Module 30 · Leadership · ⏱ 80 min · 🏆 +500 XP

GRC Leadership & Strategic Communication

Technical mastery is table stakes. GRC Directors win or lose in boardrooms, budget negotiations, and one-on-ones with the CEO. This capstone leadership module synthesises maturity models, executive communication science, risk appetite governance, and the 90-day director blueprint that separates effective leaders from technical managers.

CMMI Maturity FAIR Model Risk Appetite Board Communication GRC Team Leadership Strategic Planning 90-Day Blueprint

🎯 Learning Objectives

Maturity Assessment

Apply CMMI, GRCMM, and ISO 33001 frameworks to score an organisation's GRC capability and build a credible maturity roadmap.

Quantitative Risk (FAIR)

Use the Factor Analysis of Information Risk model to translate cyber risk into financial loss exposure that CFOs and Boards can act on.

Risk Appetite Governance

Draft a Board-approved risk appetite statement, set risk tolerance thresholds, and link them to operational KRIs and escalation triggers.

Executive Communication

Structure board risk reports using the NACD Cyber-Risk Oversight Handbook principles and the SEC cybersecurity disclosure framework.

Team Leadership

Design a high-performing GRC team, apply competency-based hiring, lead through organisational change, and build a culture of compliance.

Strategic Planning

Build a 3-year GRC strategic plan aligned to business objectives, with OKRs, budget justification, and a 90-day onboarding blueprint.

GRC Maturity Models

📐 What Is a Maturity Model?

A maturity model is an ordered set of capability levels that describes a progression from ad hoc, reactive practice toward optimised, continuously improving practice. In GRC, maturity models serve three strategic purposes: (1) diagnosis — where are we now?; (2) benchmarking — where are peers?; (3) roadmapping — what investments will advance us?

The academic lineage traces to Crosby's Quality Management Maturity Grid (1979), operationalised in software engineering as the CMM by Humphrey (SEI, 1989), and eventually ISO/IEC 15504 (SPICE). GRC-specific models adapted these foundations to governance and risk domains in the 2000s.

Key Maturity Frameworks

CMMI Capability Maturity Model Integration — GRC Lens

CMMI defines five maturity levels originally for software processes, widely adapted for GRC capability assessment:

1
Initial — Heroic / Ad Hoc

Processes undefined. Success depends on individual heroics. Controls inconsistently applied. No central policy library. Audit findings repeatedly recurring.

2
Managed — Repeatable

Basic project-level processes defined. Risk registers exist but are siloed. Compliance tracked reactively. Some documented policies.

3
Defined — Consistent

Organisation-wide GRC processes documented, standardised, and integrated across BUs. Risk appetite formally approved. Control frameworks mapped (NIST/ISO).

4
Quantitatively Managed — Measured

KRIs and KPIs tracked against baselines. Quantitative risk models (FAIR, Monte Carlo) in use. Board-level dashboards with leading indicators.

5
Optimising — Continuous Improvement

Root cause analysis drives process improvement. Threat intelligence integrated into risk models. GRC platform automation. Culture of compliance embedded.

Most large enterprises operate at Level 2–3. Movement from Level 3 to Level 4 (quantitative management) is the strategic inflection point where GRC transitions from a cost centre to a value-generating function that can demonstrate ROI to the board.

ISO 33001 Process Assessment — Capability Dimensions

ISO/IEC 33001:2015 (successor to ISO 15504) provides a two-dimensional assessment model:

  • Process dimension: What GRC processes exist (risk assessment, policy management, audit, incident response)?
  • Capability dimension: How well are they performed? (0=Incomplete → 5=Optimising)

For each process, assessors assign a rating: N (Not achieved, 0–15%), P (Partially, 15–50%), L (Largely, 50–85%), F (Fully, 85–100%). This granularity lets GRC leaders identify which processes drag overall maturity down — critical for prioritising investment.

📋 OCEG GRC Capability Model — GRCMM

The Open Compliance and Ethics Group (OCEG) GRC Capability Model ("Red Book") defines a Principled Performance framework with four capability clusters:

LEARN

Environmental scan, stakeholder context, mission/values clarity. Maps to ISO 31000 §6.3 (Context establishment).

ALIGN

Strategy, objectives, appetite, culture, and incentive alignment. Prevents mission drift under pressure.

PERFORM

Controls design and operation, risk treatment, compliance assurance. The execution engine of GRC.

REVIEW

Monitoring, assessment, assurance reporting, and improvement. Closes the feedback loop.

