The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Leadership/CISO Tradecraft®
CISO Tradecraft® artwork

#288 - How to Break Into Cybersecurity Through GRC (with Steve McMichael)

CISO Tradecraft® · 2026-06-15 · 39 min

0:00--:--

Episode notes

In this CISO Tradecraft episode, host G Mark Hardy interviews Steve McMichael, author of "How to Break into GRC: Mindset, Methods, and Skills," about entering cybersecurity through governance, risk, and compliance. McMichael shares his transition from accounting and explains GRC’s role as decision support and the interface between business and technical teams, breaking down governance, risk management, and compliance (including audits and third-party/supply-chain assurance). They discuss misconceptions that GRC is “just paperwork,” barriers like imposter syndrome, and strategies such as building T-shaped skills, targeting about 20% technical depth across domains, and developing credibility through a deep specialty. McMichael also describes an immersion mindset driven by emotional engagement, and showcases an open-source NIST Cybersecurity Framework Profile Assessment Database project on GitHub to help newcomers build skills and portfolio contributions.

More from CISO Tradecraft®

All episodes →
  • Harvest Now, Decrypt Later (with Marcus Sachs) - #29069 / 100
  • #289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)
  • #287 - Cybersecurity Insights You'll Want to Hear (with Michael Hammer)
  • #286 - AI-Native Security (with Nishant Doshi & Saro Subbiah)
  • #285 - Passwordless Authentication (with Nishant Kaushik)
Explore the best B2B Leadership podcasts →
All CISO Tradecraft® episodes →