Go From Interested in Non-Coding Cybersecurity to Interview-Ready in 11 Guided Steps

Build professional Governance, Risk, and Compliance work samples. Learn the language of the field. Practice explaining and defending the decisions you make.

The GRC Portfolio Studio is a six-month coaching program for people preparing for Governance, Risk, and Compliance and other non-coding cybersecurity roles.

Why the format matters

Why Is It Called a Studio?

The word Studio is intentional.

A studio is a place where people create, practice, receive feedback, and improve their work. That is what you will do here.

You will not simply watch videos and take notes. You will work through the TechFlow Solutions business case, complete GRC assignments, revise your work, and build a connected professional portfolio.

The goal is not only to understand GRC concepts. The goal is to create work you can explain and defend.

The reasoning behind the work

What Interviews Actually Test

AI can produce a policy draft quickly. A draft alone does not show an employer how you think.

What still shows how you think is the reasoning underneath it. Which risk did you rank first, and why? Which control did you pick, and what tradeoff did you accept to pick it? Which supplier problem did you recommend accepting, and how did you explain that to a leader?

Those are the questions interviews turn on, and they are the ones this program prepares you to answer.

Every step ends the same way. You make the call, you write down your reasoning, and you practice explaining it.

You may be closer than you think

Does This Sound Familiar?

You may already have

  • A degree in cybersecurity
  • Security+ or the Google Cybersecurity Certificate
  • Experience in IT support, project management, teaching, healthcare, finance, or another professional field

You may still be wondering

  • What does GRC work look like?
  • How does my previous experience connect to the field?
  • What should I place in a professional portfolio?
  • How do I gain experience when employers want someone who has already done the work?
  • How do I explain what I can do during an interview?

The Studio helps you answer those questions by building the work, learning the language, and connecting your experience to GRC responsibilities. You receive coaching and feedback along the way.

The TechFlow journey

Your 11-Step GRC Implementation and Portfolio Path

The eleven steps follow one company from the day its security program starts to the day you stand in front of its leaders with results.

Steps 1 to 3 get the program started. Steps 4 and 5 find and rank the risks. Steps 6 to 8 decide what to do. Steps 9 to 11 prove it works and report to leadership.

NIST guidance is used throughout the Studio to help you understand TechFlow’s risks, controls, evidence, assessment, and improvement. You do not need previous experience with NIST before joining.

Part 1

Get the Program Started

01

Establish Governance, the Program Charter, and Leadership Approval

02

Define Scope, Business Context, and the Asset and Data Inventory

03

Conduct the Gap Analysis

Part 2

Find the Risks and Rank Them

04

Build the TechFlow Risk Register

05

Conduct the Third-Party and Vendor Risk Assessment

Part 3

Decide What TechFlow Should Do

06

Select Controls and Document Applicability Decisions

07

Design Policies, Procedures, and Evidence Requirements

08

Implement Controls, Access Reviews, and Security Awareness

Part 4

Prove It Works and Tell Leadership

09

Build Audit Readiness, Evidence, and Control Testing

10

Respond to Customer Security Questionnaires

11

Conduct the Internal Audit, Prepare the Management Review, and Track Remediation

One company, followed from start to finish. Eleven Decision Briefs showing what you found, what you considered, what you recommended, and the tradeoff you accepted.

The work, the call, and what you produce

What Happens in Each of the Eleven Steps

Step 1: Establish Governance, the Program Charter, and Leadership Approval

The work: governance structure, roles and responsibilities, the program charter, and everything leadership needs to approve it.

The call: who should own security risk at TechFlow, how much authority the program needs, and how far its reach should extend at the start.

Produces: an Information Security Program Charter covering scope, objectives, roles and responsibilities, oversight, and a first statement of what risk TechFlow will accept, prepared for leadership approval.

Step 2: Define Scope, Business Context, and the Asset and Data Inventory

The work: scoping, asset inventory, classifying health and financial data, and identifying the obligations that come with them.

The call: what belongs inside the program, and which customer and regulatory obligations follow from that choice.

Produces: a TechFlow Scope and Information Profile, and a Requirements Register naming each obligation and its owner.

Step 3: Conduct the Gap Analysis

The work: comparing where TechFlow stands against NIST guidance and what its customers expect.

The call: which gaps are real problems, which are symptoms of the same cause, and what to tackle first.

Produces: a Gap Assessment with a ranked short list and the reasoning behind the ranking.

Step 4: Build the TechFlow Risk Register

The work: risk method, risk identification, scoring likelihood and impact, and building the register.

The call: which risk ranks first, and on what basis.

Produces: the TechFlow Information Security Risk Register with a reasoning note on every entry.

After completing your own TechFlow risk assessment, you receive a 15-entry reference register with notes explaining the reasoning behind the scores, rankings, and recommendations. It arrives after your own work is done, so it serves as a comparison, not an answer key.

