GRC For Mere Mortals — Mentorship Program
DOC: GRC-MENTOR / 2026
STATUS: ENROLLMENT OPEN
Mentorship Program

GRC in 10 Days. Not 10 Months.

Work through creating a cybersecurity GRC program — but never alone. Ask questions and get direct feedback from an instructor as you go, inside a live community built to support you.

You won’t just learn isolated GRC topics — you’ll see how governance, risk, controls, and incident response connect into one complete program, the same way it works inside a real company.

Included in every tier: a 10-day walkthrough that prepares you to work in GRC — start to finish, in 10 days.

View programs Cancel anytime · Monthly billing
Mere
Mortal
Approved
▶ Watch: How the 10-day walkthrough works

[ Replace this block with your embedded video — YouTube, Vimeo, or Wistia embed code ]

A full cybersecurity program, start to finish — in 10 days

By the end, you won’t just know the terms — you’ll have built the four pillars of a real security program, the same ones every CISM-aligned program is built on.

Domain 01

Information Security Governance

Set the strategy, structure, and accountability that everything else in the program answers to.

Domain 02

Information Security Risk Management

Identify, assess, and treat risk across the business — the foundation every decision gets built on.

Domain 03

Information Security Program

Build and run the controls, policies, and processes that carry the strategy into daily operations.

Domain 04

Incident Management

Detect, respond to, and report on security incidents the way a real program is expected to.

The 10-day walkthrough

Ten days, ten real GRC job duties — each one framed the way it actually shows up in a job posting and on the job, so you finish able to do the work, not just define it on a test.

Day 01

Structure a governance framework aligned to business objectives

Day 02

Identify and document risk across business units

Day 03

Score and prioritize risk using a standard risk matrix

Day 04

Build a risk register with treatment plans for each finding

Day 05

Draft policies and procedures that satisfy control requirements

Day 06

Design and implement controls to mitigate identified risk

Day 07

Monitor compliance against internal policy and external regulation

Day 08

Prepare audit evidence and walk stakeholders through findings

Day 09

Respond to incidents and report outcomes to leadership

Day 10

Present a full GRC program roadmap to leadership

By Day 10

You’ll be prepared to work in GRC — with a governance framework, a completed risk register, a set of policies, a control matrix, and an audit-ready roadmap already built. Real projects built the way a real workplace expects them, not textbook exercises — things you can show in an interview or add to a portfolio.

Prepares you for CGRC, CISSP, CISM & CISA — the practical way.

Exam prep courses teach you to memorize facts. This program teaches you the why behind them — so when a scenario question puts you in the room making the decision, you already know how to think it through, not just which term to recall.

CGRC CISSP CISM CISA

Three ways to work with me

Every tier includes full access to the course library and the private community — because GRC isn’t something you should have to learn in isolation. What changes between tiers is how much direct feedback you get on your work.

CTRL-01
Basic Access
Self-guided
$150/month

For learners who want the material and a community to work alongside.

  • Full GRC course library
  • 10-day walkthrough of a full GRC program
  • Private community access
  • Self-paced structure
  • New content as it’s released
Enroll — Basic Access
CTRL-03
1:1 Mentorship
Maximum coverage
$1,000/month

For learners who want a mentor building a plan around their specific goals.

  • Everything in Guided Feedback
  • Weekly 1:1 live call with me
  • Personalized study & career roadmap
  • Direct message access between calls
Enroll — 1:1 Mentorship
Included Basic Access Guided Feedback 1:1 Mentorship
Full course library
Private community
Weekly group call
Direct feedback on work
Weekly 1:1 call
Personalized roadmap

Do I need a background in GRC to start?

No. The course library is built to take you from plain-language fundamentals up through applied practice, regardless of tier.

Is this theory, or actual workplace practice?

Workplace practice. Every day of the walkthrough mirrors a real duty from a GRC job, not a textbook definition — you build the same documents and make the same calls you’d make on the job.

Will this help me pass CGRC, CISSP, CISM, or CISA?

Yes — but by building understanding rather than drilling flashcards. Once you know why a control or decision exists, the exam’s scenario questions get much easier to reason through.

Can I switch tiers later?

Yes. You can move up or down between Basic Access, Guided Feedback, and 1:1 Mentorship at any time — it takes effect on your next billing date.

What happens on the weekly calls?

Guided Feedback calls are small-group sessions reviewing real scenarios and answering questions. 1:1 calls are one-on-one and built around your specific goals.

Is there a contract?

No. Billing is monthly and you can cancel anytime.

Stop learning GRC in isolation.

Pick the level of feedback that matches where you’re headed, and start this week.

Choose your program