EP 14 | Doing the little things right

In episode 14 of Risk Grustlers, we sit down with Drew Danner, Managing Director at BD Emerson, who brings a refreshing and no-nonsense perspective to the world of governance, risk, and compliance (GRC). With ten years of army experience and a solid reputation in cybersecurity, Drew shares his philosophy of “keeping it stupid and simple†when tackling complex security challenges.
Drew makes a compelling case for bridging the gap between security and compliance, showing us that they're not opposing forces but two sides of the same coin. His practical approach is built on hard work, attention to detail, and a belief in the power of small, consistent actions to drive meaningful change.
From breaking into GRC as a newcomer to handling intimidating frameworks like ISO 27001, Drew offers actionable advice for both beginners and seasoned professionals. Whether you're struggling with the basics or looking to refine your program, this conversation will leave you inspired and ready to act.
Watch the full episode here
https://youtu.be/8soOKivemlM?si=ij3NdwCdY4fY1ZZ-
Let's explore some highlights from this value-packed episode.
Aayush: Why don't you tell us a bit about your journey into risk management? How did it all start?
Drew: Honestly, my career in risk management started by accidentâ€â€a happy series of accidents, actually.
I began in the army, serving in the infantry, but an injury led me to explore other career paths. A smart leader suggested I get a degree, so I went for a bachelor's in math and computer science, then a master's in math, and eventually a doctorate in business. The doctorate was less about math and more about figuring out how to make knowledge valuable in the real world.
After leading systems teams in the army for ten years, I transitioned to the intelligence community for two years, then took on digital transformation projects for large public companies. At one point, I was responsible for a $1 billion e-commerce channel, overseeing not just GRC or security, but the technology as a whole. Eventually, a lawyer convinced me that security and privacy could form the foundation of a great company. Fast forward five years, and here we are with BD Emersonâ€â€a law firm, cybersecurity consulting firm, and CPA audit firm all rolled into one.
Aayush: One hot topic in the industry is the debate about compliance vs. security. What's your take on that?
Drew: I think the debate is ridiculous. The idea that compliance isn't securityâ€â€or vice versaâ€â€comes from a misunderstanding of both. Compliance provides the left and right boundaries for security. It defines the requirements. Security, on the other hand, is the operational execution of those requirements.
Let me give you an example: In the government, we use secure facilities called SCIFs (Sensitive Compartmented Information Facilities) to keep signals out. Why don't businesses do the same? Because they're not required to. Compliance creates those requirements. Without it, there's no framework to guide security efforts.
Take Massachusetts' WISP law, for instance. It mandates written information security plans for businesses over a certain size. Even companies that don't care much about securityâ€â€like staffing agenciesâ€â€are required to comply. This drives them to hire security experts and integrate security into their operations. Compliance isn't separate from securityâ€â€it's the foundation for it.
Also read: How do security and compliance differ?
Aayush: Certifications like CISSP are often seen as the gold standard in security. What's your view on them?
Drew: Certifications are just pieces of paper. Don't get me wrongâ€â€they serve a purpose, but they're not always the best measure of competence. I got my CISSP because it was required for my role in the government. I had a month to prepare, crammed for the test, and passed. Barely, but I passed!
What matters more is real-world experience. Certifications might open doors, but they don't necessarily make you effective at solving problems or communicating with stakeholders.
Aayush: You keep talking about “the little things.†Why are they so important?
Drew: Oh, the little things are the foundation of everything in GRC. Let me break it down.
When companies are in their early stages, compliance often feels like a “nice-to-have.†Founders are laser-focused on growth, which makes sense, but they often overlook the commitments they're making in their contracts. For example, they might sign a deal in Europe and agree to a data processing agreement (DPA) or a data security schedule (DSS) without fully understanding the additional requirements those documents impose.
At first, they think, “What are the odds anyone will check?†But as the business grows, those commitments become liabilities. Suddenly, a customer comes back a year later asking for proof, and the company's scrambling to meet obligations they didn't even remember agreeing to.
Now, here's where the little things come in. If you build good habits earlyâ€â€like documenting your commitments, reviewing contracts for compliance impacts, and integrating those commitments into your operationsâ€â€you avoid that last-minute panic.
It's not glamorous work, but it's transformational.
Aayush: What do you think is the minimum viable team for a small to mid-size company just starting to create a good, mature GRC program?
Drew: We've worked with clients who hired us as their very first employee, so we've seen a lot of different approaches. I remember one case with a VC-backed startup. They knew their target customers, which included banks and other financial institutions, would only buy their product if it was already compliant with SOC 2, or even above that. So, even though they were just getting started and had about $5 to $6 million in funding to build their product, they prioritized security from the very beginning.
Their first hires were part of their security team because they knew they had to meet very specific security requirements to even get into the financial sector. Banks, VCs, and other financial entities have stricter security standards because they deal with sensitive data, and the reviews can be a lot more demanding. They knew that by addressing security first, they'd be in a better position to attract those clients down the line.
