BSides London 2025

BSides London 2025

Breaking In, Standing Tall: A Rookie’s Guide to Confidence in GRC
2025-12-13 , Rookie Track 1

Cybersecurity can feel intimidating, especially when you don’t come from a technical background. In this talk, I’ll share my journey from Sociology to Governance, Risk, and Compliance (GRC), and the lessons I learned navigating my first security audits. From handling evidence requests to battling imposter syndrome, I’ll explore what it takes to shift from self-doubt to confidence in a field full of acronyms and expectations. This session is part story, part practical guide designed to help newcomers see that their unique background is an asset, and that confidence is built through both mistakes and wins.

Audience Takeaways (4 bullets)
• Why non-technical skills strengthen cybersecurity careers
• Practical tips for preparing for your first audit
• Rookie mistakes in GRC and how to avoid them
• Simple strategies for building confidence early in cyber


This talk explores the journey of breaking into cybersecurity from a non-traditional background and the lessons learned from early experiences in Governance, Risk, and Compliance (GRC). I will begin with a short personal story of transitioning from Sociology into cybersecurity, highlighting the initial challenges of entering a technical industry. The main section will focus on lessons learned from my first audits, including preparing evidence, managing requests, and understanding the human side of audit readiness collaboration, communication, and confidence. The final part of the talk will offer practical advice for newcomers: how to recognise transferable skills, avoid common mistakes, and build credibility early in a GRC career.

The talk is designed for students, early-career professionals, and anyone curious about GRC who may feel intimidated by the field. It is not a technical deep dive but will provide realistic and practical insights, showing that confidence in cybersecurity is developed through learning, resilience, and community support.


Please confirm that I am a first time speaker and have not spoken in public and will not be before the Bsides London event date (14th December 2024).: Yes

Funke Omolere is a Sr. Technology Product Owner in Cybersecurity, specialising in Governance, Risk, and Compliance (GRC). With a background in Sociology, she has built a career driving global cloud regulatory initiatives across frameworks such as SOC 2, ISO 27001, BSI C5, and TISAX. Funke brings a distinctive perspective to cybersecurity by combining technical expertise with human insight, ensuring that compliance is not only about controls but also about collaboration and confidence.

Beyond her role, she is a mentor with WiCyS UK & Ireland , where she supports women and professionals navigating their path into cybersecurity. A proud mum of three, Funke balances her professional responsibilities with family life, making her talks both relatable and inspiring. She is passionate about empowering others to stand tall in the face of challenges and build meaningful careers in cybersecurity.