{"id":87,"date":"2026-05-05T22:16:05","date_gmt":"2026-05-05T22:16:05","guid":{"rendered":"https:\/\/student.wp.odu.edu\/rblac007\/?page_id=87"},"modified":"2026-05-05T22:16:05","modified_gmt":"2026-05-05T22:16:05","slug":"governance-risk-and-compliance-grc-analyst-in-cybersecurity","status":"publish","type":"page","link":"https:\/\/student.wp.odu.edu\/rblac007\/governance-risk-and-compliance-grc-analyst-in-cybersecurity\/","title":{"rendered":"Governance, Risk, and Compliance (GRC) Analyst in Cybersecurity"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">BLUF<\/span><\/h2>\n\n\n\n<p>Cybersecurity is not just technical\u2014it is behavioral. In a GRC role, most risk comes from how people think, act, and make decisions. Social science concepts like human behavior, risk perception, and organizational culture directly shape how security actually works.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Introduction<\/span><\/h2>\n\n\n\n<p>Cybersecurity is often viewed as technical, but that is only part of it. The career I am focusing on is a GRC Analyst, which aligns with my goals in cybersecurity. This role focuses on managing risk, enforcing compliance, and making sure systems are secure and accountable.<\/p>\n\n\n\n<p>From my labs and research, most security failures come from people, not systems. This paper explains how social science concepts apply to a GRC role and how they show up in real work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><u>Social Science Principles in Cybersecurity<\/u><\/strong><\/h2>\n\n\n\n<p>The biggest factor in cybersecurity is human behavior. Research shows that \u201c95% of all cyber incidents are human-enabled\u201d (Nobles, 2018, p. 71) . That means users, not systems, are the main risk.<\/p>\n\n\n\n<p>In GRC, this impacts everything. If systems are too complex, users bypass them. If training is weak, users make bad decisions. Policies must be built around how people actually behave.<\/p>\n\n\n\n<p>Another key concept is organizational culture. If leadership does not prioritize security, employees will not either. Culture drives compliance more than tools.<\/p>\n\n\n\n<p>There is also technological determinism\u2014the idea that companies rely too much on tools to fix problems. Nobles (2018) makes it clear that technology alone will not solve human error . In GRC, behavior must be addressed along with technology.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><u>Application of Key Concepts<\/u><\/strong><\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Risk Perception <\/h2>\n\n\n\n<p>Organizations prioritize security based on risk. GRC analysts assess impact and likelihood to decide what matters most.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Human Behavior and Social Engineering <\/h2>\n\n\n\n<p>Most attacks target people. Phishing and scams rely on human psychology. GRC responds with training and policy enforcement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Theory of Planned Behavior <\/h2>\n\n\n\n<p>People act based on what they understand and believe. Employees are not trying to cause harm\u2014they are trying to do their jobs. Many mistakes come from normal decision-making under pressure (Nobles, 2018).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Compliance and Social Order<\/h2>\n\n\n\n<p>Frameworks like HIPAA and GDPR exist to protect people. GRC ensures organizations follow these expectations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Human Factors <\/h2>\n\n\n\n<p>Human error is a major risk. GRC identifies these risks and builds controls to reduce them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Marginalization<\/h2>\n\n\n\n<p>Cybersecurity affects groups differently. Some are more vulnerable than others.&nbsp; Research shows that \u201cmarginalized communities are disproportionately vulnerable to cybersecurity threats\u201d (Chattopadhyay et al., 2024, p. 1) .&nbsp; One issue is limited access to secure technology. Not everyone has updated systems or strong protections.<\/p>\n\n\n\n<p>Another issue is recovery. These groups are \u201cless able to recover from attacks such as identity theft [and] financial loss\u201d .&nbsp; A third issue is lack of focus in research. Only about 0.2% of cybersecurity studies include marginalized groups .&nbsp; In GRC, this matters because policies should protect everyone. If they do not account for different groups, they fail.<\/p>\n\n\n\n<p>From a GRC standpoint, this means policies, training, and controls have to be designed with these gaps in mind so security is not just applied, but applied fairly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Career Connection to Society<\/span> <\/h2>\n\n\n\n<p>Cybersecurity supports critical systems like healthcare and finance. When security fails, real people are affected.\u00a0 Compliance frameworks tie security to law, ethics, and trust. GRC ensures organizations meet these expectations.\u00a0 Modern systems also require real-time risk management and response. This shows how the role continues to evolve.\u00a0 GRC professionals help maintain stability and trust in society by keeping systems secure and accountable.\u00a0 At the same time, as society becomes more digital, cybersecurity demands increase, which forces organizations to constantly adapt how they manage risk and compliance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Conclusion <\/span><\/h2>\n\n\n\n<p>A GRC cybersecurity role is not just technical. It depends on understanding people, behavior, and decision-making.\u00a0 Technology alone is not enough. Human behavior drives most risk.\u00a0 Social science concepts like human factors, risk perception, and organizational culture are part of the foundation of cybersecurity. GRC connects these concepts to real-world security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">References<\/span><\/h2>\n\n\n\n<p>Chattopadhyay, A., Carvajal, R., Chaganti, V., &amp; Venkatagiri, S. (2024). <em>Where are marginalized communities in cybersecurity research?<\/em> USENIX Symposium on Usable Privacy and Security (SOUPS).<\/p>\n\n\n\n<p>Hasan, M., &amp; Faruq, M. O. (2025). <em>AI-augmented risk detection in cybersecurity compliance: A GRC-based evaluation<\/em>. ASRC Procedia.<\/p>\n\n\n\n<p>Nobles, C. (2018). <em>Botching human factors in cybersecurity in business organizations<\/em>. HOLISTICA, 9(3), 71\u201388. https:\/\/doi.org\/10.2478\/hjbpa-2018-0024<\/p>\n\n\n\n<p>Ugoaghalam, U. J., Salami, E. O., &amp; Enyejo, L. A. (2025). <em>Real-time policy orchestration for cybersecurity risk management in fintech infrastructures<\/em>. International Journal of Innovative Science and Research Technology.<\/p>\n\n\n\n<p>Urhobo, B. (2024). <em>Understanding the role of artificial intelligence in enhancing GRC practices in cybersecurity<\/em>. World Journal of Advanced Research and Reviews.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"> <\/h2>\n","protected":false},"excerpt":{"rendered":"<p>BLUF Cybersecurity is not just technical\u2014it is behavioral. In a GRC role, most risk comes from how people think, act, and make decisions. Social science concepts like human behavior, risk perception, and organizational culture directly shape how security actually works&#8230;. <a class=\"more-link\" href=\"https:\/\/student.wp.odu.edu\/rblac007\/governance-risk-and-compliance-grc-analyst-in-cybersecurity\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":32119,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/87"}],"collection":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/users\/32119"}],"replies":[{"embeddable":true,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/comments?post=87"}],"version-history":[{"count":1,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/87\/revisions"}],"predecessor-version":[{"id":88,"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/pages\/87\/revisions\/88"}],"wp:attachment":[{"href":"https:\/\/student.wp.odu.edu\/rblac007\/wp-json\/wp\/v2\/media?parent=87"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}