Kickoff: Your First GRC Meeting
45 minutes, no clause numbers, and 4 things that actually change for the person listening.
// @18xBan · GRC Series · Chapter 16
4 questions. Everything else is your homework, not theirs.
The sentence at the end of the March review
The management review is nearly over when Maya says the thing that makes the next 2 weeks:
"This is good. But everyone outside this room has never heard any of it."
She's right, and it's uncomfortable. Wayne has a policy set, a risk appetite statement, a decision rights table, 6 measures and a review cadence. All of it lives with 5 people. The engineers who deploy to production, the support team who touch customer data every day, the sales people answering security questions in calls none of them have been told anything, except that Priya now needs a second approver on merges.
A programme that lives in leadership minutes works until it needs somebody else to do something. Then it stops.
So you get 45 minutes at the all-hands. And the first draft of that 45 minutes is where most security programmes get their reputation.
5 people have been living this. Everyone else hasn't heard a word.
The version that fails
Your first outline has 34 slides. It opens with what GRC stands for. Slide 6 is the ISO 27001 clause structure. Slide 11 is the CIS Controls v8.1 Implementation Groups. There's a maturity chart around slide 20.
You run it past Priya as a favour. She's honest about it: "This is a lecture about your job. What do you want me to do differently?"
That's the whole test, and the deck doesn't answer it until slide 29.
The unpopular truth: nobody outside security cares about your framework. They care whether their work is about to get slower, whether they're being watched, and who to ask when they're stuck. Answer those 3 and you can teach the rest over the next year.
"This is a lecture about your job." 34 slides, one useful one.
What the standards actually want from this meeting
Less than the 34 slides, and more than a memo.
ISO 27001 Clause 7.3 asks that people are aware of the policy, their contribution to the effectiveness of the ISMS, and the implications of not conforming. 3 things. Not the clause structure.
Clause 7.4 asks you to determine what to communicate, when, with whom, and how. Deciding who gets which message is itself the requirement.
Annex A 6.3 covers awareness, education and training, and CSF GV.RR-02 wants roles and authorities understood and enforced understood being the word that turns a document into a meeting.
If you want the full design of a learning programme, NIST published SP 800-50 R1, Building a Cybersecurity and Privacy Learning Program, in September 2024. It's free, it folds privacy in alongside security, and it treats awareness as a life cycle with measurement rather than an annual video.
https://csrc.nist.gov/News/2024/nist-publishes-sp-800-50-revision-1
For a first kickoff, the useful part is its basic distinction: awareness changes what people notice, training changes what they can do, education changes how they think. A kickoff is awareness. Don't try to make it training.
The 45 minutes
| Minutes | Section | What it does |
|---|---|---|
| 0–2 | Maya opens | 2 minutes from the CEO beats 20 from security |
| 2–7 | Why now | The Gotham contract, in plain numbers. No fear, no statistics |
| 7–17 | Where we actually were | 3 real Wayne findings, told without blame |
| 17–27 | What changes for you | 4 things, split by team |
| 27–34 | Who to ask, and how fast | The decision table, the security inbox, office hours |
| 34–39 | What we are not doing | The trust section. Do not skip it |
| 39–45 | Questions | Every question gets logged, even the ones you can't answer |
3 rules for the room:
No clause numbers on slides. Not one. They're in the policy set if anyone wants them, and they make everything sound like homework.
Use your own stories, not industry statistics. "A production database export was sitting in a bucket anyone on the internet could read, and we found it because a customer asked a question" lands harder than any breach-cost figure, and nobody can argue with it.
Tell the stories without blame. The bucket wasn't Priya's fault. It happened because nobody had decided who was allowed to make a bucket public. If a single person in the room feels blamed, half the room stops volunteering information for a year.
45 minutes, 7 blocks, and the one people remember is at minute 34.
