Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The GRC Economy

    I am often asked, “What do you do?” My simple answer, that I do not like, is to say that I am a consultant. This does not always help as the next question is “What type of consultant?”, or “What do I consult on?” I end up having to explain that what I actually am…

  • IT GRC Management by Design, New York

    IT GRC Management by Design, New York

    Organizations are complex. Exponential growth and change in technology, vulnerabilities, regulations, globalization, distributed operations, changing processes, competitive velocity, business relationships, legacy technology, and business data exposes organizations of all sizes. Keeping this complexity and change in sync is a significant challenge for information security professionals. Executives are constantly reacting to risk appearing around them and…

  • The Critical Foundation of Third Party Management is Technology

    The Critical Foundation of Third Party Management is Technology

    In previous posts we looked at the following: How to Develop a Third Party Management Strategy How to Define a Third Party Management Process Lifecycle Now we turn our attention to the foundation of information and technology that supports and enables a third party management strategy and process . . . Third party management fails…

  • How to Define a Third Party Management Process Lifecycle

    How to Define a Third Party Management Process Lifecycle

    The third party management strategy and policy is supported and made operational through a third party management architecture. The organization requires complete situational and holistic awareness of third party relationships across operations, processes, transactions, and data to see the big picture of third party performance and risk in context of organizational performance and strategy. Distributed,…

  • Understanding the Variety of GRC Intelligence & Content Solutions

    Understanding the Variety of GRC Intelligence & Content Solutions

    There are lots of GRC solutions available in the market, most of which do not even call themselves GRC as they are laser focused in specific GRC areas. In fact, I have mapped 843 GRC technology solution providers into and across 17 primary segments of the GRC market (and may sub-segments). Competition in RFPs, RFI,…

  • How to Develop a Third Party Management Strategy

    Managing third party activities in disconnected silos leads the organization to inevitable failure. Without a coordinated third party management strategy the organization and its various departments never see the big picture and fail to put third party management in the context of business strategy, objectives, and performance, resulting in complexity, redundancy, and failure. The organization…

  • Enabling 360° Insight & Control of Third Party Relationships    

    Enabling 360° Insight & Control of Third Party Relationships    

    The Extended Enterprise Demands Attention The Modern Organization is an Interconnected Mess of Relationships No man is an island, entire of itself; Every man is a piece of the continent, a part of the main.[1] Substitute ‘man’ with ‘organization’ and seventeenth-century English poet John Donne could be describing the post-modern twenty-first century organization: “No organization…

  • Providing 360° Contextual Awareness of Risk

    Monitoring and Managing Risk Effectively A Challenge for Boards, Executives, and Risk Management Professionals Organizations take risks all the time but fail to monitor and manage risk effectively. Organizations need to understand how to monitor risk-taking, whether they are taking the right risks, and whether risk is managed effectively. A cavalier approach to risk-taking is…

  • Enabling an Integrated Compliance Lifecycle

    Inevitability of Failure Ineffective Processes to Manage Regulatory Change and Compliance Regulatory change is overwhelming organizations across industries. Organizations are past the point of treading water as they actively drown in regulatory change from turbulent waves of laws, regulations, enforcement actions, administrative decisions, and more around the world. Regulatory compliance and reporting is a moving target…

  • Enabling 360° Insight & Control of Third Party Relationships

    The Extended Enterprise Demands Attention Organizations are no longer a self-contained entity defined by brick and mortar walls and traditional employees. The modern organisation is comprised of a mixture of third party relationships that often nest themselves in complexity such as with deep supply chains. Two decades ago the term insider was synonymous with employee,…

  • Legal at the Center of GRC Leadership and Strategy

    Legal at the Center of GRC Leadership and Strategy

    Legal Challenges in a New Era Today’s global business environment presents a broad spectrum of economic, political, social, legal and regulatory changes, which continually increase strategic and tactical complexity, and create commensurate pressures on business performance and exponential growth of often conflicting and overlapping legal and business requirements alongside global operations. The enterprise must reliably…

  • Managing Change is the Greatest GRC Challenge

    Managing Change is the Greatest GRC Challenge

    Change is the single greatest challenge for organizations in the context of governance, risk management, and compliance (GRC). Managing the dynamic and intricate web of change and how it impacts the organization is driving organizations toward improving their approach to governance, risk management, and compliance (GRC) in the context of the organization’s enterprise architecture. The challenge…