Behind the Screens – GRC Chaos due to Systems and Processes

Behind the Screens – GRC Chaos due to Systems and Processes

Operational Challenges in Implementing Tech GRC In an earlier post I talked about the why organizations face difficulties as they implement a sound Technology GRC program. As I mentioned, there are three types of factors. Environmental, those outside your control Strategic, how you choose to respond. And  Operational, how your response is implemented, which is […]

Is the Human Firewall Up? GRC’s People Issues

Is the Human Firewall Up? GRC’s People Issues

As I have mentioned earlier in my blogs on “Cyber attacks – What you cant see can hurt you” , “urgent is Loud and Important is quiet” and “Threats change faster than you can react”, organizations are constantly changing and evolving in response to the changing marketplace, customer needs, and threat environment. Organizations realize the value […]

From Fines to Foresight: How AI Is Redefining GRC in 2025 (Series 1)

From Fines to Foresight: How AI Is Redefining GRC in 2025 (Series 1)

“Could this have been prevented?” That’s the haunting question every technology leader and compliance officer asks after a major failure — when systems go down, customer data is exposed, or auditors uncover gaps that should have been caught months earlier. Take one example: a Fortune 500 global bank fined $1.5 billion for failing to maintain […]

The Technology GRC maze: What a tangled web we have woven

The Technology GRC maze: What a tangled web we have woven

Why manage technology Governance Risk and Compliance? And how? Because to err is human, to really mess things up requires a computer. I am sure you have heard the Paul Ehrlich saying. Now take it a step further, connect those computers. You now have  a recipe for conditions that can go from zero to disaster, […]

Complexity of a GRC Program – Are You Losing 4% of Your Workforce Without Noticing?

Complexity of a GRC Program – Are You Losing 4% of Your Workforce Without Noticing?

4% of your workforce. On an ongoing basis! This is what GRC tasks will exact from you if they are not managed well. This is the magnitude of ‘things’ that an organization must deal with just to ensure it is in line with the generally accepted practices to keep its data and computing infrastructure safe […]

Making Compliance Simpler: The Power of the Unified Compliance Framework

Making Compliance Simpler: The Power of the Unified Compliance Framework

Making Compliance Simpler: The Power of the Unified Compliance Framework Managing Technology Compliance can get really complex. From GDPR and HIPAA to ISO 27001, NIST CSF, and more, there’s always a new mandate to follow, each with its own requirements, documentation, and reporting formats. There are regulations by the governing bodies like RBI, SEBI, IRDAI […]

Don’t Wait for a Fire to Test Your Fire Alarm: Check Your GRC Maturity Now

Don’t Wait for a Fire to Test Your Fire Alarm: Check Your GRC Maturity Now

Let’s be honest — Governance, Risk, and Compliance (GRC) often feels like a maze of policies, audits, and checklists. For many organizations, GRC is something they do because they must — not because they truly understand how well it’s working.  So, Where Do We Begin?  Before you can improve your GRC efforts, you need to […]

Urgent is Loud, Important is Quiet

Urgent is Loud, Important is Quiet

Urgent is Loud, Important is Quiet Are you listening to the quiet stuff? In some of my earlier posts I talked about factors that influence challenges that organizations face in implementing a sound Technology GRC program. As I mentioned, there are three types of factors. Environmental, those outside your control – Earlier Blog Strategic, how you […]

From Crisis to Compliance : An opportunity to implement SEBI mandates that will ensure Peace of Mind

From Crisis to Compliance : An opportunity to implement SEBI mandates that will ensure Peace of Mind

In a key development for regulated entities, the Securities and Exchange Board of India (SEBI) has extended the deadline for implementing Technology Compliance from the original date to August 31, 2025. The Banking, Financial Services and Insurance (BFSI) sector is navigating legacy technologies, rising risks, and at the same time trying to comply with SEBI […]

Threats change faster than you can react

Threats change faster than you can react

Environmental Challenges in Technology GRC Progress is man’s ability to complicate simplicity – Thor Heyerdahl As anything grows, gets wider acceptability, and achieves success, it goes from self-regulation to being regulated by norms. However, this success attracts people who want to take advantage and profit from dubious exploitation of that success. And that finally brings […]

Cyberattacks – What you can’t see can hurt you.

Cyberattacks – What you can’t see can hurt you.

Why is Technology GRC so difficult? “There are only two types of companies: those that know they’ve been compromised, and those that don’t know.” I am sure you have heard some variation of this quote variously attributed to John Chambers (former CEO of CISCO) or to Dmitri Alperovitch (formerly of McAfee) So, why is it […]