong things. Use technology to spot issues, but prioritize, understand, and remediate findings through proper processes.
Aayush: How do you present a case to secure a budget for security, especially when establishing controls from scratch? Could you share your experiences navigating the process of obtaining security budgets?
Gary: Security shouldn't just be viewed as a cost center. It's about enabling the business, not blocking it. We aim to integrate security controls into developers' tools, creating that security "easy button."
My current focus is helping teams do just that no unnecessary overhead. Demonstrating how we reduce risk and empower the business makes these conversations smoother.
We align with the company's risk tolerance and the board's stance. It's about understanding and mitigating risks to match acceptable levels. Every board wants minimal risk, but investment has limits. Our role is to clarify accepted risk, ensure comfort, and determine the necessary investment to lower risk if needed.
Aayush: When selling LLM use cases to large enterprises, what are the top four or five crucial controls startups must have in place to enhance their appeal to these enterprises?
Gary: Public information benefits all. Think Disney using Google for character recognition identifying Mickey Mouse in pictures. But when AI affects how our business operates and thinks, we guard that IP. Data segregation is key, even when sharing learning. We isolate our data by not feeding it into an accessible system. There's the public good too, where everyone contributes.
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
See what a real security- first GRC platform looks like
Ready to see what security-first GRC really looks like?
Focus on the traveler experience. We’ll handle the regulations.
Get Scrut. Achieve and maintain compliance without the busywork.
Choose risk-first compliance that’s always on, built for you, and never in your way.
Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?
Join the thousands of companies automating their compliance with Scrut.
The right partner makes all the difference. Let’s grow together.
Make your business easy to trust, put security transparency front and center.
Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.
Your GRC team, multiplied and AI-backed.
Modern compliance for the evolving education landscape.
Ready to simplify healthcare compliance?
Don’t let compliance turn into a bottleneck in your SaaS growth.
Find the right compliance frameworks for your business in minutes
Ready to see what security-first GRC really looks like?
Real-time visibility into every asset
Ready to simplify fintech compliance?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Tag, classify, and monitor assets in real time—without the manual overhead.
Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.
Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.
Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.
Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.
Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.
Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.
Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.
Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.
Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.
Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.
Scrut ensures access permissions are correct, up-to-date, and fully compliant.
Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?
Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.
Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.
Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.
Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!
Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.
Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!
Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.
Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.
Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.
Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.
Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.



