Companies
Eight briefs. Real artifacts waiting to be built.
Each brief has systems, regulatory exposure, relevant frameworks, risks, control priorities, audit concerns, vendor risk, BCP/DR concerns, and the analyst task to actually do.
Series-B observability platform with 180 employees, mostly remote engineers, processing customer telemetry in AWS.
Analyst task
You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.
Open brief →Regional integrated delivery network with 14 clinics and a shared EHR, recently completed a merger with a smaller group.
Analyst task
You inherited a half-finished HITRUST journey and a recent OCR inquiry letter. Sequence the next 60 days: which HITRUST controls do you close first, what do you send the OCR, and how do you get the post-merger combined entity onto one risk register?
Open brief →Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.
Analyst task
Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.
Open brief →D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.
Analyst task
Quantify the PCI scope question for the next QSA and write the internal page that walks finance through what is and is not in PCI scope at WovenCart.
Open brief →Mid-sized defense contractor with cleared personnel, handling Controlled Unclassified Information (CUI) and some ITAR data.
Analyst task
You are 90 days from a CMMC L2 assessment. Write the readiness plan and the briefing for the COO on what is at risk if any of the top three POA&M items slip.
Open brief →Online K-12 tutoring platform with 1.2M students across the EU, processing minors' data and special category data (educational records).
Analyst task
Plan the privacy program uplift before launching the new AI-recommendation feature. Produce the DPIA outline, the data-minimisation argument, and the parental-consent UX changes required.
Open brief →Industrial OEM with eight plants, 3,000 employees, and a recently acquired IT/OT convergence program.
Analyst task
You inherited an OT security program in its first year. Write the 12-month roadmap that justifies the spend to the plant managers — they do not care about frameworks, only uptime.
Open brief →Singapore-headquartered dev tooling company with 60 employees and enterprise customers in JP, AU, and SG.
Analyst task
You are the first GRC hire. Write the first 90 days for a one-person program: what do you build, what do you defer, and what gets you the most audit mileage first?
Open brief →