Aayush: And if they're not bringing in consultants early on, what do they usually do?
Drew: When a company doesn't bring in consultants like us right away, they typically try to find someone internal who can own security and compliance. They might look for a unicornâ€â€someone who's a software engineer with experience in security. The issue is, those kinds of people are rare and expensive. But if they can find someone like that, they might overpay just to secure that expertise early on.
When a company reaches around 50 employees, that's when things start to shift. By that point, their revenue is growing, and they've probably started selling to larger clients. That means there are going to be more security checkpoints in the sales process. At that point, they may start bringing in external consultants because they're getting more security requests from customers or partners.
Also read: How Scrut Automation's expert guidance makes a difference
Aayush: How do you approach tailoring controls to meet specific commitments a company has made? Can you share an example of what that looks like in practice?
Drew: Let's say you've promised to delete customer data when they leave. That's a standard practice, right? But then you sign a contract with a customer who says, “Actually, for legal reasons, we need you to keep our data for two years after we leave.†That's not a requirement in SOC 2 or ISO; it's a contractual commitment.
The problem is, if you don't account for that promise in your controls, it's likely to get lost in the shuffle. You'll forget about it until the customer comes back asking for proof, and by then, you're in damage control mode.
What we do is ensure those commitments are integrated into your system. For this scenario, we'd create a specific policy or control around data retention tied directly to that contract. It's not just about complianceâ€â€it's about trust. If you say you'll do something, your systems and processes need to back that up. That's how we help companies build credibility and avoid those “uh-oh†moments.
Also read: ISO 42001 Vs ISO 27001: What is the difference?
Aayush: How have security audits changed now that AI is everywhere?
Drew: It's a big shift. So many SaaS and software companies are building AI into their productsâ€â€whether through APIs like OpenAI or Anthropicâ€â€or using AI internally for tasks like automation. But with that comes new risks. A classic example? Employees uploading sensitive company documents to tools like ChatGPT through their personal accounts to save time. That's a huge data leakage risk.
Now, audits are starting to reflect these challenges. Companies need controls to prevent unauthorized use of AI, and tools like Unbound Security have popped up to address exactly this issue. But more than tools, organizations need clear policies. A simple step? Create a document that outlines how employees can safely use AIâ€â€like “don't put sensitive data into public AI systems†or “use our enterprise license to ensure security.†It's all about setting boundaries while still enabling people to do their jobs effectively.
There are also emerging standards to guide this, like OWASP's security recommendations for AI and ISO 42001, which is specifically for AI systems. On top of that, frameworks like NIST's AI Risk Management Framework help build trust and security into AI operations.
At the end of the day, audits now focus on things like “least privilege†accessâ€â€making sure only the right people can use AI tools and that sensitive data stays protected. And here's the kicker: being upfront with customers about your AI usage can actually help your business. Transparency builds trust, and trust drives sales.
So, if you're using AI, secure it, govern it, and be honest about it. That's the new reality for security audits in the age of AI.
Aayush: What's your advice for companies just starting their compliance journey?
Drew: Start small and scale thoughtfully. You don't need a full-blown compliance program on day one, but you do need to build good habits. Begin by understanding your commitments. If you've signed a contract that includes a data processing agreement, read it carefully. Make sure you know what you're agreeing to.
From there, leverage tools that make compliance manageable. Platforms like Scrut can give you a head start, and AI can help you break down complex standards. But don't try to do it all yourself. As your company grows, the demands of compliance will outpace your ability to manage it solo. That's when it's time to bring in experts.
Most companies don't hire a full-time GRC person until they're nearing 100 employees. Until then, the key is to focus on incremental progress. Document your processes. Review your commitments. Make small, daily improvements. Those little things? They add up, and they'll save you time, money, and headaches in the long run.
Also read: How small and medium businesses can allocate cybersecurity responsibility
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
See what a real security- first GRC platform looks like
Ready to see what security-first GRC really looks like?
Focus on the traveler experience. We’ll handle the regulations.
Get Scrut. Achieve and maintain compliance without the busywork.
Choose risk-first compliance that’s always on, built for you, and never in your way.
Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?
Join the thousands of companies automating their compliance with Scrut.
The right partner makes all the difference. Let’s grow together.
Make your business easy to trust, put security transparency front and center.
Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.
Your GRC team, multiplied and AI-backed.
Modern compliance for the evolving education landscape.
Ready to simplify healthcare compliance?
Don’t let compliance turn into a bottleneck in your SaaS growth.
Find the right compliance frameworks for your business in minutes
Ready to see what security-first GRC really looks like?
Real-time visibility into every asset
Ready to simplify fintech compliance?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Tag, classify, and monitor assets in real time—without the manual overhead.
Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.
Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.
Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.
Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.
Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.
Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.
Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.
Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.
Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.
Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.
Scrut ensures access permissions are correct, up-to-date, and fully compliant.
Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?
Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.
Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.
Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.
Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!
Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.
Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!
Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.
Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.
Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.
Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.
Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.



