Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The Human Firewall: Essential to Organizations

    The Human Firewall: Essential to Organizations

    Firewalls protect us. In buildings, it is a wall intended to shield and confine a fire to an area to protect the rest of the building. In a vehicle, it is a metal shield protecting passengers from heat and potential fire in the engine. In network security, it is the logical ingress and egress points…

  • Agile & Cognitive GRC: a New Generation in GRC Solutions

    Agile & Cognitive GRC: a New Generation in GRC Solutions

    I have been on the road regularly for the past six weeks with a heavy travel schedule through mid-July that brings me across the USA and Europe. Lots of interactions with people face-to-face and the conversations center on: How do we engage the front-line/office of the organization on GRC? How do we make GRC intuitive?…

  • Delivering 360° Third-Party Risk Situational Awareness

    Delivering 360° Third-Party Risk Situational Awareness

    A dynamic business environment requires the capability to actively manage risk intelligence and fluctuating risks impacting the organization and its relationships. The old paradigm of uncoordinated third-party risk management is inadequate given the volume of risk information, the pace of change, and the broader operational impact on today’s business environment and operations. Organizations need to…

  • 360° Risk Intelligence in the Extended Enterprise

    360° Risk Intelligence in the Extended Enterprise

    The Modern Organization is an Interconnected Web of Relationships The structure and reality of business today has changed. Traditional brick-and-mortar business is a thing of the past: physical buildings and conventional employees no longer define the organization. Instead, the modern organization is an interconnected web of relationships, interactions, and transactions that extend far beyond traditional…

  • How to Operationalize ESG with GRC

    How to Operationalize ESG with GRC

    Take advantage of GRC’s structured guidance to deliver on ESG strategy and processes. ESG – Environmental, Social, and Governance – is pressuring organizations from every angle. Investors are making investment decisions based on the ESG practices of companies. Individual directors on boards are being voted out based on ESG metrics. Employees are making decisions on…

  • Improving FedRAMP: Federal Procurement & Risk Management

    Improving FedRAMP: Federal Procurement & Risk Management

    The Federal Risk and Authorization Management Program (FedRAMP) has been in place for just over a decade (2011). Its purpose is to provide a “cost-effective, risk-based approach for the adoption and use of cloud services” by the federal government. This is to equip and enable federal agencies to utilize cloud technologies in a way that…

  • Operationalize Compliance to Ensure 360° Visibility into Operational Resilience 

    Operationalize Compliance to Ensure 360° Visibility into Operational Resilience 

    Gone are the years of simplicity in business operations. Rapid growth and change in risks, regulations, globalization, distributed operations, competitive velocity, technology, and business data encumbers organizations of all sizes. Keeping business strategy, compliance, uncertainty, complexity, and change in sync is a significant challenge for boards and executives and management professionals throughout all levels of…

  • How do you add compliance controls in different parts of your business?

    How do you add compliance controls in different parts of your business?

    Organizations often fail to monitor and manage compliance controls effectively in an environment that demands agility. This results in the inevitable failure of compliance that provides case studies for future generations on how poor internal control management leads to the demise of organizations: even those with strong brands. Today’s business environment is complex. Exponential growth…

  • Strategies to Drive Compliance Operationalization

    Strategies to Drive Compliance Operationalization

    Organizations need to be organizations of integrity. What we communicate to the world about our policies, compliance and ethics practices, values, code of conduct, regulatory commitments, and now ESG statements is a reality in the organization and not fiction. The Chief Ethics and Compliance Officer (CECO) has become the Chief Integrity Officer of the organization.…

  • IRM Risk Predictions 2022

    IRM Risk Predictions 2022

    IRM – Surprise! But it its not what you think. I have not changed my stance on Gartner’s misaligned Integrated Risk Management. This is the Institute of Risk Management, the real IRM in which I am a Global Ambassador of Risk Management as well as an Honorary Life Member. They published a great report on…

  • Breaking Silos with GRC and Legal

    Breaking Silos with GRC and Legal

    Organizations take legal risks all the time but often fail to integrate these risks effectively in an environment that is continuously changing and requires agility. Too often legal is seen as a siloed exercise and not truly integrated with the organization’s strategy, decision-making, objectives, and overall enterprise risk management strategy. This results in inevitable exposures in legal…

  • Rethinking Risk Across the Enterprise

    Rethinking Risk Across the Enterprise

    Gone are the days of simplicity in business operations. The challenges that are thrown by ever-changing regulations, distributed operations, highly competitive business landscape, evolving technologies, and huge volumes of business data encumber organizations of all sizes. Risk management has become a challenge for CXOs, as well as managers throughout all levels of the organization. The…