Shadow AI vs Enterprise AI Governance

Shadow AI Is the New Shadow IT. GRC Should Know Better This Time.

Right now, somewhere in your organization, an engineer is connecting a production workflow to an LLM they spun up last Tuesday. No security review. No risk assessment. No procurement process. Just an API key, a use case, and a deadline. Your GRC team will find out eventually. Probably not today. This is not a technology problem. It is not even a people problem. It is a governance problem, and the uncomfortable truth is that the GRC profession has seen this exact movie before. ...

May 21, 2026 · 6 min · Manju Mayachar
PCI Hybrid Cloud Scoping

PCI Scoping in Hybrid Cloud Environments

PCI Scoping in Hybrid Cloud Environments PCI DSS version 4.0 puts fresh attention on scoping through Requirement 12.5.2. You now need a formal scoping exercise at least once a year and after major changes, and you have to be able to explain and defend it. That is hard enough in a simple on premises setup. In a hybrid world with cloud services, shared tools, and legacy systems, it can feel messy and unclear. ...

November 15, 2025 · 6 min · Manju Mayachar

Compliance as Code

The future of GRC is technical. As cloud systems grow more complex, companies need controls that scale. This post explores how Compliance as Code helps GRC teams move faster, stay accurate, and work directly with engineers.

July 24, 2025 · 4 min · Manju Mayachar

From GRC Analyst to GRC Engineer: Why Compliance Alone Doesn’t Cut It Anymore

The role of GRC is changing. Today’s SaaS companies need more than policy writers—they need GRC engineers. Here’s why.

June 28, 2025 · 4 min · Manju Mayachar

How 'The Assist' Became My Leadership Philosophy

A leadership philosophy shaped by lacrosse, Auth0 values, and real-world security work.

May 26, 2025 · 7 min · Manju Mayachar