The GRCMM scores each cluster on a 1–5 scale, producing a radar chart that visually identifies imbalance — e.g., an organisation with strong PERFORM but weak REVIEW tends to over-control without knowing if controls are working.

🗺️ Maturity Roadmap Construction

A credible maturity roadmap answers three board-level questions: Where are we? Where do we need to be? How long will it take and what will it cost?

1
Baseline Assessment

Interview control owners, review documentation, test controls against framework. Score each domain. Validate with external assessor for objectivity.

2
Target State Definition

Align target maturity to business risk appetite, regulatory requirements, and peer benchmarks (industry surveys, SANS, Gartner). Not every domain needs Level 5.

3
Gap Analysis & Prioritisation

Identify delta between baseline and target per domain. Prioritise gaps by risk exposure × implementation feasibility × regulatory mandate.

4
Initiative Mapping

Map each gap to a specific initiative (e.g., "implement GRC platform" → moves Risk Management from L2→L4). Estimate effort, cost, dependencies.

5
Board Presentation

Present roadmap as a 3-year heat map: red/yellow/green per domain per year. Include investment ask, risk reduction quantified (FAIR), and success milestones.

💡 Director Insight: When presenting maturity assessments to boards, never lead with the score. Lead with the risk story: "At current Level 2 maturity in third-party risk, we cannot detect a SolarWinds-style supply chain compromise within our detection window. Moving to Level 3 requires $X and reduces our expected annual loss exposure by $Y." The maturity score is evidence; the business impact is the message.

FAIR: Factor Analysis of Information Risk

🔬 The FAIR Ontology

FAIR (Factor Analysis of Information Risk), developed by Jack Jones and standardised by The Open Group (O-RA, O-RT standards), is the dominant quantitative risk model in enterprise cybersecurity. It decomposes risk into a taxonomy that maps to actuarial and financial analysis methods boards already understand.

The top-level FAIR equation: Risk = Probable Frequency × Probable Magnitude

FAIR disaggregates each component into measurable sub-factors, enabling Monte Carlo simulation to produce a loss exceedance curve — a probabilistic distribution of annual loss that replaces the subjective "High/Medium/Low" heat map.

🌲 FAIR Factor Tree

A
Loss Event Frequency (LEF)

How often a loss event will occur per year. Decomposed into: Threat Event Frequency (TEF) × Vulnerability (% of threat events that become loss events).

B
Threat Event Frequency (TEF)

How often a threat agent acts against an asset. Driven by: Contact Frequency (how often threat touches asset) × Probability of Action (% chance they attempt exploit).

C
Vulnerability

Threat Capability (threat agent skill level) vs. Control Strength (effectiveness of current defences). Modeled as a range: min/most likely/max.

D
Loss Magnitude (LM)

Financial impact if a loss event occurs. Six loss form categories: Productivity, Response, Replacement, Competitive Advantage, Fines/Judgements, Reputation.

Monte Carlo simulation runs 10,000+ iterations sampling each factor from its probability distribution, producing a loss distribution with percentile outputs: "90th percentile annual loss = $4.2M" — a statement any CFO can underwrite against.

📊 FAIR vs. Qualitative Risk Heat Maps

DimensionQualitative Heat MapFAIR Quantitative
OutputHigh/Medium/Low ratingAnnual Loss Exposure ($) with CI
Board credibilityLow — subjective scoringHigh — actuarial method
PrioritisationOrdinal rank onlyROI of each control investment
AggregationCannot sum "Highs"Portfolio risk ($) summed across risks
Regulatory alignmentNIST CSF, ISO 31000SEC disclosure, NACD guidance
EffortDaysWeeks (initial); hours (updates)
Tool supportSpreadsheetRiskLens, SAFE One, Axio

The 2023 SEC cybersecurity disclosure rules effectively require FAIR-style thinking: material risk must be disclosed with enough specificity for investors to make informed decisions. Organisations still using qualitative-only models face SEC enforcement risk for inadequate materiality determination processes.

🛠️ FAIR Analysis in Practice — 6-Step Workflow

1
Scope the scenario

Define: Asset at risk, threat community, loss type (confidentiality breach, ransomware, etc.). Specific scenarios produce defensible estimates; vague scenarios produce noise.

2
Gather data

Historical incidents (internal SIEM, FS-ISAC, Verizon DBIR), threat intel (CrowdStrike, Mandiant), industry loss databases (NetDiligence, RiskIQ).

