Jacob Hill

GRC Academy

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!

Author

Jacob Hill

Category

Technology

Podcast website

grcacademy.io

Latest episode

Nov 18, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Zero Trust - It's Way Easier Than You Think with John Kindervag 03.09.2024

Zero Trust is NOT complicated! Don't believe me? Let me introduce you to its creator! In this episode, Jacob speaks with John Kindervag, the creator of Zero Trust. John is the Chief Evangelist at Illumio where he accelerates awareness and adoption of Zero Trust Segmentation. In the episode he shares the origin story of Zero Trust starting with his time at Forrester Research. He explains the fundam...

The Cisco Whistleblower - The First Settled Cybersecurity False Claims Act (FCA) Lawsuit 24.08.2024

Introducing the Cisco Whistleblower. In this episode, Jacob speaks with lawyer Hamsa Mahendranathan about the FIRST cybersecurity False Claims Act (FCA) lawsuit that reached a settlement! This goes all the way back to 2008 believe it or not… The lawsuit was FINALLY settled in 2019! As we all know, the DoJ has intervened in the Georgia Tech NIST 800-171 FCA whistleblower complaint. Wonder what the...

CMMC and Manufacturing with Daniel Stark 20.08.2024

Think your users are resistant to CMMC? You ain't seen nothin' yet! In this episode, Jacob speaks with Daniel Stark of Meerkat Cyber about the unique CMMC compliance challenges in a manufacturing environment. Here are some highlights: Daniel's experience running IT in a family-owned manufacturing shop How Controlled Unclassified Information (CUI) flows on the shop floor Physical and environmental...

Insights on NIST 800-171 Joint Surveillance Voluntary Assessments (JSVA) from IntelliGRC 01.08.2024

So… How do I get a CMMC’d early? In this episode, Jacob speaks with Steven Molter of IntelliGRC about his experiences helping IntelliGRC clients complete NIST 800-171 Joint Surveillance Voluntary Assessments (JSVAs). Here are some highlights: The JSVA process & how to request one The different teams within DIBCAC The challenge of subjectivity during assessments Advice for companies preparing f...

Hypori Halo: Redefining Mobile Device Security with Brian Kovalski 16.07.2024

In this episode, Jacob speaks with Brian Kowalski, Senior Vice President of Federal at Hypori. In the episode they discuss Hypori's origin story and its innovations in the mobile security space. Here are some highlights from the episode: Hypori's origin story and its roots starting as an NSA Commercial Solutions for Classified Program (CSfC) product How it is different from traditional Mobile Devi...

The Business Case for Information Security with Mark Nicholls 18.06.2024

In this episode, Jacob speaks with Mr. Mark Nicholls! Mark is the CEO of Information Professionals Group and has over 30 years of experience! In the episode they discuss the business case for information security, and how cybersecurity professionals can effectively communicate with the C-suite and other business leaders! Here are some highlights from the episode: The Importance of information secu...

How To Stop Social Engineering in Its Tracks with Chris Silvers 07.06.2024

In this episode, Jacob speaks with Penetration Tester & Social Engineer Chris Silvers! Chris Silvers is the founder of CG Silvers Consulting! Chris has a vast amount of experience ranging from CMMC assessments to penetration testing. He even won the prestigious DEF CON black badge during the DEF CON 24 Social Engineering Capture the Flag (SECTF)! In this episode they focus on how organizations...

ISO 27001 Essentials with Aron Lange 06.05.2024

In this episode, Jacob speaks with ISO 27001 expert Aron Lange! Aron is the founder of the GRC Lab, and a Udemy instructor with more than 11,000 students! He is an experienced auditor for management systems based on ISO 27001, ISO 9001, ISO 27018 and ISO 22301. In this episode they discuss the essentials of ISO 27001 including the history of the standard and the changes in the latest revision, but...

Why Threat Intel is Essential for Vulnerability Management with Patrick Garrity 30.04.2024

In this episode, Jacob speaks with cybersecurity researcher Patrick Garrity! Patrick Garrity is a seasoned security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors. In this episode they discuss the importance of integrating threat intelligence into vulnerability management using the Exploit Prediction Scoring System (EPSS), CISA Known Explo...

The False Claims Act and The DOJ's Civil Cyber Fraud Initiative with Julie Bracker 26.03.2024

In this episode, Jacob speaks with attorney Julie Bracker! Julie is the whistleblower attorney for both the Penn State University and Georgia Tech University FCA complaints. These complaints essentially allege the defendants misrepresented their compliance with NIST 800-171! They discuss the False Claims Act and the DOJ's Civil Cyber Fraud Initiative, and what federal contractors can do to avoid b...

CMMC and Security Compliance in Higher Education 20.03.2024

In this episode, Jacob speaks with a panel of information security experts from universities about CMMC and their experience preparing for it! They discuss security and compliance challenges at universities, the Penn State NIST 800-171 False Claims Act lawsuit, and much more! Here are some highlights from the episode: How universities are different from other types of organizations Different compl...

AI's Impact on Cybersecurity Risk with Dr. Raghuram Srinivas of MetricStream 01.03.2024

In this episode, Jacob talks to Dr. Raghuram Srinivas from MetricStream! They discuss the beginnings of AI, how it has evolved over time, and the risks and opportunities it presents to companies around the world! Raghuram is the Senior Vice President of Product Management at MetricStream. He is an AI expert and has worked in AI-focused roles at JPM Chase, KPMG, as well as the Watson Group at IBM....

