Insights

Exploited Vulnerability: Activision Blizzard Faces Growing Scrutiny Over Mobile Game Monetization

Video games were once a hobby defined by premium products. Consoles often cost several hundred dollars, and games themselves were priced around $60 for most of the last two decades. Purchasing a console and building a collection of games was an intentional act. A console is no small purchase, especially for a young audience or the generous parent. The purchase of individual games was typically a decision informed by quality and value from a discerning consumer.

Some Internal Audit Wisdom

In this article, Norman Marks reflects on a handful of recent and not-so-recent pieces that, taken together, offer a revealing snapshot of where internal audit is headed and where it may be at risk of losing its way. Drawing on insights from industry leaders, consultants, and former global audit officials, Marks contrasts the profession’s growing ambition around agility, insight, and relevance with an increasingly prescriptive standards environment that threatens creativity, judgment, and imagination. The result is both a cautious critique and a hopeful argument for an internal audit function that stays forward-looking, tailored to the business, and grounded in professional judgment rather than rigid process.

2026 GRC, Ethics & Compliance Guide: Trends You Need to Stay Ahead

In 2025, the balance between risk and reward became materially more consequential. Advances in AI, rising expectations for operational resilience, and intensifying regulatory scrutiny reshaped executive agendas and exposed the limits of reactive risk management. Some organizations adapted quickly, using governance, risk, compliance, ethics, and learning to move faster with confidence. Others struggled to keep pace.

Third-Party Risk & the Quiet Collapse of Accountability

Third-party risk rarely announces itself with alarms. More often, it arrives quietly, disguised as an assumption. The assumption is that responsibility can be shared without consequence. That accountability can be distributed, diluted, and still hold its shape when pressure arrives. That contracts, frameworks, and carefully worded clauses will stand in for human judgment when systems fail and decisions cannot wait.

Unlocking the Hidden Value in Your Current GRC Platform

In this article, Ayoub Fandi examines how organizations can unlock untapped value in their existing GRC platforms by applying an engineering mindset rather than defaulting to new tools or costly overhauls. Drawing on practical experience, he explores why most GRC platforms remain significantly underused and how data optimization, strategic integrations, and workflow design can transform them from passive documentation systems into active drivers of risk and control execution.

What Happens When Prevention Fails, & Cyber Resilience Takes Over

For years, cybersecurity has been treated like a home alarm system. You install it, arm it, and hope it only goes off when something truly bad happens. The problem is that modern cyber threats no longer behave like burglars rattling windows at night. They act more like termites, quietly weakening structures over time, or like flash floods that overwhelm defenses faster than alarms can react. In this environment, reacting after the fact is no longer enough. Organizations must move from reactive cybersecurity to proactive cyber resilience.

The Problem With Risk Registers in Modern ERM

In my latest post, I discuss how if you look at how enterprise risk management is practiced today, you’d be forgiven for thinking that the entity-level risk register sits at the center of ISO 31000 and COSO ERM. It doesn’t.