Step 5: Conduct the Third-Party and Vendor Risk Assessment

The work: vendor intake, risk tiering, sending security questionnaires, reviewing vendor audit reports, security terms in contracts, and ongoing monitoring.

The call: whether a supplier's security is good enough, and what to require when it is not.

Produces: a TechFlow Vendor Risk Assessment covering two suppliers at different risk levels, with a written recommendation for each.

The Challenge introduced this supplier as one short risk among several. Here, participants receive the full vendor file: the questionnaire, supporting evidence, the audit report, contract terms, and monitoring information. Then they decide whether the vendor is acceptable, and defend the call.

Step 6: Select Controls and Document Applicability Decisions

The work: choosing controls, mapping them across frameworks, and recording why each one applies or does not.

The call: which controls TechFlow needs, which it does not, and how to justify leaving anything out.

Produces: a Control Selection Matrix and a Control Applicability Record, with every row naming the option not chosen and why.

When ISO/IEC 27001 is discussed, participants learn how their control-applicability decisions support a Statement of Applicability and what additional information that document requires.

Step 7: Design Policies, Procedures, and Evidence Requirements

The work: choosing and tailoring the policy set, writing procedures, and deciding what evidence each control has to produce.

The call: which policies TechFlow actually needs, how strict each one should be, and what to leave out.

Produces: a Policy Selection Note and the tailored policy set. The selection note is the portfolio piece. Participants choose and adapt rather than writing from scratch.

Step 8: Implement Controls, Access Reviews, and Security Awareness

The work: sequencing implementation, running a user access review, and building the security awareness program.

The call: what happens first when everything cannot happen at once.

Produces: a Control Implementation Plan with sequence, owners, dates, and dependencies, a completed simulated access review, and a security awareness plan worked through as a scenario.

Step 9: Build Audit Readiness, Evidence, and Control Testing

The work: organizing the evidence, mapping it to controls, testing whether controls hold up, and answering auditor requests.

The call: how much evidence is enough, and whether a control is genuinely working.

Produces: an Audit Readiness Evidence Package with an evidence index and control test results, built from provided TechFlow case evidence.

Step 10: Respond to Customer Security Questionnaires

The work: completing customer security questionnaires, building a reusable answer library, and supporting sales conversations.

The call: how to describe TechFlow's security honestly when the honest answer is partial, and what evidence to share.

Produces: a completed customer security questionnaire and the answer library behind it.

This mirrors Step 5. Participants assess a supplier, then answer as one.

Step 11: Conduct the Internal Audit, Prepare the Management Review, and Track Remediation

The work: a simulated internal audit using the fictional case records, preparing the management review, tracking fixes, handling exceptions and risk acceptance, and reporting on compliance.

The call: which findings should be raised to leadership, which corrective actions should be recommended, and which remaining risks leadership should consider accepting.

Produces: an Internal Audit Report and a Management Review and Remediation Presentation, prepared for leadership.

The curriculum teaches that a real internal audit must be objective, and that people should not audit their own work without safeguards for independence. Leadership conducts the management review; the analyst prepares it.

Your reasoning, one step at a time

One Decision Brief for Every Step

Every step ends with a one-page Decision Brief in your own words:

  • What I found
  • What I considered
  • What I concluded and recommended

Each one also names what would make you change your mind, because a good analyst knows what new information would send them back to the drawing board.

By the end you have eleven of them. They turn a folder of documents into a record of how you think, and they become your interview answers, already written down.

One company, followed from start to finish

What You Will Do at TechFlow, From First Day to Final Report

The eleven steps follow one company from the day its security program starts to the day you stand in front of its leaders with results. Here is the work, in four parts.

01

Get the program started. Help TechFlow win leadership approval, work out who owns what, set the boundaries of the program, find the rules the company has to follow, and decide which gaps need attention first.

02

Find the risks and rank them. Look inside the company and at its suppliers, decide which risks matter most, and explain why you put them in that order.

03

Decide what TechFlow should do. Choose the controls the company needs, decide which policies actually fit it, and work out what should happen first given the money, the risk, and what the business can absorb.

04

Prove it works and tell leadership. Decide what evidence is enough, test whether the controls hold up, answer customer security questions honestly, and bring leaders the findings, the risks you recommend they accept, and the fixes you recommend they fund.

One company, followed from start to finish. Eleven Decision Briefs showing what you found, what you considered, what you recommended, and the tradeoff you accepted.

The analyst and leadership relationship

What You Decide, and What Leadership Decides

You work as TechFlow's Governance, Risk, and Compliance analyst.

At the start, leadership approves the program, hands over authority, and names who is responsible. You prepare what they need to make that call.

At the end, leadership reviews your findings, approves the fixes, and decides which remaining risks the company will live with. You bring the recommendation and the reasoning behind it.

