Guerilla GRC

Joshua Boyles (LHMCO · VP of Cybersecurity)

SAINTCON 2025 · Day 1 · Main Track 1

Overview

In his SAINTCON talk, "Guerilla GRC," Joshua Boyles, VP of Cybersecurity at the Larry H. Miller Company, introduces an innovative and pragmatic approach to addressing two pressing challenges in the cybersecurity landscape. The core concept, Guerilla GRC, is a call to action for cybersecurity professionals to leverage their existing knowledge and networks to bolster the defenses of vulnerable small businesses, while simultaneously providing invaluable real-world experience for those aspiring to enter the field.

Watch on YouTube

Visual summary for Guerilla GRC by Joshua Boyles
Visual summary for Guerilla GRC by Joshua Boyles

Key moments

  1. 0:00 Introduction to Guerilla GRC and speaker.
  2. 3:00 Introducing two major cybersecurity problems.
  3. 3:10 Problem 1: Small businesses' cyber vulnerability.
  4. 4:15 Problem 2: Entry-level cyber job experience paradox.
  5. 5:00 Guerilla GRC: The solution connecting problems.
  6. 6:00 Defining GRC and the 'Green Team' concept.
  7. 7:00 Understanding compliance in cybersecurity standards.

Guerilla GRC

Speakers: Joshua Boyles, VP of Cybersecurity, LHMCO

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=ujxFPiGJ8sU

Overview

In his SAINTCON talk, "Guerilla GRC," Joshua Boyles, VP of Cybersecurity at the Larry H. Miller Company, introduces an innovative and pragmatic approach to addressing two pressing challenges in the cybersecurity landscape. The core concept, Guerilla GRC, is a call to action for cybersecurity professionals to leverage their existing knowledge and networks to bolster the defenses of vulnerable small businesses, while simultaneously providing invaluable real-world experience for those aspiring to enter the field.

Boyles highlights the disproportionate impact of cyber threats on small businesses, many of which lack the resources, expertise, and tailored tools to defend against sophisticated attackers. Concurrently, he points out the paradox of entry-level cybersecurity jobs often demanding years of experience, creating a significant barrier for new talent. Guerilla GRC bridges this gap by advocating for a volunteer-driven, informal application of Governance, Risk, and Compliance (GRC) principles, transforming cyber professionals into an "irregular force" capable of making a tangible difference.

This talk is crucial because it offers a scalable, community-based solution to a systemic problem. It reframes GRC from a perceived "box-checking" exercise for large enterprises into an accessible, security-enhancing practice for even the smallest organizations. By empowering individuals to act as informal cybersecurity consultants within their personal networks, Boyles not only champions the protection of critical economic foundations but also cultivates a new generation of skilled and empathetic cybersecurity practitioners.

Background

▶ Watch: Introduction to Guerilla GRC and speaker. (0:00)

The genesis of Guerilla GRC lies in two significant, interconnected problems facing the cybersecurity community and the broader economy.

First, small businesses are acutely vulnerable to cyber threats. Boyles presents sobering statistics: at least 70% of small businesses will be targeted by phishing attacks in a given year, 30% will experience a cyber incident, and a staggering 25% of those affected will go out of business within a year. This paints a grim picture, with Boyles humorously calculating that, statistically, all small businesses could be out of business in 12 years if current trends continue. The fundamental issue is a severe resource disparity; small businesses, often operating on tight budgets, lack the funds, specialized tools, and dedicated staff to defend against well-resourced attackers like ransomware gangs or even nation-states. Existing cybersecurity solutions are predominantly designed for enterprises, leaving a significant gap for smaller entities.

Second, the cybersecurity industry faces a paradoxical entry-level hiring problem. Many "entry-level" cybersecurity job postings demand two to eight years of experience, while less than 10% of all cybersecurity jobs are genuinely entry-level positions. This creates a Catch-22 for aspiring professionals: how can one gain the requisite experience without first securing an entry-level job? This barrier to entry prevents passionate and capable individuals from contributing to a field that desperately needs talent, exacerbating the overall cybersecurity workforce shortage.

