Ep 95 ·
Beyond the Debate: Security as an Enabler & GRC Maturity with Winthrop Welch, Fractional CISO
Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.
Guest
Fractional CISO
Andy Welch is a cybersecurity executive who has led security, GRC and risk strategy at companies including Yahoo, IBM and Goldman Sachs. He brings a pragmatic, executive-level lens to building secure, compliant and resilient organizations, from Fortune 500 firms to emerging tech.
Ep 95 ·
Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.
Andy says security and effective compliance shouldn't be at odds. He defines compliance broadly, covering external requirements such as regulations and contracts and internal obligations such as policies and controls, and argues that good compliance mandates describe what must be done, not how. Clear, traceable compliance requirements then become inputs to the security roadmap and can be prioritized like any other requirements.
According to Andy, it is gaining persistent, regular access to the right people on the business side, so you understand their motivators and where the business is headed. Security has to offer those stakeholders value and keep the dialogue open and refreshed, and he thinks many organizations don't spend enough time keeping that alignment steady.
Andy sees GRC maturity as pretty low in many organizations, where GRC is treated as the assessments team that arrives after development with a checklist and a list of problems. That makes it a source of noise and friction, and it quickly gets marginalized. The shift comes when GRC moves upstream, embeds in development and operations, learns their workflows and helps teams make security decisions as they are being made.
Andy starts with clarity: when he built out the GRC program at Yahoo, he defined its vision, scope and value proposition and tied everything back to them. Rather than splitting teams into governance, risk and compliance, he splits them by internal focus (policies, control standards, risk oversight, internal compliance) and external focus (regulatory engagement, third-party risk, M&A contracts, customer and partner assurance). He finds this aligns better with how businesses are structured and builds more natural relationships with stakeholders.
Andy sees tool sprawl as a symptom of never having a cohesive security architecture or long-term plan, with tools picked reactively for each problem, leading to overlap, integration gaps and bloated cost. The fix is strategic: step back, map out your future state architecture and build a reasonable roadmap to get there. It takes time and coordination across teams, but the payoff is a leaner, more effective and more affordable program.
Andy says security has to be part of the deal from the deal thesis through diligence to execution, not bolted on at the end. He describes a deal that collapsed because the deal team didn't engage IT or security until after close, and the acquired software's architecture proved too expensive to integrate. Once his team started adding insight to deal teams, those teams began inviting them in, which he treats as the sign of success.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.