Risk Grustlers / Episode #14

Doing the little things right

featuring Drew Danner, Managing Director, BD Emerson

In this episode, Drew Danner, Managing Director at BD Emerson, offers a new take on the old security vs. compliance debate—they’re one and the same. With ten years in the army and a no-nonsense approach to cybersecurity, he’s been in the trenches (literally and figuratively) and is a go-to professional for all things security. So grab a coffee and a notepad, because this conversation is packed with insights you won’t want to miss. Tune in now!

“Security is the operation of achieving compliance.”

“Consistency, that’s what it’s all about. Doing the little things right, every single time.”

“The easiest security controls can have the biggest impact if you just do them right.”

“You don’t need a certificate to do the right thing. Start with the basics.”

Listen on
Your favourite platforms

Description

In this episode, Drew Danner uncomplicates GRC and stresses the importance of “keeping it stupid and simple.” Drawing from his experiences in both the army and cybersecurity, he shares easy and practical tips for building a sustainable security program.

Drew emphasizes the importance of doing the “little things” in GRC. He highlights how small, consistent actions—like reviewing contracts and integrating compliance into daily operations—can drive meaningful change and prevent last-minute crises.

Tune in to hear his insights on bridging the gap between compliance and security, navigating intimidating frameworks, and how early attention to security can help companies win customer trust and build stronger businesses.

Highlights from the episode

More Episodes

Derek Kalles & Glen Willis
Kalles Group
Episode #1
Strategies to Master Cloud Security
Davis Hake
Co-Founder of Resilience
Episode #1
Fancy some acronym soup, mate?
Vignesh Kumar
Manager of Security and Privacy at Microsoft
Episode #2
Do Auditors Have Horns?
Walter Haydock
CEO of StackAware
Episode #3
AI With a Pinch of Responsibility
Gary Hunter
Cybersecurity at The Walt Disney Company
Episode #4
Back to Basics: A Crash Course for Experts!
Ross Haleliuk
Head of Product at LimaCharlie
Episode #5
De*Romanticizing the Cybersecurity Complexity
Satya Nayak
Head of Security Engineering & Operations at Outreach
Episode #6
Are You YAFing, Bud?
Renae Martin
Senior Technical Program Manager
Episode #7
The Process of Setting Up A Process To Set Up A Process
Jason Leuenberger
Team Coach
Episode #8
A Scoop of Risk, Squishy Not Crunchy!
Akshay Ahuja
Principal - Information Security
Episode #9
The Art of Breaking Into the Security Space
Shashank Karincheti
Senior Manager - Razorpay
Episode #10
The Perks of Automating Audits
Joshua Zweig
Zip Security
Episode #2
Cracking the Cyber Code with Evolving Perspectives of Cybersecurity
Beau Butaud
Risk and Compliance Manager at Moss Adams
Episode #3
Compliance Beyond the Checkbox: A Fresh Perspective on Auditors and Risk
Farshad Abasi
Founder and CEO of Forward Security
Episode #4
Cyber Roulette: Playing with Digital Risks
Aaron Wurthmann
CIO & CSO at Spire One
Episode #12
Security: Building a Business Within a business
Todd Dekkinga
CISO at Scrut Automation and Zluri
Episode #11
The Upshot of (Un)continous Compliance
Kevin Qiu
Security Expert at Tech Startups
Episode #13
Security on a shoestring budget

See Scrut in action!