Boyles introduces GRC, which stands for Governance, Risk, and Compliance, often humorously dubbed the "Green Team" to give it a more distinct identity alongside the traditional Red and Blue teams. He defines compliance as ensuring an organization follows the recommendations outlined in a standard, whether regulatory, legal, contractual, or an industry expectation. While GRC can sometimes be perceived as merely "box-checking," Boyles argues it doesn't have to be. He uses a compelling basketball metaphor to illustrate this: an individual playing casually for fun and exercise benefits from basketball differently than an NBA player, who benefits from salary and fame. Both benefit, but their requirements and investments differ. Similarly, compliance offers benefits to organizations of all sizes, from the NSA to a local car wash, with the level of effort scaled to their needs and resources. The key is to shift the mindset from mere adherence to genuine security improvement.

Key Findings

▶ Watch: Problem 1: Small businesses' cyber vulnerability. (3:10)

The central finding and contribution of Boyles' talk is the articulation and promotion of Guerilla GRC as a viable, impactful solution to the identified problems. This approach is founded on several key insights:

  1. Leveraging Existing Resources: The "irregular force" of Guerilla GRC is composed of existing cybersecurity professionals and IT-savvy individuals. Boyles asserts that "all of us have knowledge" and "know more than most small business owners about cybersecurity." This collective, untapped expertise is the primary resource.
  2. Targeting the Outmatched: The primary beneficiaries are small businesses, which are "outmatched" by well-resourced attackers. Guerilla GRC provides a framework for these irregular forces to assist these vulnerable entities using "whatever is available" and "however makes a difference regardless of tradition," akin to guerrilla warfare.
  3. Simplicity and Approachability are Paramount: For small businesses, complex enterprise solutions are infeasible. The core of Guerilla GRC is to simplify cybersecurity standards, breaking them down into understandable, actionable, and "doable" steps. Even "something is better than nothing" is a foundational principle.
  4. Cybersecurity is a People Problem: Beyond the technical aspects, successful cybersecurity implementation, especially for small businesses, hinges on effective communication, persuasion, and understanding the unique needs and constraints of the people involved.
  5. A Win-Win Proposition: Guerilla GRC is designed to be mutually beneficial. Small businesses receive much-needed cybersecurity assistance, potentially saving them from going out of business. Simultaneously, aspiring and current cybersecurity professionals gain practical experience, hone communication skills, build networks, and acquire resume-worthy accomplishments, addressing the entry-level job paradox. This "win-win" scenario is central to the model's sustainability and appeal.

These findings coalesce into a practical framework that redefines cybersecurity assistance for the underserved and offers a pathway for career development for the aspiring.

Technical Deep Dive

▶ Watch: Problem 2: Entry-level cyber job experience paradox. (4:15)

Guerilla GRC is conceptualized as an "irregular armed force" fighting a "stronger force" through "sabotage and harassment," translated into the cybersecurity context. The "irregular force" is comprised of individuals with cybersecurity knowledge, which, as Boyles points out, includes "almost everyone in the crowd" with at least some IT experience. The "stronger force" represents the well-resourced ransomware gangs and other malicious actors targeting small businesses. The "sabotage and harassment" translates to applying practical, non-traditional methods to improve security, unconstrained by formal processes or large budgets.

The practical flow of Guerilla GRC involves a series of steps:

  1. Step 0: Get to know them and their business. This emphasizes leveraging existing relationships (friends, family, local businesses frequented). Understanding their operations is crucial to tailoring advice.
  2. Step 1: Find out if they're concerned about cybersecurity. Most small business owners are, but they often perceive it as an overwhelming, expensive problem.
  3. Step 2: Help them understand that simple steps can make a difference. Countering the perception that robust security requires "thousands and hundreds of thousands of dollars and weeks and weeks to solve."
  4. Step 3: Find an appropriate standard. Boyles recommends standards like the CIS Critical Security Controls (CIS CSC) due to their practical, prioritized nature.
  5. Step 4: Put together a subset of controls. Instead of overwhelming them with a full standard, select 3-5, or even just 1 crucial item, such as implementing multi-factor authentication (MFA) or a password manager.
  6. Step 5: Explain and implement. Clearly articulate what needs to be done and how to do it. This might involve a quick demonstration or guiding them through the process.
  7. Step 6: Occasionally check in. This is not about constant auditing but friendly follow-up to reinforce efforts and offer further assistance.