Knowing where your authority stops is part of the profession, and it is something interviewers ask about.

Start with one live weekend

How the Risk Register Weekend Challenge Connects to the Studio

ONE RISK CASEFind, rank, recommend, and explain

Spend one live weekend doing the work Governance, Risk, and Compliance analysts do every day. Step into the TechFlow case, find the risks, decide which one matters most, and recommend what the company should do.

You leave with one risk case you can walk a hiring manager through, your reasoning written down, and your explanation practiced.

In the Studio, Step 4 takes the risk work deeper. After completing your own TechFlow risk assessment, you receive a 15-entry reference register with notes explaining the reasoning behind the scores, rankings, and recommendations. It arrives after your own work is done, so it serves as a comparison, not an answer key.

Your full Challenge ticket price counts toward the Studio when you enroll by the stated deadline.

Support throughout the six months

What Is Included in the Coaching Program?

01

Video Curriculum and Portfolio Templates

Receive six months of access to the 11-step video curriculum, TechFlow Solutions case materials, portfolio templates, workbooks, checklists, examples, decision guides, risk and control resources, and audit-readiness tools.

02

Live Coaching and Feedback

Join two live group coaching calls each month and submit one portfolio piece at least two days before a call to be considered for focused feedback.

03

Private Community

Use the private community for six months to ask questions, share progress, learn with other participants, and access coaching-call recordings.

04

Career Readiness Workshop

Attend one live Career Readiness Workshop series focused on your resume, LinkedIn profile, interview stories, portfolio presentation, and job-search plan. Your eleven Decision Briefs are the raw material. Your interview answers are already written in your own words, so the workshop is spent making them sharper.

05

Job-Search Support

Receive group guidance on finding suitable roles, preparing applications, connecting your experience to GRC work, and discussing your portfolio during interviews.

Recognition for completed work

Earn Recognition for Your Work

Complete the Studio requirements and you may earn recognition that reflects the work Dr. Shumba directly observed.

Digital recognition

GRC Portfolio Studio Digital Badge

Earn the GRC Portfolio Studio Digital Badge after completing all 11 steps, submitting your final portfolio, meeting the completion requirements, and making all required payments.

You may display the badge on your LinkedIn profile after it is awarded.

Earned recognition

Earned Professional Reference Letter

Participants who complete all 11 steps, submit their final portfolio, participate consistently and professionally, and make all required payments may be considered for a signed professional reference letter from Dr. Shumba.

The letter is earned and is not automatically provided to every participant.

A practical way to build and explain GRC work

What Makes the Studio Different?

One Connected Professional Portfolio

Every portfolio piece is based on TechFlow Solutions. Your leadership and governance work leads into business analysis, gap assessment, risk assessment, control decisions, policies, implementation planning, audit readiness, control testing, corrective actions, and leadership reporting.

You will not complete a collection of unrelated assignments. Your completed portfolio tells one connected professional story.

Work You Can Explain and Defend

You make the decisions and complete the work. Templates help you organize your thinking, but they do not make the decisions for you.

Every step ends with a written Decision Brief and a chance to talk it through on a coaching call. By the end, explaining your work is a habit, not a first attempt.

Build Judgment You Can Defend

A document alone does not show how you think.

Here, every important piece of work comes with a decision you made and a written record of your reasoning: what you found, what you considered, and what you concluded and recommended.

You also talk those decisions through on coaching calls.

By the time you sit in an interview, explaining your work is something you have done many times, not something you are trying for the first time.

Coaching Directly From Dr. Shumba

Dr. Rose Shumba designed the 11-step Studio path and developed the TechFlow Solutions business case. She also leads the live group coaching calls.

You receive guidance and feedback directly from the person who created the program.

Practical Use of NIST Guidance

The Studio uses NIST guidance to help you understand risk assessment, control selection and design, implementation planning, evidence review, control assessment, and ongoing improvement.

You apply these ideas through the TechFlow case and the portfolio work you complete.

Optional next step

Optional Mentored Industry Projects

Qualified Studio members may apply for a supervised client project with Dr. Shumba.

With the client's approval, participants may be permitted to describe approved parts of the experience on a resume or LinkedIn profile.

Mentored Industry Projects are optional, offered separately, and cost extra. Placement is not guaranteed. It depends on participant readiness, client requirements, and project availability.

Guidance from the program creator

Meet Your Coach

Dr. Rose Shumba

Dr. Rose Shumba is a cybersecurity educator and computing professor with more than 20 years of experience preparing students and professionals for technology and cybersecurity careers.

She is a former director of a National Security Agency and Department of Homeland Security-designated Center of Academic Excellence in Cyber Defense.

Dr. Shumba also holds the PECB ISO/IEC 27001 Foundation credential.

