Skip to content
MVPeople Group Logo
MVPeopleGroup
Back to insightsCase Study

Building a GRC Team from Scratch

Floris Akkerhuis24 March 20266 min read

The Situation

A Dutch fintech scale-up with 200 employees faced a DORA compliance deadline. The problem: zero GRC capacity in-house. No framework, no policies, no dedicated team. Series B investors required compliance as a condition for the next funding round.

Phase 1: The Interim GRC Lead (Month 1-2)

MVPeople placed an experienced interim GRC Lead within 8 days. This professional immediately executed a gap analysis, drew up a roadmap and defined the required team composition. In parallel we started recruiting the permanent team.

Phase 2: Team Building (Month 2-4)

We placed three permanent team members: a GRC Specialist, a Risk Analyst and a Compliance Officer. Each selected on both technical expertise and cultural fit with the scale-up mentality. The interim GRC Lead coached the team and transferred knowledge.

Phase 3: Framework & Audit (Month 4-6)

The team implemented a DORA-compliant governance framework, including incident response procedures, ICT risk management and third-party oversight. The first audit was passed successfully.

Result

Series B successfully closed. GRC team of 4 FTE operational. DORA compliance achieved. The interim GRC Lead completed his assignment in month 5 and handed over to the permanent GRC Manager. Total lead time: 5 months from zero to fully operational.

Floris Akkerhuis

Co-Founder & Lead Consultant, MVPeople Group

Regularly writes about cybersecurity recruitment trends, market analyses and the unique approach of MVPeople Group.

Want to know more?

Do you have questions about this article? Or would you like to discuss your specific situation? Get in touch with us, no strings attached.

READY TO FIND THE RIGHT CYBERSECURITY PROFESSIONAL?