Zscaler on FedRAMP and Zero Trust with Patrick Perry 05.12.2023

In this episode, Jacob talks to Patrick Perry from Zscaler. They discuss Zscaler's experiences navigating the FedRAMP and DoD Impact Level processes as well as Zero Trust! Pat is a cybersecurity expert with over 20 years of experience. He currently works at Zscaler as Field CTO and is responsible for the alignment of Zscaler capabilities to the DoD and IC mission sets in order to provide dynamic,...

Cyber Security Questionnaire Essentials with Derrich Phillips of Aspire Cyber 28.11.2023

In this episode Jacob speaks with Derrich Phillips from Aspire Cyber about best practices and tips when filling out cybersecurity questionnaires. Derrich Phillips is a cybersecurity expert with over 20 years of experience in the field. He started his career in the Army's security operations center, defending networks against cyber attacks. As the founder of Aspire Cyber, he focuses on helping smal...

Behind the Curtain of Federal Rulemaking with Shauna Weatherly of FedSubK.com 18.11.2023

In this episode Jacob speaks with Shauna Weatherly from FedSubK.com . Shauna recently retired from the federal government after serving more than 35 years in the federal acquisition / contracting space! During her career she served as chief of contracting, contracting officer representative, and as an advisor to the Civilian Agency Acquisition Council (CAAC). She even has direct experience in the...

Cloud Security & DFARS 7012 Compliance with Michael Greenman from Deltek 02.11.2023

In this episode Jacob speaks with Michael Greenman from Deltek. Michael has worked in government and cloud-based technology for over 20 years, and currently works at Deltek in the Product Strategy group and is the evangelist for cybersecurity compliance and cloud services! Michael shares Deltek's perspective on security and compliance as a cloud service provider. Here are some highlights from the...

CMMC Insights with Redspin Assessor Thomas Graham 23.10.2023

In this episode Jacob speaks with Dr. Thomas Graham who is a CMMC assessor. Thomas is the Vice President and CISO at Redspin, and Redspin is the first CMMC Third Party Assessor Organization (C3PAO)! This episode has a lot of great information for the defense industrial base! Here are some highlights from the episode: Redspins' experience becoming the first C3PAO Notable changes in NIST 800-171 r3...

CMMC Rulemaking with Jacob Horne 22.09.2023

In this episode Jacob Hill talks with Jacob Horne from Summit 7! Jacob Horne is Summit 7's Chief Security Evangelist, and has a unique genetic superpower that allows him to delve into NIST publications & government regulations without experiencing even a hint of boredom! In the episode Jacob Horne explains the history leading up to the CMMC program, when CMMC may be required, and the significance...

Talking Cybersecurity with Dr Ron Ross of NIST 01.09.2023

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the final of a three-part series with Dr. Ross. In the episode Dr. Ross shares his thoughts on topics like ChatGPT, zero trust, his top 5 security controls, advice to folks new to cybersecurity, and much more! Here are some key topics we discussed: Top challenges in federal cybersecurity compliance How to enable positive cybersecurit...

NIST 800-171 r3 August 2023 Status Update with Dr Ron Ross 14.08.2023

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 2nd of a three-part series with Dr. Ross. In the episode Dr. Ross shares a status update on NIST 800-171 revision 3. At the time of this recording, NIST has released the 1st initial draft, and the 1st public comment period has closed. Here are some key topics we discussed: Notable changes in NIST 800-171 r3 Thoughts on public com...

NIST Cybersecurity History with Dr Ron Ross 11.08.2023

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 1st of a three-part series with Dr. Ross. In the episode Dr. Ross shares the fascinating history of NISTs involvement in cyber security! Here are some key topics we discussed: How he started at NIST and the projects he has worked on NIST's and the Joint Task Force's Mission How he convinced the DoD to transition from DIACAP to RM...

Securing the Oil and Gas Industry with Industrial OT Cybersecurity Expert Joseph Loomis 22.07.2023

In this episode Jacob talks with operational technology (OT) cybersecurity expert Joseph Loomis! Joseph is the President of Secrabus Inc where he performs cybersecurity assessments on Oil & Gas companies to help elevate their security posture and protect their critical assets. Joseph shares his experiences after more than 15 years in the Oil & Gas industrial control system (ICS) and OT cybersecuri...

From Aircraft Maintenance to GRC and Cybersecurity with Jonathan Fisher 22.06.2023

In this episode Jacob talks with GRC professional Jonathan Fisher. Jonathan shifted into the GRC field after 20 years in the military supporting aircraft maintenance, and explains how others can do the same! Here are some key topics we discussed: What GRC is How he transitioned into GRC and cybersecurity How nontechnical folks can transition into cybersecurity by starting in a GRC role How most fo...

Privacy Laws and GRC with Attorney Donata Stroink-Skillrud 14.06.2023

In this episode Jacob speaks with privacy attorney Donata Stroink-Skillrud. Donata is the chair of the American Bar Association’s ePrivacy committee, and has an excellent understanding of privacy laws in the US and the EU. She shares the impact of US and EU privacy laws on businesses, how they can plan to comply, and much more! Here are some key topics we discussed: The importance of privacy laws...

Insights from CMMC Consultant and Assessor Koren Wise 09.06.2023

In this episode Jacob speaks with Koren Wise who is a highly experienced CMMC consultant, assessor, and instructor. Koren offers insights from her experience helping companies prepare for CMMC, and gives advice on hiring the right CMMC consultant and assessor for your business - and much more!. Here are some of the topics we discussed: How she got to where she is today Common misconceptions busine...

Listen to the GRC Academy podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.