3
Estimate factor ranges

SME workshops with IT, legal, finance, business. Use calibrated estimation techniques (confidence intervals, reference class forecasting) to set Min/ML/Max per factor.

4
Run simulation

10,000-iteration Monte Carlo via RiskLens, Axio, or open-source Python (pyfair). Output: loss exceedance curve, VaR at 80th/90th/95th percentile.

5
Sensitivity analysis

Tornado chart identifies which factor drives the most variance — tells you where to invest in data quality or control improvement first.

6
Communicate & decide

Present as "Without control X, 90th-percentile loss = $4.2M/yr. With control X ($300K investment), loss drops to $1.1M/yr. 2.7-year payback." ROI-framed risk decisions.

Risk Appetite & Tolerance Framework

📖 Definitions & Distinctions

These three concepts form a nested hierarchy. Confusing them is a common governance failure:

Risk Appetite

The aggregate level and type of risk the Board is willing to accept in pursuit of strategic objectives. A qualitative policy statement approved at board level. Example: "We accept moderate reputational risk but zero tolerance for regulatory non-compliance resulting in licence revocation."

Risk Tolerance

The quantitative boundaries within which risk must remain. Operationalises the appetite statement. Example: "Customer PII breach < 5,000 records per incident; audit findings must be remediated within 90 days." Set by senior management.

Risk Capacity

The maximum risk the organisation can bear before existential impact. Determined by capital reserves, insurance coverage, regulatory licence conditions. Risk appetite must always be set below capacity.

KRIs (Key Risk Indicators)

Metrics that provide early warning when risk is approaching tolerance thresholds. KRIs are leading indicators (unlike KPIs which are lagging). Example: "% of third-party vendors with overdue risk assessments > 10% = amber trigger."

ISO 31000:2018 §6.3.3 requires organisations to establish risk criteria — the explicit conditions against which risk significance is evaluated. Risk appetite is the governance mechanism that sets those criteria at the Board level, then cascades them to management through tolerance thresholds and KRI triggers.

✍️ Anatomy of a Risk Appetite Statement (RAS)

An effective RAS has five components. Absence of any component creates governance gaps:

1
Strategic Context

Links appetite to business objectives. "As a digital-first financial services firm pursuing 25% CAGR, we accept elevated technology risk while maintaining strict regulatory compliance posture."

2
Risk Category Statements

Qualitative appetite per risk category (Cyber, Operational, Regulatory, Third-Party, Data Privacy). Each rated: Zero / Low / Moderate / High appetite with justification.

3
Quantitative Thresholds

FAIR-derived financial thresholds. "Annual expected cyber loss must not exceed $10M (0.5% of revenue)." Linked directly to insurance coverage and capital reserves.

4
KRI Dashboard Linkage

Named KRIs with amber/red thresholds and escalation paths. "If critical vulnerability remediation SLA breach rate > 15%, CISO escalates to Board Risk Committee within 30 days."

5
Review & Approval Cadence

Annual Board re-approval with interim CISO review quarterly. Material business change (M&A, new product, regulatory change) triggers ad hoc review.

📐 Sample Risk Appetite Matrix — Cascade Structure

Risk DomainBoard AppetiteMgmt Tolerance (KRI Amber)Mgmt Tolerance (KRI Red)
Regulatory ComplianceZero — licence-critical1 unresolved critical findingRegulatory inquiry opened
Data Privacy (GDPR/CCPA)Low — brand sensitive1 reportable breach / quarterSupervisory authority notice
CybersecurityModerate — managed riskMTTD > 72 hrs for Severity-1Ransomware with data exfiltration
Third-Party RiskModerate — business-enabling>10% critical vendors overdue reviewCritical vendor breach affecting us
Technology InnovationHigh — growth imperativePilot failure rate > 40%Regulatory sanction on new product
Financial/FraudLow — fiduciary dutyFraud losses > $500K/qtrMaterial restatement required

Board-Level Risk Communication

📚 Regulatory & Governance Drivers

Board risk communication is no longer optional soft-skill territory — it is a regulatory imperative:

  • SEC Cybersecurity Disclosure Rules (2023): Require annual 10-K disclosure of cybersecurity risk management processes, governance, and material incident reporting within 4 business days (Form 8-K Item 1.05). CISOs who cannot explain risk in material terms expose the company to SEC enforcement.
  • NACD Cyber-Risk Oversight Handbook (2023 edition): Five principles for board directors — directors must be informed, CISOs must communicate in business language, and cyber risk must be treated as an enterprise risk, not just an IT issue.
  • NIST IR 8286 series: Enterprise Risk Management Integration guidance explicitly requires cybersecurity risk to be aggregated to ERM-level reporting using a common risk language.
  • UK FRC Corporate Governance Code: Boards must make a "viability statement" that implicitly requires cyber risk scenario analysis.

