People Don't Scale: Tamelia Hutchinson on the 40 Year "Fad" of GRC Engineering

People Don't Scale: Tamelia Hutchinson on the 40 Year "Fad" of GRC Engineering

Source: YouTube · GRC Engineering Club · published Aug 1, 2026 · 41:24

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

GRC engineering is not a fad but a necessary evolution toward automation and system maturity, requiring professionals to bridge the gap between technical security and business value through effective communication and change management 2:15.

Key Takeaways:
• GRC engineering involves both process and technical aspects, with the core goal being the automation of compliance and risk assessment to reduce manual toil 1:31.
• Automating bad processes only accelerates failure; therefore, organizations must first mature their processes before implementing software solutions 3:26.
• Successful transformation requires "shepherding" stakeholders through change, using tangible internal proof-of-concepts to build trust and demonstrate value 7:15.
• Professionals must avoid the "curse of knowledge" by translating security benefits into business value, ensuring decision-makers understand the ROI rather than just the technical features 16:46.
• The ultimate goal of GRC maturity is to build systems so robust and automated that they scale without relying on individual human intervention, effectively making the specialist's role obsolete in routine operations 30:50.

Building scalable GRC systems requires humility, active listening, and a focus on business outcomes over technical prestige to drive sustainable adoption.

Sources:

  • 2:15 Definition of GRC engineering and its cyclical nature.
  • 3:26 Risks of automating flawed processes.
  • 7:15 Strategies for change management and adoption.
  • 16:46(http

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome friends to another edition of the anti-checkbox podcast. Fighting through rain, sleet, and snow. We're like the US Postal Service here. My guest as well as I just came out on the other side of this. So, wild by Mother Nature is is not playing games midsummer. Reminds me of those those summers in Puerto Rico at least personally for me, right? Where the weather can be absolutely bananas. Get want to get right into it. Timalia Hutchinson, please introduce yourself. Let the folks know and and and we'll we'll get right into it, please. >> Hello. My name is Timalia Hutchinson. I have been in security and compliance initially accidentally and then on purpose for about 20 years. It's been an up and down and interesting ride. Thank you for having me. >> Of course. Thank you so much for for …