The Call That Started It All
“I can’t open any of my files.”
Those were the first words a client said to me one fall morning. Within an hour, we discovered why: a small California-based family advocacy and social services training provider had been hit by ransomware. Every file on the hard drive was encrypted. The ransom note demanded $7,200 in Bitcoin.
For a large enterprise, $7,200 is a rounding error. For this small nonprofit, it was a devastating hit to the bottom line.
That call — and the dozens like it I’ve fielded over three decades of consulting — is why this book exists. The organization hadn’t been targeted specifically. They’d simply left a door open, and an automated script found it. What they were missing wasn’t better technology. It was governance: the rules, habits, and ownership that keep a business protected without slowing it down.
Three Decades in the Trenches
I’ve spent more than 30 years in software engineering, IT infrastructure, and cybersecurity, and more than 20 years teaching cybersecurity, information assurance, cloud computing, and technology leadership at the university level. In between, I’ve advised organizations of every size — from small nonprofits to multi-million-dollar enterprise modernizations — through cybersecurity assessments, cloud migrations, and governance programs across both public and private sectors.
More than a decade ago, my doctoral research explored how enterprise architecture principles could be adapted for small and medium-sized businesses without importing the administrative complexity built for organizations twenty times their size. That question has shaped everything I’ve done since.
Why This Book Exists
Most GRC frameworks are written as if every business has a dedicated compliance department, an unlimited technology budget, and months to spend on paperwork. Small and medium-sized businesses don’t have any of that — and they don’t need to. The Pragmatic GRC Methodology™ strips enterprise governance down to what actually matters: three living documents, four implementation guides, and a habit that takes a few minutes a month to sustain.
The goal was never to create more paperwork. It’s to help business owners make better decisions, protect what they’ve built, and sleep a little easier.
Want to see the methodology in action?
Ready to put GRC into practice?
Connect with THE PRAGMATIC GRC METHODOLOGY™ to explore practical resources, implementation guidance, and next steps tailored for your business.