Building a Compliance Program That Scales Without Scaling Your Team

What two years of ISO 27001 with Scytale actually looks like in practice

Brett Hardman, CISO at Cabonline, shares how building an ISO 27001 compliance program turned information security into a business differentiator , and why AI is changing the way CISOs approach GRC.


In this session, Brett joins Ronan Grobler, Head of GRC at Scytale, to walk through his journey from software engineer to "accidental CISO," how ISO 27001 certification laid the groundwork for NIS2 compliance, and where AI is already adding value, from analysis and document generation to security questionnaires. They also discuss why human oversight still matters in an agentic AI world, and what ISO 42001 and the EU AI Act mean for the future of AI governance.