Prof. Karthik Subramanian
CISA, CRISC, ISO 27001 LA

A governance, risk, and compliance specialist who guides organisations through certification and regulatory frameworks.
Professor Karthik Subramanian is a Professor of Governance, Risk, and Compliance at GICCT, where he leads the programs that turn security from a technical concern into a managed, accountable business discipline. While much of cybersecurity focuses on technology, he teaches the equally vital work of governing it — the frameworks, controls, and decisions that determine whether an organisation’s security actually holds together.
Background and career
Professor Subramanian built his career in audit and risk management before specialising in information security governance. That background gave him a perspective many technical security professionals lack: an understanding of how boards think, how risk is weighed against cost, and how security must ultimately justify itself in business terms. He learned early that the most sophisticated technical controls are worthless if they are not governed, maintained, and aligned with what the organisation actually needs to protect.
He has guided numerous organisations through the journey from ad-hoc security to structured, certifiable management systems, conducting gap analyses, building risk registers, and steering companies through certification audits. He has served as an external advisor and interim security manager for organisations that needed to mature quickly, and he holds the CISA, CRISC, and ISO 27001 Lead Auditor certifications.
Areas of expertise
Professor Subramanian’s expertise covers information security management systems, the ISO 27001 standard, risk assessment and treatment, audit, and the major regulatory frameworks shaping the field — including the GDPR and the NIS2 directive that now reaches a wide range of organisations across Europe. He has particular depth in making these frameworks practical, translating their abstract requirements into the concrete policies, procedures, and controls that an organisation can actually implement.
He also specialises in the human and organisational dimensions of governance: how to build a security culture, how to get genuine buy-in from leadership, and how to design controls that people will follow rather than circumvent. He argues that governance fails most often not on technical grounds but on human ones, and his work consistently addresses that reality.
Teaching philosophy
Professor Subramanian makes a subject that can seem dry genuinely engaging by grounding it in real documentation, real risk registers, and real case studies. His students do not just read about an information security management system; they build the components of one, working through the decisions and trade-offs that a real implementation demands. His goal is that graduates can lead a compliance project, not merely describe one.
He places strong emphasis on the “why” behind every control, believing that practitioners who understand the intent of a requirement can adapt it intelligently, while those who merely follow a checklist will be lost the moment reality departs from the template. He teaches governance as reasoning, not box-ticking.
A practitioner’s perspective
Professor Subramanian’s teaching is shaped by having sat on both sides of the audit table, as both assessor and the assessed. He knows what auditors actually look for, where implementations typically fall short, and how to build a management system that is genuinely effective rather than merely presentable. He shares these insights freely, giving students a realistic picture of what compliance work involves.
He keeps a close watch on the shifting regulatory landscape, particularly the growing reach of NIS2 and the increasing personal accountability it places on organisational leadership. He helps students understand that compliance is no longer a back-office function but a board-level concern, and that professionals who can bridge the technical and the regulatory are increasingly valuable.
At GICCT
At the institute, Professor Subramanian leads the ISO 27001 Lead Implementer and governance, risk, and compliance programs, and advises on regulatory content across the curriculum. He is a strong advocate for the view that good governance is what makes security sustainable, turning one-off efforts into lasting capability. For professionals looking to move into the management side of security — one of the field’s clearest paths to senior roles — his courses offer a thorough, practical grounding.