Doing the little things right
Featuring
Drew Danner
Drew Danner, Managing Director at BD Emerson, joins us to challenge the age-old security vs. compliance divide. With a military background and a straight-talking approach, Drew shares why getting the small things right can make the biggest difference. Practical, grounded, and full of sharp insights—don’t miss this one.


Doing the little things right
Doing the little things right
Drew Danner, Managing Director at BD Emerson, joins us to challenge the age-old security vs. compliance divide. With a military background and a straight-talking approach, Drew shares why getting the small things right can make the biggest difference. Practical, grounded, and full of sharp insights—don’t miss this one.


Description
In this episode, Drew Danner uncomplicates GRC and stresses the importance of “keeping it stupid and simple.” Drawing from his experiences in both the army and cybersecurity, he shares easy and practical tips for building a sustainable security program.
Drew emphasizes the importance of doing the “little things” in GRC. He highlights how small, consistent actions—like reviewing contracts and integrating compliance into daily operations—can drive meaningful change and prevent last-minute crises.
Tune in to hear his insights on bridging the gap between compliance and security, navigating intimidating frameworks, and how early attention to security can help companies win customer trust and build stronger businesses.
Highlights from the episode
- Pro tips for companies that are getting started with compliance
- The simplicity of building effective security controls
- The evolving nature of security audits in the age of AI
“You don’t need a certificate to do the right thing. Start with the basics.”
About the Risk Grustlers Podcast
Risk Grustlers is a podcast for people working in security, risk, and governance who want sharper conversations than the usual industry soundbites. Each episode features CISOs, security leaders, and risk practitioners sharing how they think through the real operational challenges behind cybersecurity, compliance, AI governance, and enterprise risk.
Hosted by Aayush Ghosh Choudhury (CEO and Co-founder of Scrut Automation) and Nicholas Muy (CISO at Scrut Automation), this podcast series focuses on practical lessons, hard-earned perspectives, and the nuance that comes only from years spent in the security and compliance space.


