"What changes for you" : 4 things, not 40
The temptation is to explain the whole policy set. Instead, each team gets the short version of what actually touches them.
| Team | What changes |
|---|---|
| Engineering | A second approver on merges to main; production access is requested, approved by Priya, and expires; new vendors and SDKs get checked before customer data goes near them |
| Support | Customer data stays in the product and the ticket system; no exports to spreadsheets; if a customer sends you credentials, tell them to rotate them |
| Sales | Security questions get answered from the standard answers file, not invented on a call; commitments in contracts need Dan's sign-off |
| Everyone | MFA on everything; 4 documents to read, assigned by role; report anything odd to the security inbox, and you'll never be told off for a false alarm |
And the section that buys you credibility for the year:
What we are not doing: no keystroke logging. No reading your personal messages. No blocking tools without talking to the team that uses them. No making you read 40 policies you have 4, and they're short. No punishing people who report mistakes; the only thing that gets someone in trouble is hiding one.
Say it out loud, with the CEO in the room, and let people hold you to it.
4 things per team. One list of what you're not doing.
The 3 questions you will definitely get
Rehearse these, because they arrive in every kickoff.
"Is this going to slow us down?" The honest answer is: sometimes, by minutes, and there's a path when it matters. Then tell the SDK story customer emails heading to a vendor, resolved in 2 minutes with 3options, shipped the same day. A named exception path with a time limit is more persuasive than any promise.
"Are you watching us?" Answer with scope, not reassurance. Wayne logs what happens in production systems and on company accounts, keeps it for a defined period, and reads it when something looks wrong or when an investigation is authorised. Nobody is watching browsers or personal devices. Say where it's written down.
"Do I have to read all the policies?" No. 4 documents, assigned by role, and each is a couple of pages. That answer only works because of the cull in the policy set 13 live documents instead of 40 is what makes this promise keepable.
The 3 questions that arrive in every kickoff. Rehearse them.
Pre-work: no surprises in the room
The kickoff is the visible part. The work is in the week before.
Brief the leads individually. Priya, Farah and the support lead each get fifteen minutes before the all-hands. Anything they'd object to publicly, you want to hear privately first.
Ask Maya to open. 2 minutes, her words, about why the company is doing this. If leadership doesn't open it, the room reads it as a security-team project.
Test it on one sceptic. Priya was the right choice precisely because she pushes back.
Fix the 4 documents first. Don't announce role-based reading if the role-based assignment doesn't exist yet.
Book the follow-ups before the meeting. 15 minutes per team, the following week, where the real questions get asked.
2 minutes from the CEO, then 43 that answer "what about me?"
After the room: the 48 hours that decide whether it stuck
Within 2 days, everyone gets one short message: what was said, the 4 things per team, the link to their assigned documents, the security inbox address, and the questions that came up including the ones you couldn't answer, with a date for the answer.
Then the per-team sessions. That's where the actual questions live, because people don't ask "can I use my personal laptop for a customer demo?" in front of 40 colleagues.
Wayne's question log from the kickoff has 11 entries. 3 were answered in the room. 6 got answered in the follow-up notes. 2 needed a decision: one about contractor laptops, one about a support tool that stores ticket attachments outside Canada. The second one turns into a real piece of work.
That second question is the quiet win. Somebody in support knew about a data-residency problem that no assessment had found, and they mentioned it because a kickoff made it look like the kind of thing worth mentioning.
The unpopular truth: the most valuable output of a kickoff isn't what you tell people. It's what they tell you afterwards, and you only get that if the meeting made it safe to speak.
Keeping it as evidence
Awareness is one of the easiest requirements to satisfy and one of the most commonly failed, because nobody keeps the record.