🧠 Communication Science — Why Technical Reports Fail

Research in risk communication (Slovic, 1987; Kahneman, 2011; Fischhoff, 2013) identifies why technically accurate reports fail at the board level:

Psychic Numbing

Decision-makers become desensitised to large numbers. "$50M cyber risk" is less actionable than "equivalent to losing 3,000 customers and our payment licence."

Affect Heuristic

Boards make decisions based on emotional response to risk, not statistical analysis. Stories activate affect; dashboards do not. Lead with a scenario narrative, then quantify.

Scope Insensitivity

People respond similarly to risks of vastly different magnitude. Anchoring to familiar business metrics (revenue %, customer count, days of downtime) corrects this.

Dread Risk Bias

Novel, uncontrollable risks (AI-enabled attacks, quantum decryption) create disproportionate dread. Directors need calibrated probability alongside consequence to avoid over-investment in low-probability threats.

📋 The NACD-Aligned Board Risk Report Structure

1
Executive Summary (1 page)

Risk posture status (Red/Amber/Green). Top 3 risks requiring board attention. Actions needed from the board (approve budget, ratify appetite, note escalation). No technical jargon.

2
Risk Posture Dashboard

KRI heatmap vs. tolerance thresholds. Trend arrows (improving/stable/worsening). Benchmark vs. industry peer (e.g., SANS, Gartner). FAIR-derived loss exposure vs. insurance coverage.

3
Top Risk Deep-Dives (3–5 risks)

One page per risk: Scenario narrative → Probability/magnitude (FAIR) → Current controls → Residual exposure → Recommended treatment with cost/benefit. Business language throughout.

4
Program Performance

OKR/KPI performance vs. targets. Audit finding remediation rate. Compliance posture (certifications, upcoming renewals). Investment efficiency (GRC spend vs. risk reduction achieved).

5
Horizon Scan

Emerging risks (regulatory changes, threat actor TTPs, geopolitical, AI). Proposed appetite adjustment if needed. Early warning for next-quarter priorities.

🗣️ The Risk Narrative Framework — STORY Method

Effective board communicators structure risk presentations using narrative psychology. The STORY method (adapted from Heath & Heath, "Made to Stick"):

  • S — Situation: Set the business context. "We process 2M payment transactions daily. Our PCI-DSS scope covers 47 systems."
  • T — Threat: Name the concrete scenario. "A Magecart-style skimmer injected into our checkout page could exfiltrate all card data in real time — as happened to British Airways in 2018, resulting in a £183M ICO fine."
  • O — Odds & Outcome: Quantify using FAIR. "Our FAIR model estimates a 35% probability of a comparable incident in the next 12 months with an expected loss of $3.8M."
  • R — Response: Present the recommended treatment. "Implementing client-side JavaScript security monitoring ($120K) reduces probability to 8% — a $2.2M annual expected loss reduction."
  • Y — Your decision: Explicitly state what the board must decide. "We are requesting approval of the $120K investment and amendment of the Payment Risk tolerance threshold."

GRC Team Leadership & Culture

🏗️ GRC Organisational Design Models

The structure of the GRC function significantly impacts its effectiveness and independence. Three dominant models exist in practice:

Centralised GRC

Single GRC function reports to CISO or CRO. Uniform standards, economies of scale, strong independence. Risk: disconnected from business operations, seen as "compliance police." Best for: highly regulated industries (banking, healthcare).

Federated GRC

Central GRC CoE sets policy and frameworks; business unit GRC liaisons handle day-to-day. Balances consistency with business context. Most common model in large enterprises. Risk: coordination overhead, inconsistent execution.

Embedded GRC

GRC professionals sit within business units, matrixed to a central function. Maximises business alignment. Risk: independence compromise, capture by business priorities. Best for: mature, high-trust organisations.

Three Lines Model (IIA 2020)

Line 1: Operations own risk. Line 2: GRC/Risk/Compliance provide oversight. Line 3: Internal Audit provides independent assurance. Separates ownership, oversight, and assurance — the governance gold standard.