She designed the GRC Portfolio Studio, developed the TechFlow Solutions business case, and leads the live coaching calls.

Use the tool without giving away the thinking

Where AI Helps, and What Stays Yours

Use AI to organize ideas, improve wording, check structure, and draft, the same way people do in the job.

What stays yours is the judgment. You check the work, choose the recommendation, and explain your reasoning. Do not hand in anything you cannot talk through.

Work only with the TechFlow materials. Never put a real employer's, customer's, or client's information into an AI tool.

Founding cohort

Your Investment

Founding Price: $997 for Six Months

The standard Studio price is $1,997. The founding price of $997 is available for the first cohort only. Founding-cohort enrollment closes Saturday, September 12, 2026.

Attended the Risk Register Weekend Challenge? Your full ticket price is credited when you enroll by Wednesday, September 9, 2026.

Join the GRC Portfolio Studio

Before you join

Frequently Asked Questions

What does "Studio" mean?

Studio means this is an active, hands-on environment. You will not simply watch videos and take notes. You will build professional GRC work samples, receive guidance and feedback, revise your work, and develop a connected portfolio using the fictional TechFlow Solutions business case.

Is the Studio live or on demand?

Both. The video curriculum is available on demand, and you may join two live group coaching calls each month.

How long do I have access?

You receive six months of access to the video curriculum, live coaching, private community, feedback process, coaching-call recordings, and career support.

What guidance is used in the Studio?

The Studio teaches a practical GRC work process. NIST guidance is used to help you understand risk, controls, evidence, assessment, and improvement. You do not need previous experience with NIST before joining.

How does the Risk Register Weekend Challenge connect to the Studio?

The Challenge gives you one risk case you can explain and defend. The Studio follows eleven guided steps through the full TechFlow company case. Your full Challenge ticket price counts toward the Studio when you enroll by the stated deadline.

Do I have to complete the Risk Register Weekend Challenge before joining?

No. You may join the Studio without attending the Challenge.

How does portfolio feedback work?

Submit one portfolio item at least two days before a coaching call. Dr. Shumba will provide focused feedback during the live session when the item is selected for review.

How do I earn the digital badge?

Complete all 11 steps, submit your final portfolio, meet the completion requirements, and make all required payments.

Does everyone receive a professional reference letter?

No. The professional reference letter is earned. You must complete all 11 steps, submit your final portfolio, participate consistently and professionally, and make all required payments. Dr. Shumba must also have enough direct knowledge of your work and professional conduct to write an accurate reference.

Can I use AI in the Studio?

Yes. Use it to organize ideas, improve wording, and draft. You check the work, choose the recommendation, and explain your reasoning. Work only with the TechFlow materials, and keep real employer or client information out of any AI tool.

What is a Decision Brief?

A one-page brief you write at the end of each step: what you found, what you considered, and what you concluded and recommended. Eleven steps, eleven briefs, and together they show how you think.

Do I make the final decisions for TechFlow?

You make the analyst's decisions: what the risks are, how to rank them, which controls fit, what evidence is enough. Leadership decides which risks to live with and which fixes to fund. You bring the recommendation and explain it.

Why does policy work matter if AI can write policies?

Because writing them is not the skill. Choosing which policies TechFlow actually needs, adjusting them for healthcare and financial clients, and explaining what you left out is the skill. That is what you practice, and that is what you record.

Will I implement controls in a real company?

The main Studio work uses TechFlow Solutions, a fictional company. You will develop realistic control designs, implementation plans, procedures, evidence requirements, assessment records, and improvement plans. You should not describe the TechFlow work as employment or as work completed for a real client. Qualified participants may separately apply for an optional Mentored Industry Project when one is available.

Do I need previous GRC experience?

No previous GRC position is required. You need basic computer and spreadsheet skills, attention to detail, a willingness to receive feedback, and enough time to complete the work.

Is TechFlow Solutions a real company?

No. TechFlow Solutions is a fictional company created for portfolio development. Your resume, LinkedIn profile, and interviews should identify the work as a fictional case study. It should not be presented as employment or work completed for a real client. Decision Briefs describe your own reasoning about a fictional company and may be shared in full, as long as the work is identified as a case study and not as employment.

Does the Studio provide a professional certification?

No. The Studio is an educational and coaching program. It does not provide a professional certification.

Does the Studio guarantee a job?

No. The Studio helps you build professional work samples, prepare for interviews, and organize your job search. Employers make all hiring decisions.

Do I need to complete the free roadmap first?

No. If you are still exploring non-coding cybersecurity roles, the free GRC Career Roadmap is a helpful place to begin. Visit kudzaiedugroup.com/grc_roadmap.

Your next step

Show Employers What You Can Do

Follow the 11 guided steps. Build professional GRC work samples. Learn the language of the field. Prepare to explain and defend your decisions with confidence.

Join the GRC Portfolio Studio