# awareness-record.py — who attended, who has what to read, who's acknowledged
ROLE_DOCS = {
"engineering": ["InfoSec Policy v1.0", "Acceptable Use v2.1",
"Secure Development v1.0", "Endpoint Standard v1.0"],
"support": ["InfoSec Policy v1.0", "Acceptable Use v2.1",
"Data Classification v1.0", "Endpoint Standard v1.0"],
"sales": ["InfoSec Policy v1.0", "Acceptable Use v2.1",
"Data Classification v1.0", "Vendor Management v1.0"],
}
ATTENDED = {"session-1": 96, "session-2": 71, "recording": 24}
ACK = {"engineering": (38, 41), "support": (22, 27), "sales": (14, 19)}
print(f"Attended live: {ATTENDED['session-1'] + ATTENDED['session-2']}, "
f"recording: {ATTENDED['recording']}")
for team, docs in ROLE_DOCS.items():
done, total = ACK[team]
flag = "" if done == total else f" <-- {total - done} outstanding"
print(f"{team:<12} {len(docs)} documents acknowledged {done}/{total}{flag}")
Attended live: 167, recording: 24
engineering 4 documents acknowledged 38/41 <-- 3 outstanding
support 4 documents acknowledged 22/27 <-- 5 outstanding
sales 4 documents acknowledged 14/19 <-- 5 outstanding
Sample output (illustrative). Wayne Industries is fictional.
13 outstanding acknowledgements is a normal two-week number, and it's a list Farah can chase. What matters is that it's countable which is the whole difference between "we ran a session" and evidence.
Attendance, materials, questions, acknowledgements. 4 things, kept once.
Evidence #16
The deck and the speaker notes, versioned and dated.
Attendance for both sessions, plus recording views.
The question log: 11 questions, who answered, when, and the two that became work items.
Role-based document assignments and acknowledgement status per team.
The follow-up message, with the 4 asks per team and named owners.
The next awareness date, so this isn't a one-off.
Evidence #16: people were told what's expected of them, in a way that can be shown, counted and repeated.
"We ran a session" isn't evidence. Attendance, questions and acknowledgements are.
What an auditor accepts vs rejects
| Accepted | Rejected |
|---|---|
| Dated materials with attendance records | "We covered it at an all-hands" |
| Role-based content, with who got what | One deck for everyone, with no assignment |
| Acknowledgements tied to document versions | A signature sheet with no versions |
| A question log with follow-up dates | No record of what was asked |
| A schedule: kickoff, then recurring awareness | A single session, never repeated |
| Evidence the message reached joiners since | Nothing for anyone hired after the session |
What you actually do on Monday
Write the 4 things per team first, before you open a slide deck.
Cut every clause number out of the material.
Pick three of your own findings to tell, without naming anyone.
Write the "what we're not doing" list and check it with your CTO.
Get the CEO to open it, even for two minutes.
Rehearse the three questions and give the honest answer to each.
Log every question, including the ones you fumble.
Send the follow-up in 48 hours and book the per-team sessions.
Framework mapping
Awareness and communication, as each framework asks for it.
Maturity ladder
| Stage | 20 people | 200 people | 2,000 people |
|---|---|---|---|
| The kickoff | One meeting, everyone in it | Two sessions plus a recording | Cascaded by department, with local owners |
| Content | One list of what changes | Role-based content per team | Role-based curricula tied to job families |
| Records | A calendar invite and a shared note | Attendance, acknowledgements, question log | A learning platform with completion reporting |
| Repetition | A reminder when something changes | Annual refresh plus onboarding | Continuous programme with measured behaviour |
| The trap | Never telling anyone | Telling everyone once | Measuring completion instead of behaviour |
At 20 people the kickoff is a 30 minute conversation and a shared document. It still counts, and it still needs a record.
Where Wayne sits: two sessions delivered, role-based documents assigned, 13 acknowledgements outstanding,11 questions logged, and 2 of them now on the work list. The next awareness touchpoint is scheduled rather than hoped for.
Cheatsheet
The kickoff, on one page.
The takeaway
Answer 3 questions before anything else: will this slow me down, are you watching me, who do I ask. Tell your own stories, without blame, and leave the clause numbers in the policy set. The "what we're not doing" list is the part people remember in 6 months. Keep the attendance, the questions and the acknowledgements that's the difference between a session and evidence.
⚠️ This content is for educational purposes only. Wayne Industries is a fictional company. Nothing here is legal, audit, or compliance advice, validate against your own auditor and jurisdiction.
