Skip to content
Scale To Zero by Cloudanix
W(

Guest

Winthrop (Andy) Welch

Fractional CISO

Andy Welch is a cybersecurity executive who has led security, GRC and risk strategy at companies including Yahoo, IBM and Goldman Sachs. He brings a pragmatic, executive-level lens to building secure, compliant and resilient organizations, from Fortune 500 firms to emerging tech.

Episode with Winthrop

Questions Winthrop answered

  • Should security and compliance be treated as separate priorities?

    Andy says security and effective compliance shouldn't be at odds. He defines compliance broadly, covering external requirements such as regulations and contracts and internal obligations such as policies and controls, and argues that good compliance mandates describe what must be done, not how. Clear, traceable compliance requirements then become inputs to the security roadmap and can be prioritized like any other requirements.

  • What is the biggest hurdle to aligning security strategy with the business?

    According to Andy, it is gaining persistent, regular access to the right people on the business side, so you understand their motivators and where the business is headed. Security has to offer those stakeholders value and keep the dialogue open and refreshed, and he thinks many organizations don't spend enough time keeping that alignment steady.

  • How mature is GRC in most enterprises?

    Andy sees GRC maturity as pretty low in many organizations, where GRC is treated as the assessments team that arrives after development with a checklist and a list of problems. That makes it a source of noise and friction, and it quickly gets marginalized. The shift comes when GRC moves upstream, embeds in development and operations, learns their workflows and helps teams make security decisions as they are being made.

  • How should you structure a GRC team?

    Andy starts with clarity: when he built out the GRC program at Yahoo, he defined its vision, scope and value proposition and tied everything back to them. Rather than splitting teams into governance, risk and compliance, he splits them by internal focus (policies, control standards, risk oversight, internal compliance) and external focus (regulatory engagement, third-party risk, M&A contracts, customer and partner assurance). He finds this aligns better with how businesses are structured and builds more natural relationships with stakeholders.

  • How do you fix security tool sprawl?

    Andy sees tool sprawl as a symptom of never having a cohesive security architecture or long-term plan, with tools picked reactively for each problem, leading to overlap, integration gaps and bloated cost. The fix is strategic: step back, map out your future state architecture and build a reasonable roadmap to get there. It takes time and coordination across teams, but the payoff is a leaner, more effective and more affordable program.

  • When should security get involved in M&A deals?

    Andy says security has to be part of the deal from the deal thesis through diligence to execution, not bolted on at the end. He describes a deal that collapsed because the deal team didn't engage IT or security until after close, and the acquired software's architecture proved too expensive to integrate. Once his team started adding insight to deal teams, those teams began inviting them in, which he treats as the sign of success.

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.