I work at the intersection of cybersecurity, compliance, and technology. And I’ve learned that the hardest part is rarely the technical problem. It’s getting people aligned, cutting through the noise, and building something that actually sticks.
I’ve done it hands-on and at the strategy level. Built controls from scratch, run compliance programs, helped teams navigate risk without drowning in frameworks. I care about being straight with people, keeping things simple, and making sure the humans behind the systems aren’t an afterthought.
Building Practical Solutions
Exploring technology, cybersecurity, and life with strategy, discipline, and transparency.
Manju Mayachar
Virtual CISO & GRC Consultant
We're Deploying AI Like It's Been Tested. It Hasn't.
An elderly Medicare patient needs post-acute rehabilitation care. Their doctor says so. The hospital says so. UnitedHealthcare’s AI model disagrees.
A class action lawsuit filed in November 2023 alleged that UnitedHealth’s algorithm, called nH Predict, was denying rehabilitation coverage to seriously ill patients at scale, including cases involving feeding tubes and severe pressure wounds. The lawsuit alleged that nine out of ten of those denials were overturned on appeal. A U.S. Senate Permanent Subcommittee on Investigations report, published in October 2024, found that UnitedHealthcare’s prior authorization denial rate for post-acute care jumped from 10.9 percent in 2020 to 22.7 percent in 2022, as the company was implementing automated review processes. The lawsuit further alleged UnitedHealth knew about the error rate and kept using the model anyway, because only 0.2 percent of denied patients actually appeal.
...
PCI Scoping in Hybrid Cloud Environments
PCI Scoping in Hybrid Cloud Environments PCI DSS version 4.0 puts fresh attention on scoping through Requirement 12.5.2.
You now need a formal scoping exercise at least once a year and after major changes, and you have to be able to explain and defend it.
That is hard enough in a simple on premises setup.
In a hybrid world with cloud services, shared tools, and legacy systems, it can feel messy and unclear.
...
Compliance as Code
The future of GRC is technical. As cloud systems grow more complex, companies need controls that scale. This post explores how Compliance as Code helps GRC teams move faster, stay accurate, and work directly with engineers.
From GRC Analyst to GRC Engineer: Why Compliance Alone Doesn’t Cut It Anymore
The role of GRC is changing. Today’s SaaS companies need more than policy writers—they need GRC engineers. Here’s why.
How 'The Assist' Became My Leadership Philosophy
A leadership philosophy shaped by lacrosse, Auth0 values, and real-world security work.