Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Hilton
Brad Morick, Senior Director, GRC and Reporting - Cybersecurity
Third-Party Risk Management in the GRC Space

What are some of the latest challenges and trends in the industry?
One of the most significant trends and opportunities in the marketplace, particularly in GRC (Governance, Risk, and Compliance), is identifying and hiring diverse talent. This involves seeking individuals from all walks of life with varying ethnicities, backgrounds, genders, and career paths. My journey into the field was atypical for a cybersecurity professional, as I came from an audit background. Working with the GRC team at Hilton, I realized the immense advantage of having a team with diverse backgrounds and traits.
A diverse team allows us to challenge each other in a constructive manner and explore new opportunities while viewing issues and risks through various lenses that an undiverse team might overlook. By collaboratively considering multiple perspectives, we can effectively mitigate risks across the organization, which would not have been achievable through a singular point of view. This inclusivity fosters innovation and creativity, leading to better decision-making and improved solutions for the challenges we face in the cybersecurity and GRC landscape.
Could you share some technological trends you notice in the GRC space?
The GRC marketplace offers various platforms, each catering to different needs. From service management platforms to point solutions and audit tools, a diverse array of platforms serve the GRC space, each with niche capabilities. However, the challenge with these platforms lies in the fact that they often retain their original purposes.
For instance, service management platforms tend to focus primarily on delivering service management capabilities, while audit platforms that attempt to cater to cyber GRC remain rooted in serving the audit marketplace rather than the specific needs of the cybersecurity landscape.
Since no two organizations' needs are alike, what works well for one may not be the ideal fit for another. Making the wrong choice in selecting a GRC platform can lead an organization down the wrong path and result in inefficiencies and missed opportunities for effective governance, risk management, and compliance. It is essential to thoroughly assess the capabilities and limitations of each platform and ensure it can adequately address the unique requirements to avoid potential pitfalls and maximize the benefits of a well-suited GRC solution.
Can you talk about any recent project initiative you have been part of?
Over the past year, we focused on third-party risk management, specifically on cyber third-party risk. However, as we delved deeper, we recognized that cyber risk is just one component of the broader third-party risk management process. To address this comprehensively, we collaborated with risk management partners from various departments, including legal, finance, and ESG. Together, we worked towards a typical process solution and identified a shared platform to collectively address third-party risk.
By taking this collaborative approach, we achieved efficiency in monitoring our third-party relationships from multiple perspectives. This ensures that no single risk takes precedence over another, and we can effectively manage and mitigate risks across the entire spectrum. At Hilton, we now have a holistic overview of third-party risks, empowering us to make informed decisions encompassing the entire risk landscape.
Inclusivity fosters innovation and creativity, leading to better decision-making and improved solutions for the challenges we face in the cybersecurity and GRC landscape.
How do you envision the future of GRC space a couple of years down the line?
Over the past couple of years, there has been a growing focus on third-party risk. Organizations are coming together to develop a common framework that goes beyond the commonly used frameworks in highly regulated industries like financial institutions. Although the hospitality industry is different from financial institutions, it requires a distinct approach and level of rigor in addressing cyber risk. Industry-wide discussions are underway to define the appropriate cyber risk framework, enabling companies that do business with hospitality companies to have standardized controls in place and simplifying the process for their partners.
What is your piece of advice to your fellow peers?
Although cyber professionals are highly technical and often have great ideas and solutions, they are not commonly found in the GRC space. However, having diverse opinions and insights on technological solutions is incredibly valuable in the GRC domain. This diversity ensures that the solutions implemented are well-rounded and well-thought-out.
In today's thriving cybersecurity space, more individuals from various backgrounds are attracted to the field. People from all walks of life are adding value in unexpected ways. For instance, one of my team members is a former nurse practitioner who transitioned into the cyber field. Her perspective and experiences from the front lines of healthcare have provided our team with invaluable insights that we, as traditional cyber professionals, might never have considered.

