EPISODE · Dec 8, 2025 · 6 MIN
Bonus Episode 5: How Do I Get Ready? School, Certs, and Skills
from All About Risk · host C1Risk
Lily Yeoh breaks down what you really need to enter GRC, from choosing between a degree or certifications to knowing which starter certs are worth your time. She explains how to get hands-on experience before your first role, the soft skills that actually help you stand out, and the one practical skill that’s shaped her own career. This episode gives you a clear, grounded starting point for building a future in GRC.1. GRCP — GRC ProfessionalOCEG-Great intro to governance, risk, compliance, ethics, and audit basics.2. CCEP — Certified Compliance & Ethics ProfessionalSCCE-Focuses on compliance, ethics, investigations, and corporate policy.3. ISO 31000 Risk Management CertificationVarious accredited bodies-Covers organizational risk frameworks and is accessible without technical depth.4. CompTIA SecurityCompTIA-Security fundamentals that support GRC roles tied to IT and cybersecurity.5. CGRC (formerly CAP)ISC2-Intro to governance, risk and security authorization. Good for early GRC careers.ADVANCED LEVEL CERTIFICATIONSThese require experience, deeper security knowledge, or exposure to audit, risk, or governance functions.6. CISSP — Certified Information Systems Security ProfessionalISC2-High-level security governance, risk, architecture, and leadership.7. CISA — Certified Information Systems AuditorISACA-The gold standard for audit, controls, and assessment work inside GRC teams.8. CRISC — Certified in Risk and Information Systems ControlISACA-Focused on IT risk, business risk, mitigation, and control design.9. CISM — Certified Information Security ManagerISACA-Security governance, program management, and risk management at scale.10. CGEIT — Certified in the Governance of Enterprise ITISACA-Enterprise-level IT governance, strategic alignment, and performance risk.
What this episode covers
Lily Yeoh breaks down what you really need to enter GRC, from choosing between a degree or certifications to knowing which starter certs are worth your time. She explains how to get hands-on experience before your first role, the soft skills that actually help you stand out, and the one practical skill that’s shaped her own career. This episode gives you a clear, grounded starting point for building a future in GRC.1. GRCP — GRC ProfessionalOCEG-Great intro to governance, risk, compliance, ethics, and audit basics.2. CCEP — Certified Compliance & Ethics ProfessionalSCCE-Focuses on compliance, ethics, investigations, and corporate policy.3. ISO 31000 Risk Management CertificationVarious accredited bodies-Covers organizational risk frameworks and is accessible without technical depth.4. CompTIA SecurityCompTIA-Security fundamentals that support GRC roles tied to IT and cybersecurity.5. CGRC (formerly CAP)ISC2-Intro to governance, risk and security authorization. Good for early GRC careers.ADVANCED LEVEL CERTIFICATIONSThese require experience, deeper security knowledge, or exposure to audit, risk, or governance functions.6. CISSP — Certified Information Systems Security ProfessionalISC2-High-level security governance, risk, architecture, and leadership.7. CISA — Certified Information Systems AuditorISACA-The gold standard for audit, controls, and assessment work inside GRC teams.8. CRISC — Certified in Risk and Information Systems ControlISACA-Focused on IT risk, business risk, mitigation, and control design.9. CISM — Certified Information Security ManagerISACA-Security governance, program management, and risk management at scale.10. CGEIT — Certified in the Governance of Enterprise ITISACA-Enterprise-level IT governance, strategic alignment, and performance risk.
NOW PLAYING
Bonus Episode 5: How Do I Get Ready? School, Certs, and Skills
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m
Feb 4, 2026 ·18m