ZABEZ.com

Governance · Risk · Compliance

GRC analyses of the world's largest enterprises.

I read how the world's biggest companies handle governance, risk, and compliance, then write it up plainly: which frameworks they run on, what they certify, where regulators have pushed back, and what their programs actually reveal. All of it grounded in public sources, with citations on every page.

Updated daily Frameworks: NIST CSF 2.0 · ISO 27001 · SOC 2 · FedRAMP Domains: Cloud · Finance · Pharma · Privacy
Editorial illustration: a magnifying lens revealing the machinery inside corporate towers

Illustrations original to ZABEZ.com

0Enterprise case studies
0Frameworks mapped
0+Program lessons
0Free tools, no catch
NIST CSF 2.0ISO 27001SOC 2FedRAMPGDPRPCI DSSHIPAASOXGxP NIST CSF 2.0ISO 27001SOC 2FedRAMPGDPRPCI DSSHIPAASOXGxP
02. The Scoreboard

All six, side by side

NIST CSF 2.0 maturity, scored 1–5 from documented public posture. Same method, same evidence standard, every company. Assessed August 2026.

JPMorgan ChaseFinance
0 / 5
Amazon Web ServicesCloud
0 / 5
MicrosoftCloud · AI
0 / 5
GoogleCloud · Privacy
0 / 5
PfizerPharma
0 / 5
MetaPrivacy
0 / 5

Scores are analytical judgments of documented posture, not audits. Method below.

04. Start Here

Three ways to use this site

Tell me who you are, and I'll tell you where the value is.

Breaking into GRC

Career changers & students

Start with the free five-lesson course, grab the resume template, then follow the daily news to build the vocabulary interviewers expect.

Start the free course →
Hiring or evaluating

Managers & recruiters

The case studies show you how I think: method, evidence standards, and judgment. The scoreboard is the fastest read.

Read a case study →
Working in GRC

Practitioners

The starter policy pack saves you a blank-page afternoon, and the daily digest keeps regulator moves on your radar in two minutes a day.

Get the free tools →
05. Free Resources

Practical GRC tools, free

The tools I wish someone had handed me when I started: a resume template that actually gets read, policy documents you can adapt in an afternoon, and a plain-language guide to what GRC really is. Enter your email, grab what you need, and you'll also get the daily news digest. Unsubscribe anytime.

Resume Template

One-page, ATS-friendly GRC resume template (.docx) with the rules that get past filters, plus the exact phrasing patterns that work.

Download →

Starter Policy Pack

Three ready-to-adapt documents every GRC program needs first: Information Security Policy, Acceptable Use Policy, and a working Risk Register.

Download →

What Is GRC?

A plain-language introduction to governance, risk, and compliance: the frameworks, the daily work, and how to break in. Perfect for career-changers.

Read →

Editorial illustration: climbing a staircase of books toward a golden flag
06. Courses

Learn GRC, the practical way

Two paths: start free with a five-lesson mini-course that shows you what GRC actually is, or go all the way with the full analyst program that ends with a real skillset and a resume that proves it.

GRC Foundations Free

Five short lessons, about an hour total. What GRC is, the frameworks that matter, a real day in the life, and how people actually break in.

Start the free course →

GRC Analyst Program RM 499

Eight modules, 40+ lessons, four hands-on labs (audit, risk, policy, awareness), a job-hunting module, and resume bullets unlocked along the way. Lifetime access.

See the full program →

07. Capabilities

What I assess, and how

Years of security and GRC work across SaaS, cloud, and regulated environments, applied here to reading and scoring the public posture of the world's largest enterprises.

Governance

Board and management oversight structures, policy hierarchies, risk appetite statements, and accountability frameworks, mapped against COSO and NIST CSF 2.0 Govern.

Risk Management

Enterprise and third-party risk programs, risk registers, control testing, and how risk tolerance flows from the board to the control room.

Compliance

Certification posture (ISO 27001, SOC 2, FedRAMP, PCI DSS), regulatory exposure (GDPR, SOX, GLBA, HIPAA, GxP), and evidence of sustained audit readiness.

Security Posture

Control design across the NIST CSF 2.0 core, identify, protect, detect, respond, recover, evaluated from public reporting, trust centers, and breach history.

08. Method

How the analyses are built

Every case study follows the same disciplined process, so you can compare companies on a level playing field.

01

Framework mapping

Identify the frameworks the sector actually operates under, FedRAMP for cloud, Basel/CCAR for banking, GxP for pharma, and map the company's documented posture to them.

02

Evidence collection

Public-posture evidence only: trust centers, certification registries, annual reports, 10-K risk factors, regulatory actions, breach disclosures, and auditor opinions.

03

Control assessment

Score each NIST CSF 2.0 function on a 1–5 maturity scale, using the strength and breadth of documented controls, not reputation.

04

Findings & watch items

Distill what the company does exceptionally, where the pressure points are, and what a GRC practitioner should watch next.

09. About

The analyst behind the lens

I'm Kok Jabez, a GRC and cybersecurity analyst who has spent years both building production systems and securing them. My day to day lives at the intersection of governance, risk, and compliance: the structures that let an organization take on risk on purpose instead of by accident.

I've worked inside the controls themselves, running security and compliance programs against the frameworks the industry actually audits on, NIST CSF, ISO 27001, SOC 2, GDPR, and more. I know what these look like from the inside, not just from the brochure. I hold CompTIA SecurityX (formerly CASP+), CompTIA CySA+, and CEH, with CISM in progress.

This portfolio applies the same lens to the biggest companies in the world: what they publish, what they certify, where regulators have pushed back, and what their programs say about how they really operate.

Location: Southeast Asia (UTC+8), available for remote GRC, security, and compliance work worldwide.

10. Contact

Let's talk GRC

Open to GRC consulting, security assessments, compliance projects, and full-time remote roles. I read everything that lands here and I reply to all of it.

Or connect on LinkedIn.