Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

Dancing With the Gray Rhino: Why Obvious Risks Still Destroy Organizations

In risk management, we tend to obsess over black swans. Rare, unpredictable, high impact shocks that arrive without warning and rewrite the narrative overnight. Yet most organizational failures are not born from surprise. They emerge from visible, accelerating threats that were identified, debated, scored, and then quietly deprioritized because mitigation was inconvenient, expensive, or politically uncomfortable. These are gray rhinos. High probability, high impact risks charging directly at the organization. The breakdown is not foresight. It is governance.

Wherever You Are on the FedRAMP 20x Journey, Know What Comes Next

There is a point in any FedRAMP program when the conversation has to leave the whiteboard. The target date is on the calendar. The evidence exists somewhere, though perhaps not in the form the new model expects. Controls are operating, responsibilities are divided among teams, and someone has to determine how much of what already exists can make the move to 20x.

Book Review: Mission-Critical Governance—Focusing on What Matters Most

I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. All of these are important components of GRC, but none of them is the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives. What ultimately matters, then, is not the volume of governance activity an organization can demonstrate, but whether it can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.

When Controls Compete With Each Other

A critical system goes down, and the operations team needs an administrator inside it immediately. Privileged access, however, requires approval, and the designated approver is unavailable. A change may restore the system, but normal procedure requires testing before anything reaches production. Meanwhile, the recovery clock is running.

The Compliance Illusion: When More Controls Create More Risk

There is a strange rule in compliance: when something goes wrong, organizations add a control. A regulator raises a concern? Add a control. An auditor finds a weakness? Add another. A cyberattack happens? Add three. A new framework arrives? Someone opens a spreadsheet. Nobody ever gets celebrated for deleting one.

Governing AI Between the Checkpoints

A few weeks ago, I wrote about a question that had followed me from a computer room in Milwaukee thirty years ago into today's conversations about agentic AI, "Where is the big red button?"

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

For a long time, seeing someone or hearing their voice gave us a reasonable level of confidence that we knew who we were dealing with. If your manager called, you recognized their voice. If a senior executive joined a video meeting, you could see them on the screen. There was usually little reason to question whether the person you were speaking to was actually who they claimed to be.