🧬 GRC Competency Model — Hiring for the Modern Team

The modern GRC team requires a blend of competencies that no single hire possesses. A Director must consciously build complementary capability:

Role ArchetypeCore CompetenciesCertification Target
GRC AnalystControl testing, evidence gathering, policy writing, tool proficiencyCISA, CompTIA Security+
Risk AnalystFAIR modelling, risk register management, scenario analysis, data analysisCRISC, CGEIT
Compliance SpecialistRegulatory mapping, audit management, crosswalk analysis, vendor liaisonCCEP, CRCM, ISO 27001 LA
Privacy AnalystDPIA/PIA, data mapping, GDPR/CCPA interpretation, breach responseCIPP/E, CIPP/US, CIPM
GRC ArchitectPlatform design, control framework mapping, automation, API integrationSABSA, TOGAF, CISSP
GRC DirectorBoard communication, strategic planning, budget management, stakeholder influenceCGRC, CISM, MBA

🌱 Building a Compliance Culture — Behavioural Theory

Research in organisational behaviour (Tyler, 2006; Treviño et al., 2014) demonstrates that rule compliance driven by fear is fragile and expensive to enforce, while value-driven compliance is self-sustaining. The GRC Director's leadership challenge is cultural transformation:

1
Tone at the Top

Culture follows leadership behaviour, not policy documents. If the CEO bypasses approval workflows, no training program will create a compliance culture. GRC Directors must partner with the C-suite to model compliant behaviour visibly.

2
Procedural Justice

Tyler's research shows employees comply when they perceive processes as fair, even if outcomes are unfavourable. GRC must explain the "why" behind controls, involve employees in policy design, and apply rules consistently regardless of seniority.

3
Positive Reinforcement

Most GRC programs only engage employees when violations occur. Shift to recognising compliant behaviour: gamified security training, department compliance scoreboards, formal recognition in performance reviews.

4
Friction Reduction

Behavioural economics (Thaler & Sunstein, "Nudge") shows that making the compliant path the easiest path is more effective than training. Design controls that are embedded in workflows rather than bolt-on approvals.

⚡ GRC Director Influence Without Authority

GRC Directors rarely have direct authority over the business units they must influence. Robert Cialdini's influence principles, applied to GRC leadership:

  • Reciprocity: Provide value first. Help a business unit understand a regulatory requirement they were struggling with — they will reciprocate when you need their cooperation on a control implementation.
  • Authority: Position the GRC team as experts, not enforcers. Publish research, present at industry events, get certified. When you cite NIST or SEC, you borrow regulatory authority.
  • Social Proof: "Competitor X implemented this control after their breach. Peer Y already passes this audit check." Industry benchmarks and peer comparisons motivate action better than policy mandates.
  • Commitment & Consistency: Get business leaders to publicly commit to risk-reduction milestones in steering committee forums. Written commitments dramatically increase follow-through.
  • Liking: GRC teams that build genuine relationships with business partners get faster cooperation. Invest in cross-functional relationships before you need them.

The 90-Day GRC Director Blueprint

📖 Theoretical Foundation — First 90 Days

Michael Watkins' "The First 90 Days" (2003, updated 2013) is the definitive framework for leadership transitions. Applied to GRC, Watkins' STARS model (Start-up, Turnaround, Accelerated Growth, Realignment, Sustaining Success) determines the initial strategic posture:

  • Turnaround: Previous audit failures, regulatory sanction, or breach. Rapid stabilisation, quick wins, authority-based leadership. Board is watching closely.
  • Realignment: Organisation doesn't recognise it has a GRC problem. Requires diagnosis, coalition-building, and data-driven persuasion before action. The most common scenario for new GRC Directors.
  • Sustaining Success: Strong program, hired to continue and mature it. Focus on innovation, talent, and capability advancement. Avoid "change for change's sake."

Diagnosis before action is the cardinal rule. The first 30 days are intelligence-gathering, not initiative-launching.

🗓️ Phase 1: Days 1–30 — Diagnose & Listen

W1
Stakeholder Mapping

Meet every C-suite executive, business unit head, and key IT leader. Ask: "What are your top 3 risks? What's your biggest frustration with the current GRC program? What does success look like to you?" Listen 80%, speak 20%.

W2
Program Inventory

Document every existing policy, framework, tool, certification, audit commitment, and regulatory requirement. Build the authoritative GRC universe. Identify what exists vs. what is operational.

W3
Risk Assessment Review

Review the most recent risk register, audit reports (internal and external), regulatory examination findings, and incident post-mortems. Identify systemic patterns, not just individual findings.

