In our latest Lexicon episode, we sit down with Andry Rakotomalala, a seasoned cybersecurity and compliance professional, to discuss the rapidly evolving cybersecurity landscape, governance, risk management, and compliance (GRC).
In our talk, Andry breaks down the essentials of GRC, its relevance across industries, and how advancements in AI are transforming the field. Also, check out our educational platform, IE Academy.
What on Earth is GRC anyway?
“GRC stands for governance, risk, and compliance,” Andry started by explaining. He clarified that GRC professionals oversee regulatory standards and manage risks to ensure companies protect data and follow industry rules.“I see GRC as one of the areas that will have a big boom, especially in 2025,” Rakotomalala added.
Andry further explained that GRC is essential because it helps organizations minimize the risk of data breaches and other cyber incidents. “At the end of the day, GRC is about protecting data, and really, cybersecurity is about protecting people, places, and things,” he noted.
Importantly this protection extends beyond the tech industry; any organization handling sensitive financial, health, or customer-related data benefits from implementing GRC strategies.
GRC and its role in cybersecurity
When asked how GRC connects to cybersecurity, Andry shared an important industry adage: “We have a saying in cybersecurity that it’s not just about if you get hacked; it’s when you get hacked.”
More from Career
See AllThis inevitability, he explained, underscores the need for a robust GRC framework that not only reduces the likelihood of a security breach but also minimizes its potential impact.Andry explained that one core aspect of GRC’s role in cybersecurity is ensuring that security practices align with company goals and client expectations.
“If you’re a client-centric company, you have to say, ‘We want to protect our customers, and doing this will help us do that.’,” Andry explained. So, by tying GRC practices to customer-centric goals, companies can align their risk management strategies with broader organizational values.
Andry also touched on one of GRC’s vital tools: frameworks like COBIT, NIST, and ISO 27001, which provide structured guidance on assessing and mitigating risks.
“COBIT, for example, gives you a guide to find out what risks are and how to address them,” he said. Frameworks like these help organizations identify vulnerabilities, decide which risks to mitigate and establish ongoing practices to maintain security and compliance.
GRC to help build trust manage reputation
A critical aspect of GRC, Andry explained, is managing reputational risk. A cyber incident can impact more than just data; it can erode public trust in a company. “There are countless hacks out there—SolarWinds, Target, LastPass,” he said, adding, “If they get into the news, they face major reputational downfalls.”
“Back in 2013, when Target leaked a bunch of credit card data, people were wary of shopping there,” Andry said. For companies, establishing a GRC program is a way to protect their reputation and data.
Compliance with standards and obtaining certifications like ISO 27001 or SOC 2 also play a key role. Andry explained that these accreditations signal stakeholders and customers that an organization takes security seriously. “Accreditation does several things. It legitimizes the business and helps stakeholders and end-users feel safer knowing that, ‘Hey, we’re accredited,’” he said.
GRC is not just for tech
While GRC is often associated with software and tech companies, Andry clarified that it applies to various industries.
“Every industry has regulations,” he noted. “Think of restaurants—they have food regulations, and automotive companies have regulations for building cars. In cybersecurity, compliance regulations protect data because we’re all handling sensitive information,” he added.
“Different industries and regions have specific standards. For instance, GDPR in the EU protects end-user privacy, and in California, we have CCPA,” he added.
Despite variations, many compliance standards overlap, so being accredited in one framework often means an organization complies mainly with others, Andry said. “Compliance with one or two standards sets you up well to be compliant with others,” he said.
AI and automation in GRC
Looking to the future, Andry discussed the transformative role AI and automation could play in GRC. “AI will be a big player in automating compliance and improving precision in risk management,” he explained.
“Humans can do a lot of cybersecurity work but have a higher error rate. AI can provide real-time insights and be more accurate,” he explained.
Andry mentioned tools like ServiceNow and LogicGate, which leverage AI to automate compliance processes, making it easier for companies to stay compliant across large networks.
“You could manually check each device for security settings, but AI can scan the entire network in seconds and find any issues,” he said, adding that this automation saves “countless hours of human work.”
He also noted that automated penetration testing tools allow companies to regularly evaluate their vulnerabilities without needing a large security team. “There are tools that can do one-click tests to see how your vulnerabilities stand, which is a requirement in many compliance standards,” he said.
This proactive monitoring is crucial as threats evolve, helping organizations stay one step ahead.
Company culture and training are essential
Implementing GRC isn’t just about technology and policy—it’s about fostering a culture of security awareness throughout an organization. Andry emphasized the importance of employee education in cybersecurity: “Humans are the biggest weak link in cybersecurity breaches. About 80% of incidents happen because of a human mistake, like clicking on a phishing email.”
To make cybersecurity training engaging, Andry described tools like Hacker Rangers, a gamified platform for cybersecurity awareness. “It’s competitive and makes learning fun,” he said. “Employees get points for identifying phishing attempts, making cybersecurity part of the company culture without scaring them,” he added.
This approach, he argued, is essential for embedding GRC practices into a company’s ethical framework. “You want to integrate it with the culture,” Andry said. “When employees understand the importance of GRC, they’re more likely to follow best practices and protect both company data and customer trust,” Andry said.
Continuous monitoring and improvement
Andry explained that one of the ongoing challenges of GRC is the need for continuous monitoring and improvement. “It’s not enough to say, ‘We’re compliant,’ and be done with it,” he warned. “Continuous documentation and monitoring should be set as an expectation from the beginning.”
He added that choosing the right tools and partners is essential to this process. “Some vendors will help you achieve compliance and then leave, but others provide monitoring support, making reaccreditation easier,” he said. By setting these expectations, companies can ensure their GRC efforts remain effective.
The future of GRC
Finally, Andry shared his outlook on the future of GRC, particularly as technology advances. “The future of GRC is bright, especially with AI on the horizon,” he said. “AI will automate tasks, improve accuracy, and provide real-time compliance insights.” However, he also cautioned that AI comes with ethical considerations, like privacy concerns and potential biases.
Overall, Andry believes the future of GRC will see even more integration with AI, driving efficiency and precision in compliance and risk management. He had a final piece of advice for anyone considering a cybersecurity career:
“Not all cybersecurity professionals need to know how to hack or code, but a technical understanding is crucial. GRC and privacy roles are booming, and they’re key to the future of cybersecurity,” he added.





