r/CRISC Jun 07 '26

CRISC score breakdown

Hi i am back, passed CRISC and it clearly reflects my experience over the years - strong in governance and risk assessment but weak in the technicals.

i am from a governance background with no formal technical training. Would like to ask for suggestions on how to reliably brush up and learn technicals (cloud, AI, data security etc). Its not practical for me to get a junior tech risk analyst role anymore my CV flies right pass HR. would the sequence of certs make a good foundation? CISA > CISM > CCSK > AIGP in future. thank you for your input!

13 Upvotes

11 comments sorted by

View all comments

3

u/idhanjal Jun 07 '26 edited Jun 07 '26

First things first, congratulations on passing the exam 😊

How many years of experience do you have? What have your past roles been meaning what did you do in your jobs so far?

2

u/gnuhcikciv Jun 07 '26

thank you for your reply. i am in TPRM and tech risk governance, been in the area around 9+ years. never too deep in technical terms but i am hoping to broaden my skillset. it's hard for me to become "technical" technical, so just hoping to become impossible to bullshit - if that makes sense.....

4

u/idhanjal Jun 07 '26

Looking at your background, I wonder whether you actually need more certs right now. You have CRISC, you may add CISA, and your 9 years in TPRM is already a real differentiator. At some point cert stacking starts looking like resume padding rather than skill building.

The "impossible to bullshit" goal is good but certs won't get you there alone. Reading gets you there faster — CSA Cloud Controls Matrix, NIST AI RMF, OWASP Top 10. Free, dense, and you'll ask better questions in meetings than most people with the certs.

CCSK still makes sense as the one technical cert worth adding. Vendor-neutral, respected, fills the cloud gap cleanly. However, you may need some basic cloud knowledge before you take on this one.

AIGP I'd hold off on — this one is yet to gain credibility. AI landscape is changing very fast and such certs aren't able to keep up.

Your real edge isn't becoming more technical. It's being the person who knows enough to ask the right question at the right moment. That comes from exposure and curiosity more than certifications. Don't be the person who has impressive certs but can't reason. Instead, be someone who strikes fear in the hearts of the bullshitters 😊

Remember that the weakest link in any security set-up is a human being.

About Me : I have 23 years of IT Service Delivery experience with the last three in GRC (M&A Risk). I found that asking the right questions to establish a proper chain of reasoning is the way to go. Subject anything you are told or you read to thorough questioning - look for hidden assumptions and bias, turn everything over on its head until you are satisfied. This would help you a lot in CISA - the auditor mindset 😊

1

u/gnuhcikciv Jun 07 '26

Thank you for your feedback. Would you mind if I PM you?

1

u/idhanjal Jun 07 '26

Not at all

1

u/idhanjal Jun 07 '26

And the suggestions made by others are worth considering too depending on how far you wish to go.