Insights

When Leadership Becomes a Single Point of Failure

In a founder-centric organization, the founder isn’t just the CEO. They’re the mascot, the mythology, the exception to the rules, and the emotional thermostat of the building. Identity, authority, and narrative all get bundled into one human nervous system. That’s efficient. It’s also a little like running a power grid through a single extension cord.

The Wildfire Doesn't Have to Reach You to Disrupt Your Business

On the morning of July 16, I looked outside in Milwaukee and the city seemed to have misplaced its horizon. The light had that strange, dirty cast that wildfire smoke gives it, and the air smelled faintly burned. This was Wisconsin, not a community evacuating ahead of a fire line. Nothing nearby was burning. The fires were hundreds of miles away, in northern Minnesota near the Boundary Waters and across Canada. Yet by then, the distinction between where the disaster was happening and where its consequences were being felt had become almost meaningless.

The Side of GRC Most People Overlook

Whenever I tell people that I work in Governance, Risk and Compliance (GRC), the reaction is usually the same. “So, you spend your day writing policies?” It’s a fair question because, from the outside, that’s exactly what GRC looks like. Before I started working in this field, I probably would have said the same thing. The reality is very different.

Who Is Auditing Governance?

I recently posed what I believe is one of the most important unanswered questions in governance on LinkedIn: Who is auditing the governance framework? The responses confirmed two things. First, many practitioners instinctively recognize the gap. Second, there is still remarkably little agreement on who should be responsible for assessing governance effectiveness or even what "effective governance" actually means. That conversation reinforced why I have been asking this question for decades.

Proof Over Paperwork: FedRAMP's Shift From Rev5 to 20x

Government rarely moves first on anything, which is what makes the current change at FedRAMP worth attention. The Federal Risk and Authorization Management Program is the seal that lets cloud providers sell to federal agencies, and for years it has been synonymous with a particular way of proving security: a very large stack of documents, assessed once, and revisited on an annual cadence.

Book Review: From Heatmaps to Histograms

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.

Changing the Conditions of the Test: Command Judgment, the Digital Twin & the Next Frontier of GRC

In a recent piece on my site, I wrote about Captain Batel's digital twin, and about what I am calling GRC 7.0 — GRC Orchestrate. I made the case that the future of risk management is not another dashboard bolted onto yesterday's process, but a living model of the enterprise that senses, simulates, and orchestrates response. That piece generated more conversation than almost anything I have written this year, and one question kept surfacing in different forms, from different people, in different words. If the digital twin can model the scenario, simulate the intervention, and recommend the path . . . what is left for the human being standing on the bridge?