Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

Wherever You Are on the FedRAMP 20x Journey, Know What Comes Next

There is a point in any FedRAMP program when the conversation has to leave the whiteboard. The target date is on the calendar. The evidence exists somewhere, though perhaps not in the form the new model expects. Controls are operating, responsibilities are divided among teams, and someone has to determine how much of what already exists can make the move to 20x.

Book Review: Mission-Critical Governance—Focusing on What Matters Most

I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. All of these are important components of GRC, but none of them is the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives. What ultimately matters, then, is not the volume of governance activity an organization can demonstrate, but whether it can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.

When Controls Compete With Each Other

A critical system goes down, and the operations team needs an administrator inside it immediately. Privileged access, however, requires approval, and the designated approver is unavailable. A change may restore the system, but normal procedure requires testing before anything reaches production. Meanwhile, the recovery clock is running.

The Compliance Illusion: When More Controls Create More Risk

There is a strange rule in compliance: when something goes wrong, organizations add a control. A regulator raises a concern? Add a control. An auditor finds a weakness? Add another. A cyberattack happens? Add three. A new framework arrives? Someone opens a spreadsheet. Nobody ever gets celebrated for deleting one.

Governing AI Between the Checkpoints

A few weeks ago, I wrote about a question that had followed me from a computer room in Milwaukee thirty years ago into today's conversations about agentic AI, "Where is the big red button?"

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

For a long time, seeing someone or hearing their voice gave us a reasonable level of confidence that we knew who we were dealing with. If your manager called, you recognized their voice. If a senior executive joined a video meeting, you could see them on the screen. There was usually little reason to question whether the person you were speaking to was actually who they claimed to be.

The “AI Employee” Is a Governance Failure Waiting to Happen

Corporate America has found a new way to signal its ambition: hiring software. Companies are giving artificial intelligence (AI) agents names, titles, and places on the organizational chart, and press releases celebrate the arrival of the “first AI employee” as though a person had walked through the door. According to MIT Technology Review’s James O’Donnell, nearly a third of the 1,261 managers surveyed in a recent Boston University study said their companies already frame AI agents as employees, and 23 percent list them on org charts.