People are the ones who build trust. The governance, risk, compliance, and security community is full of practitioners, educators, and provocateurs who turn "check-the-box" compliance into something that earns real customer confidence. These are our Trust Titans: the voices the Drata learns from, engages with, and avidly follows.
Here's a short introduction to each, in no particular order.
Olivia Rose
Founder of the Rose CISO Group and a multi-time global CISO (formerly at Mailchimp and Amplitude), Olivia advises Fortune 1000 companies on vCISO services and board communications. She's also a board member at Cyversity and a passionate mentor for women and underrepresented groups in cyber. She recently appeared on our When Trust Meets AI podcast.
Chuck Brooks
President of Brooks Consulting International and adjunct faculty in Georgetown's graduate cybersecurity and applied intelligence programs, Chuck is one of the most-followed cybersecurity voices anywhere, named by LinkedIn as a "Top 5 Tech Person to Follow." A prolific Forbes contributor and author of Inside Cyber, he covers the full sweep of emerging-tech risk, from AI to quantum.
Evan Kirstel
One of the most recognizable names in B2B tech media, Evan is a social media strategist, podcaster, livestreamer, and host of the TechImpact TV show seen on FOX Business and Bloomberg. With a 600,000-plus following and partnerships spanning Cisco, Microsoft, Intel, and Palo Alto Networks, he turns complex topics, cybersecurity among them, into accessible, jargon-free stories that reach decision-makers worldwide.
Jane Frankland
Awarded an MBE for services to women in cybersecurity, Jane is the founder of the IN Security Movement and author of the bestselling IN Security. A pioneer who built one of the UK's first ethical hacking firms, she's now one of the industry's leading advocates for diversity and cyber resilience.
Shane Tierney
Currently the Senior Program Manager, GRC at Drata, Shane is a GRC and legal operations leader with 15+ years of experience building and modernizing security, privacy, and AI governance programs across regulated environments. He specializes in translating complex regulatory, security, and third-party risk requirements into practical, automated controls that reduce friction, embed trust, and make compliance a strategic business capability..
Dan Lohrmann
Field CISO for the public sector at Presidio and the former first Chief Security Officer for the State of Michigan, Dan is an award-winning blogger and co-author of Cyber Mayday and the Day After. His annual cybersecurity prediction reports are among the most cited in the industry.
Christophe Foulon
Founder and cybersecurity coach at CPF Coaching, Christophe is a vCISO, host of the Breaking into Cybersecurity podcast, and co-author of Hack the Cybersecurity Interview. He's built a following helping people enter and advance in the field while translating complex risk into business terms.
Scott Mitchell
Founder and chair of OCEG, Scott coined the term "GRC" and created the GRC Capability Model (the "Red Book") and the concept of Principled Performance. His open-source standards have shaped how organizations around the world integrate governance, risk, and compliance.
Shira Rubinoff
CEO of The Cybersphere Group and author of Cyber Minds, Shira is a global keynote speaker and a recognized authority on the human side of cybersecurity. She's known for connecting people, process, and technology into a single, practical view of security.
Aron Lange
Founder of The GRC Lab and creator of the popular LearnGRC newsletter, Aron has taught GRC and ISO 27001 fundamentals to tens of thousands of students through his courses. A former Deloitte security professional, he's on a mission to demystify the field and open doors for newcomers.
Gerald Auger
Founder of Simply Cyber and holder of a PhD in Cyber Operations, Gerald hosts the Daily Cyber Threat Brief (named SANS Podcast of the Year in 2024) and co-authored Cybersecurity Career Master Plan. He's built a community of hundreds of thousands helping people launch and grow security careers.
Kayne McGladrey
Independent vCISO, senior member of the IEEE, author of the GRC Maturity Model and the upcoming book "Cyber Risk is a Myth", Kayne is a go-to voice on treating GRC as a core business competency rather than a one-time project. He has a rare gift for making complex risk feel simple and actionable in the boardroom.
Jacob Hill
Founder of GRC Academy, the practical CMMC and NIST 800-171 training platform now part of Summit 7 (where he serves as Director of Cybersecurity), Jacob has made compliance education accessible to the small and mid-sized defense contractors who need it most.
Michael Rasmussen
Widely known as the "Father of GRC," Michael was the first to define and model the GRC market back in 2002 while at Forrester. As founder of GRC 20/20 Research, he remains one of the most authoritative analysts and advisors shaping how organizations approach governance, risk, and compliance.
Jacob Horne
Chief Security Evangelist at Summit 7, Jacob is a former NSA intelligence analyst and Navy cryptologic technician who has become one of the clearest explainers of CMMC, DFARS, and NIST requirements for the defense industrial base. As he likes to put it, “CMMC isn't making you do the requirements; it's making sure you did”.
Akhila Chitiprolu
Head of Security GRC at Sierra, where she leads AI governance, security, risk, and compliance, Akhila previously led GRC at Stripe and served on the PCI Security Standards Council Board of Advisors. She's a sharp voice on building trust for regulated customers in the age of AI.
Jack Rumsey
Head of Solutions Engineering at Paramify, Jack works across frameworks like ISO 27001 and SOC 2 and is a candid advocate for replacing spreadsheet-driven "GRC chaos" with streamlined, automated, cross-team workflows. He's also the author of the popular GRC Destroyer Substack.
Thomas Fox
Known as "The Compliance Evangelist," Tom is the founder of the Compliance Podcast Network and the author of The Compliance Handbook along with dozens of other books. A daily blogger since 2010, he's one of the most recognized voices in corporate compliance and ethics.
Nikita Gupta
A security practitioner with experience spanning SOC 2, SOX, FedRAMP, ISO, and privacy standards like GDPR, Nikita has worked across risk assessments, audits, and vendor reviews. She partners with leadership to manage risk and streamline compliance, and writes on Medium about making security practical and operational.
Troy Fine
A longtime SOC 2 auditor turned GRC leader and founder of Fine Assurance, Troy is one of the most direct voices on audit quality and the emerging discipline of GRC engineering. He's also a familiar face to the Drata community from his years helping customers navigate compliance.
Linda Tuck Chapman
A leading authority on third-party risk management, Linda is the author of Third-Party Risk Management: Driving Enterprise Value, founder of the Third Party Risk Institute, and creator of the C3PRMP certification. A former bank Chief Procurement Officer, she's a trusted educator and advisor in highly regulated industries.
Ayoub Fandi
Now at Lovable after leading security assurance and GRC engineering at GitLab, Ayoub hosts the GRC Engineer podcast and is one of the most prominent advocates for cloud-native, engineering-minded GRC. He treats compliance as engineering work: something teams build, automate, and operate.
Gary Brickhouse
CISO and VP of GRC Services at GuidePoint Security, Gary leads both the company's internal security program and its GRC consulting practice. He hosts "The Brick House," a recurring conversation with fellow security leaders on the hottest topics in the field.
This list is just a starting point. The GRC and security community is full of thoughtful, generous voices worth your attention, so pick a few names here, hit follow, and let your feed get smarter.
Follow Drata on LinkedIn for more on earning trust, automating compliance, and the people shaping where security is headed.