Boyles outlines four guiding principles for effective Guerilla GRC:

  1. Something is better than nothing: This principle combats the paralysis of perfection. Even enabling MFA on a single account, or explaining its importance, is a significant security improvement for a small business. The focus should be on achievable, incremental gains rather than an exhaustive, daunting list of controls.
  2. Focus on finding the right wheel, not inventing one: This addresses the "additive bias" and "not invented here syndrome" prevalent in technical fields, where there's a tendency to build custom solutions. For small businesses, established best practices and readily available tools are almost always the superior choice. Boyles provides an example from CIS CSC: the control "establish and maintain a documented secure configuration for enterprise assets" sounds complex. For an enterprise, this might mean a hardened image. For a small business buying a new Dell laptop, it simplifies to a checklist: "install endpoint protection, turn on automatic updates, set a new strong password." The solution isn't inventing a new process but simplifying an existing standard.
  3. Cybersecurity is a people problem: Technical solutions are only effective if people implement and maintain them. This requires strong communication skills, an ability to explain complex concepts in simple terms, and empathy for the business owner's perspective. Boyles shares his own experience learning PCI DSS (Payment Card Industry Data Security Standard) while working for a theater chain, where he had to translate legalistic controls into understandable policies for his team. Effective communication, he argues, relies more on understanding the audience and the subject matter than on charisma.
  4. Take the win-win: This principle highlights the dual benefits. Small businesses gain vital security improvements (e.g., turning on MFA dramatically reduces breach likelihood), and the individual providing help gains practical experience, communication skills, and a tangible accomplishment for their resume. Boyles illustrates this with a hypothetical resume entry: "Learned, modified, and helped deploy CIS CSC standards for local small businesses (e.g., Squeaky Clean Car Wash, Zero Cool Frozen Yogurt)." This kind of real-world experience, he argues, is far more impactful than school projects when applying for entry-level cybersecurity roles.

Demo / Proof of Concept

▶ Watch: Defining GRC and the 'Green Team' concept. (6:00)

The most compelling demonstration of Guerilla GRC in action was the live role-play between Joshua Boyles and a volunteer named Chris, who adopted the persona of a small business owner. This segment effectively illustrated the conversational, non-technical approach central to the Guerilla GRC philosophy.

Boyles initiated the conversation by catching up with Chris, framing it as a casual chat between old friends. Chris described his business: providing practice management software for small doctors' offices, emphasizing the digitization of medical records. Boyles then subtly pivoted to cybersecurity concerns, asking, "What happens to you guys if [a ransomware attack] happens?" Chris's initial response, "What's a ransomware attack?", immediately highlighted the knowledge gap prevalent among small business owners.

Boyles patiently explained ransomware in simple terms – computers getting locked until money is paid. Chris then revealed his "IT guy" was his wife's cousin, a recent graduate who "sets up new computers" and "always messes up our conference room software." This anecdote perfectly illustrated the common scenario of small businesses relying on informal, often inexperienced, IT support.

Boyles then gently probed Chris's confidence in his cousin's cybersecurity capabilities, leading to Chris's humorous admission, "less so now the longer we're talking." This opened the door for Boyles to offer help, not as a sales pitch, but as a favor between friends. He demystified cybersecurity, stating, "the way to fix it is pretty simple. There's like some really simple things." He introduced the concept of MFA by referencing bank security codes, acknowledging it could be a "hassle" but suggesting "better ways to handle it."

The interaction concluded with Chris enthusiastically agreeing to a follow-up meeting for lunch, where Boyles could "tell me a little bit more about all this nerd stuff" and "check out what my weird cousin-in-law is all about." This role-play successfully demonstrated:

  • The natural entry point for a Guerilla GRC conversation (existing relationships).
  • The common lack of cybersecurity awareness and over-reliance on inadequate IT support in small businesses.
  • The effectiveness of demystifying complex threats and offering simple, actionable solutions.
  • The power of a non-sales, helpful approach in building trust and gaining buy-in.
  • The potential for even a slightly "awkward" conversation to yield significant security benefits.

This practical example served as a blueprint for how attendees could initiate their own Guerilla GRC efforts within their personal and professional networks.

Defensive Implications

▶ Watch: Understanding compliance in cybersecurity standards. (7:00)

The defensive implications of Guerilla GRC are substantial, impacting both small businesses and the broader cybersecurity community.

