The Art of Cybersecurity

Cheri Hotman

Cybersecurity is as much art as science. The hard part is not knowing another framework or buying another tool. It is figuring out what actually matters, making good tradeoffs, and building security that works with real-world limits on time, budget, people, and technology. On The Art of Cybersecurity, Cheri Hotman explores the judgment, creativity, leadership, and practical problem-solving behind cybersecurity that actually protects the business. Expect candid conversations about cyber risk, Cyber GRC, governance, compliance, technology, audits, AI, leadership, and the messy reality of making

  1. 2d ago

    GRC Is Cybersecurity: Why Compliance Alone Isn’t Enough with Mea Clift

    What happens when organizations start treating compliance as the goal instead of using it as one piece of a stronger cybersecurity program? In this episode of The Art of Cybersecurity, Hotman Group CEO Cheri Hotman sits down with GRC leader and educator Mea Clift for a candid conversation about what governance, risk, and compliance (GRC) should actually look like in practice. Cheri and Mea dig into why passing an audit doesn’t necessarily mean an organization is secure, how risk should drive cybersecurity priorities, and why frameworks, tools, and maturity scores can create a false sense of security when they become the objective instead of the input. They also explore cybersecurity budgeting and return on security investment, vendor and technology decisions, what effective cyber leadership really requires, and the importance of trust, integrity, mentorship, and continuous learning in the profession. In this episode:• Why GRC is part of cybersecurity — not just compliance documentation• Compliance vs. actual security• Using risk to prioritize cybersecurity investments• Why “cheap, fast, and easy” doesn’t work in cyber• Communicating cybersecurity risk to business and financial leaders• What makes an effective cybersecurity leader• Building trust and integrity into cybersecurity programs• Developing the next generation of GRC professionals At its core, the conversation comes back to one idea: cybersecurity isn’t about checking the final box. It’s about continuously making better, risk-informed decisions and moving the organization forward. Learn more about Hotman Group at hotmangroup.com

  2. 12/12/2025

    From CPA to Cyber Leader: Seeing the Whole Business

    In this episode, Cheri Hotman sits down with Joe Kodali, a fellow CPA turned cybersecurity and GRC leader, to have a blunt, practitioner-level conversation about what is actually broken in modern cybersecurity programs and why compliance theater is making organizations less secure, not more. They unpack the unique value CPAs bring to cybersecurity, not because of accounting, but because of how auditors are trained to understand entire businesses, ask uncomfortable questions, and tie controls back to real risk and return on investment. From there, the discussion goes deep into the widening gap between executives and cyber teams, the failure of checkbox audits, and how GRC tools and low-quality SOC 2 practices have created a dangerous false sense of security. Cheri and Joe challenge the industry’s obsession with compliance over governance and risk, calling out poor scoping, copy-paste controls, and the misuse of frameworks that were never meant to be treated as templates. They also address the hard truth that tools do not fix broken programs, people and discipline do. The conversation closes with a candid discussion on why governance is the most overlooked and undervalued part of GRC, how boards should be asking better questions, and what it actually takes to build a cyber program that protects the business rather than just passing audits. This episode is required listening for CISOs, security leaders, GRC practitioners, auditors, and executives who want real security outcomes instead of green checkmarks.

Ratings & Reviews

4.7
out of 5
3 Ratings

About

Cybersecurity is as much art as science. The hard part is not knowing another framework or buying another tool. It is figuring out what actually matters, making good tradeoffs, and building security that works with real-world limits on time, budget, people, and technology. On The Art of Cybersecurity, Cheri Hotman explores the judgment, creativity, leadership, and practical problem-solving behind cybersecurity that actually protects the business. Expect candid conversations about cyber risk, Cyber GRC, governance, compliance, technology, audits, AI, leadership, and the messy reality of making