A question we are hearing more and more, often phrased almost exactly this way, is some version of “I need to run a proper governance, risk and compliance function, but I do not want to hire a cyber consultant to do it.” It is a reasonable thing to want, and the instinct behind it is sound, because the person asking has usually worked out two things that the market tends to blur together. They have worked out that they genuinely do need a GRC function, with a live risk register, obligations mapped to controls, evidence collected, exceptions managed and a board that can be told the truth on any given week. And they have also worked out that paying a senior cyber consultant or a virtual CISO to sit inside that function and run it week after week is an expensive way to buy something that is, for the most part, not actually cyber expertise at all.

So the short answer is yes. You can run a credible GRC function without hiring a cyber consultant, and you can do it in a way that stands up to a regulator, an insurer or a board. The trick is to separate two things that are constantly conflated, because once you see them as separate the whole problem becomes tractable. The first thing is the ownership and operation of the GRC function itself, which is governance work. The second thing is deep technical cyber-security expertise, which is specialist assurance work. They are not the same job, they do not need the same person, and the expensive mistake is to buy the second when what you needed was the first.

What a GRC function actually requires

Strip a GRC function back to what it does day to day and very little of it is technical in the way people assume. The work is maintaining the risk register, mapping your obligations to your controls, assigning an owner to each control, collecting the evidence that each control is operating, managing the exceptions and the remediation, keeping an eye on your third parties, and turning all of that into reporting that a board and an accountable executive can actually use. That is governance and coordination work, and it calls for someone organised, credible and senior enough to hold control owners to account, rather than someone who can architect a network or run a penetration test.

The technical accountability, meanwhile, never moves. It stays exactly where it already sits, with the people who run the controls in the first place. IT owns the things IT has always owned, such as multi-factor authentication, backups and patching. HR owns onboarding, offboarding and awareness. Legal and privacy own their obligations, procurement owns the supplier side, and the executive owns the acceptance of residual risk. A GRC function does not take that accountability away from anyone, it coordinates it, evidences it and reports on it, which is a very different and much less rarefied job than the one a cyber consultant is trained and priced for.

GRC operator, not vCISO

The person who should run this for you is best thought of as a GRC operator rather than a virtual CISO. It might be a risk and compliance manager, a governance manager, or a capable business-risk person who is comfortable with frameworks and evidence and is not intimidated by a room full of technical control owners. What they need is not the ability to personally judge whether a particular firewall rule is sound, but the discipline to run the system that proves your position: the controls, the risks, the evidence, the suppliers, the obligations, the remediation and the reporting, kept current and kept honest.

Here is roughly how the model divides up, and it is worth keeping this picture in mind because it is the thing that makes the whole approach affordable.

FunctionWho owns it
GRC program ownershipInternal GRC or risk owner
Frameworks and obligationsThe GRC platform
Risk registerInternal owner, with the business
Control ownershipIT and business control owners
Evidence collectionAutomated and platform-driven where possible
Policies and attestationsPlatform templates, internally approved
Supplier and third-party riskProcurement and GRC, on the platform
Board and management reportingThe GRC owner
RemediationThe relevant control owner
Independent assuranceAn external specialist, periodically
Audit and certificationAn independent auditor

The economic difference this unlocks is the whole point. A senior in-house cyber or GRC leader, or a full virtual CISO engagement, commands a package that runs well into the hundreds of thousands of dollars a year, and those people are scarce and largely already employed, which is a good part of why the gap exists in the first place. A capable governance operator running a good platform, with genuinely specialist expertise bought in only when it is genuinely needed, costs a fraction of that. You are no longer paying senior consulting rates for what is mostly administration and coordination.

The trap at both ends

There are two ways to get this wrong, and they sit at opposite ends. The first, and the more common, is to reach for a “managed GRC” offer and discover on closer inspection that what you are actually buying is a consultant or a virtual CISO by another name, with advisory hours and a fractional leadership fee attached. A lot of the market conflates running your GRC system with selling you cyber expertise by the hour, so if your requirement is specifically to have someone operate the machinery without being sold an advisory engagement, it pays to make that requirement explicit and to keep asking until the answer is clear.

The second trap is the opposite one, and it is just as costly in the long run. It is to try to eliminate cyber expertise altogether, on the theory that a platform and a governance operator can do everything. They cannot, and they should not pretend to. There are moments when you need real specialist expertise, and the right move is to buy it as assurance rather than as administration: periodic penetration testing, an architecture review, ISO certification readiness, informed interpretation of an obligation such as APRA’s CPS 234 where it applies to you, or an independent test of whether your controls are actually effective rather than merely documented. You are not trying to remove cyber expertise from the picture, you are trying to stop paying for it to sit in a chair doing governance admin that does not require it.

The proposition changes from “hire a cyber consultant to run your GRC program” to “run your own GRC function, and bring in cyber experts only when you actually need cyber expertise.”

Who can run this for you, without the consultant

If what you actually want is for someone to operate the GRC function on your behalf, so that you get the outcome without either the recruitment problem or the consulting bill, this is precisely the model BayRisk was built to deliver, and it is what we mean by RiskOps: GRC.

We run your governance, risk and compliance function as a continuous operation rather than a project or an advisory retainer. Your people continue to own the controls, because that accountability belongs with them and never moves. Your board and your accountable executive continue to own the risk and the decisions, because that is where the law puts them and where they belong. What we add is the operating layer in between: we run the platform, which is licensed in your name rather than ours so there is no lock-in and you can be as hands-on or as hands-off as you like, we keep the register and the evidence current, we chase the control owners, we maintain your framework mappings, and we produce the management and board reporting on a rhythm rather than in a pre-audit scramble. Crucially, the senior CISO and cyber-security expertise the function needs is embedded in the service and baked into the cost, rather than being something you have to go and source separately. RiskOps: GRC is not a governance operator handed to you without the cyber judgement behind it, it is the operating layer and the necessary, contracted CISO expertise together, at a fraction of what a full-time in-house CISO would cost. Where a specific piece of deep specialist work is genuinely called for beyond that, such as a penetration test or a formal certification audit, we coordinate it as part of running your position, so you are never left holding a gap the model quietly assumed someone else would fill.

The distinction we hold to, and the reason clients come to us with exactly the question this article started with, is that we are running the machine, not selling you expertise by the hour. You are not buying advisory time and hoping it adds up to a function. You are buying the outcome: a GRC function that runs, a position you can prove, and an accountable person who can walk into a board meeting or a regulator’s office and stand behind it, on any ordinary Tuesday.

At BayRisk this is the whole reason we exist. We run cyber and enterprise risk as a continuous operating function rather than selling you another platform to administer or another consultant to interpret, we hold the operating layer and stay accountable for it, and we keep your risk position current and provable while the ownership and the decisions stay firmly with you.

If you want to see how that compares to the cost of hiring for the role, we set it out in full, with current Australian salary figures, in what RiskOps replaces https://www.bayrisk.com.au/#cost