W4
Maturity Baseline

Score current GRC program maturity using CMMI or GRCMM framework. Present preliminary findings to CISO/CRO. Frame as "diagnostic" not "criticism." Propose 90-day and 12-month objectives.

🗓️ Phase 2: Days 31–60 — Stabilise & Win

W5
Quick Wins

Identify 2–3 visible, high-impact improvements achievable in 30 days. Examples: automate a recurring evidence collection task, close a long-overdue audit finding, publish a policy that was missing, implement a KRI dashboard. Quick wins build credibility and momentum.

W6
GRC Charter & Mission

Draft the GRC team charter: mission statement, scope, reporting lines, decision rights (RACI), escalation paths. Socialise with CISO, CRO, Legal, Internal Audit. Get formal sign-off from executive sponsor.

W7
Risk Appetite Alignment

If no formal RAS exists, draft one. If one exists, review it against current business strategy and regulatory environment. Present to CRO for endorsement, then route to Board Risk Committee for next meeting.

W8
Team Assessment

Evaluate current team capabilities against the GRC competency model. Identify gaps. Begin recruiting plan for critical gaps. Define development plans for existing team members. Establish team OKRs for the year.

🗓️ Phase 3: Days 61–90 — Strategic Foundation

W9
3-Year GRC Strategic Plan

Build the strategic roadmap: maturity targets by domain, investment requirements (OpEx + CapEx), technology roadmap (GRC platform, automation), hiring plan, and regulatory compliance calendar. Align to board-approved risk appetite.

W10
Budget Proposal

Develop ROI-based budget justification using FAIR analysis. Frame as: "Current risk exposure = $X. Proposed GRC investment = $Y. Expected risk reduction = $Z (FAIR-modelled). Payback period = N years." Submit through CRO to CFO.

W11
Board Presentation

Deliver first formal board/Board Risk Committee presentation. Structure using NACD framework: program assessment, top risks, strategic plan, resource ask, appetite confirmation. Set expectations for quarterly reporting cadence.

W12
Operating Rhythm

Establish recurring governance cadences: weekly GRC team standup, monthly CISO/CRO briefing, quarterly Board Risk Committee report, annual risk appetite review. Launch programme OKR tracking dashboard.

90-Day Success Criteria: Board has approved risk appetite statement. Top 5 critical audit findings have remediation plans with owners. GRC team has documented charter and OKRs. FAIR baseline completed for top 3 enterprise risks. First board risk report delivered. Quick wins visible and publicised internally.

📊 GRC Strategic Plan OKR Template

ObjectiveKey Result 1Key Result 2Key Result 3
Achieve quantitative risk managementFAIR models for top 10 risks by Q2Board receives loss exposure ($) quarterlyROI demonstrated on 2+ control investments
Close critical compliance gapsAudit finding remediation rate >90% by Q3Zero overdue regulatory commitmentsSOC 2 Type II certification maintained
Mature third-party risk program100% Tier-1 vendors assessed annuallyTPRM platform implemented by Q2Vendor risk scoring embedded in procurement
Build high-performing GRC teamCompetency gaps filled (hire/train) by Q3Team NPS > 70 in annual surveyAll team members have active certification path

🧪 Lab — Board Risk Memo

You are a newly appointed GRC Director at NovaBridge Capital, a mid-size investment management firm with $8B AUM. The Board Risk Committee meets in 2 weeks. Write a 1-page executive risk memo using the STORY method and NACD framework structure.

Scenario brief: Your FAIR analysis of a ransomware scenario produces: TEF = 2.4 events/year; Vulnerability = 42%; Expected loss per event = $2.1M. Your current cyber insurance covers $1.5M per incident. A proposed EDR upgrade ($280K) would reduce Vulnerability to 18%.

🎭 Scenario — The Board Revolt

📝 Knowledge Assessment — 17 Questions

🎓

Course Complete — CYBS105 GRC

You have completed all 30 modules of the TemDaniels Academy GRC programme. You now possess the theoretical knowledge, practical frameworks, and leadership skills of a GRC Director. The discipline of Governance, Risk, and Compliance is not a destination — it is a continuous practice of principled performance.

🏆 GRC Director CYBS105 Complete 30 Modules Expert Level
"The goal of GRC is not compliance. The goal is principled performance — achieving objectives, addressing uncertainty, and acting with integrity." — OCEG GRC Capability Model, Red Book
← Return to Course Home