A yellow industrial articulated robot arm (FANUC-style) enclosed in a wire-mesh safety cage, positioned within a beverage packaging/bottling facility. Conveyor belts carrying cases of canned drinks run through the surrounding warehouse, with stacked product visible on shelving in the background and a concrete factory floor.

The GRC Integration You Don't Have to Wait For

For years, Governance, Risk, and Compliance (GRC) systems weren’t much more than specialized document repositories. They might integrate with some of your tooling, such as a vulnerability scanner, in some basic way. We did use one, as it helped us map controls of a framework, like ISO 27001 or NIST SP 800-171, to evidence, such as policies, procedures, or other documentation that demonstrate compliance. Then we could easily identify any controls we hadn’t addressed. But we still spent hours manually collecting evidence— shuffling screenshots, spreadsheets, and PDFs, and eating up product engineers’ time with meetings whose entire content could be summarized as, “Yes, that access list is still correct, please let me get back to my actual job.” And validating all this material was also a soul-crushing, manual process, poring over reams of documentation every audit cycle for any needed changes, broken links, or anything else that was missing. ...

July 31, 2026 · 3 min · Andrew Korty
Giant metal spiral slide with surrounding wooden walkway ramp, viewed from above through a protective chain-link fence

Vendor Security Assessments Are Out of Control

Assessments and questionnaires are slowing down business, yet there’s no evidence they improve security Your security team has spent hours this week alone on security questionnaires despite your organization’s unpatched systems, unfinished and untested disaster recovery plans, and unencrypted backups. Sound familiar? Security analysts’ desks are awash these days with the spreadsheets, Word documents, and even custom apps organizations use to quiz prospective vendors about their security practices before buying a product. That product is usually an online app, known in the industry as software as a service (SaaS). ...

September 23, 2025 · 7 min · Andrew Korty
Black & white selfie of the author wearing sunglasses and a hat, whose wide brim he is gently bending in salutation

Your Personal Attack Surface

When we security types talk about “attack surface” or “threat surface,” we mean the part of our technology environment that’s potentially vulnerable. Think of your skin. We wear clothing to protect it from the sun’s harmful rays. A construction worker wears heavy leather to guard against wounds from tools and sharp materials. A cook wears an oven mitt to avoid burns. Any skin we leave exposed is vulnerable to these threats. We often deliberately accept these risks—for example, wearing just a swimsuit to the beach—sacrificing some security for some enjoyment and versatility. Ideally, we use good judgment and make a sensible, balanced risk decision. We can also use compensating safeguards (e.g., sunscreen) to limit the downside risk of our decision. ...

December 9, 2024 · 3 min · Andrew Korty