For small businesses, the primary implication is a clear pathway to significantly enhance their cybersecurity posture without requiring massive financial investment or specialized staff. Defenders within these organizations (often the owner or a general IT person) should focus on implementing foundational, high-impact controls. Based on Boyles' guidance, this includes:

  • Multi-factor authentication (MFA): This is repeatedly highlighted as a simple yet vastly effective measure against common attacks.
  • Robust backup strategies: Ensuring data can be restored in the event of ransomware or other data loss incidents. Immutable backups are ideal.
  • Secure configurations for end-user devices: Implementing basic security hardening for new devices, such as installing endpoint protection, enabling automatic updates, and setting strong, unique passwords.
  • Password managers: To facilitate the use of strong, unique passwords across various services, moving away from insecure practices like sticky notes.
  • Awareness and training: Understanding why these controls are important and recognizing common threats like phishing attacks.

Small businesses are urged to be receptive to informal advice from trusted, knowledgeable individuals. The talk underscores that even basic measures are vastly superior to doing nothing, potentially saving them from going out of business, a concern highlighted by the FBI regarding small businesses as critical economic infrastructure.

For cybersecurity professionals and aspiring practitioners, the defensive implications revolve around active community engagement and career development:

  • Become Guerilla GRC practitioners: Leverage personal networks (family, friends, local businesses they patronize) to offer informal, voluntary cybersecurity assistance.
  • Practice communication skills: The ability to translate complex technical concepts into understandable, actionable advice is a critical skill for any cybersecurity role, particularly GRC. Boyles emphasizes "understanding more than charisma" as key to effective communication.
  • Gain real-world experience: This initiative provides a practical avenue to apply theoretical knowledge, identify real-world vulnerabilities, and implement solutions, creating valuable experience for resumes and job interviews.
  • Foster a culture of mutual support: By helping small businesses, the cybersecurity community strengthens the overall digital ecosystem, recognizing that the weakest links can have cascading effects.
  • Advocate for broader initiatives: While Guerilla GRC starts informally, Boyles acknowledges the potential for more organized efforts, such as partnering with Chambers of Commerce, to connect businesses with volunteers.

In essence, Guerilla GRC advocates for a decentralized, community-driven defense model where every knowledgeable individual contributes to fortifying the most vulnerable segments of the digital economy.

Key Takeaways

  • Small businesses are critically vulnerable to cyberattacks, with many lacking the resources and expertise to defend themselves, leading to significant rates of business failure after incidents.
  • The entry-level cybersecurity job market is paradoxical, often requiring years of experience for "entry-level" roles, creating a significant barrier for new talent.
  • Guerilla GRC offers a dual solution: It empowers cyber professionals to provide crucial, free cybersecurity assistance to small businesses while simultaneously allowing aspiring professionals to gain invaluable real-world experience.
  • Focus on "something is better than nothing" and simplicity: Even implementing one or two basic controls like Multi-Factor Authentication (MFA) or a password manager can vastly improve a small business's security posture. Avoid overcomplicating solutions.
  • Cybersecurity is fundamentally a people problem: Effective communication, empathy, and the ability to explain complex concepts in simple, actionable terms are paramount for successful security implementation, especially with non-technical audiences.
  • Leverage existing relationships: Start by helping people you already know (family, friends, local businesses) as a natural, low-pressure way to initiate Guerilla GRC efforts and build practical skills.

About the Speaker(s)

Joshua Boyles is the Vice President of Cybersecurity for the Larry H. Miller Company (LHMCO). The Larry H. Miller Company is a diverse organization known for formerly owning the Utah Jazz NBA team and a network of car dealerships. Today, their portfolio includes a soccer team, a baseball team, and various other ventures. Boyles' role involves managing the cybersecurity posture for this expansive and varied corporate structure.

His career trajectory includes a personal experience with GRC when he was made Director of IT for a theater chain and was unexpectedly tasked with handling a PCI DSS audit. This experience, working closely with a patient auditor, taught him the importance of understanding and translating complex security controls into understandable, actionable policies for a non-technical team, directly informing his "cybersecurity is a people problem" philosophy. This background makes him uniquely qualified to speak on the practical application of GRC principles in diverse business environments, from large enterprises to the smaller entities the Larry H. Miller Company invests in, which often benefit from their cybersecurity assessments.

All talks from SAINTCON 2025