DTG-G29 · GRC & Control Reality · 4 min

Inherited Risk Is Still Your Risk

Risk that enters an organization through acquisition, outsourcing, partnership, or technology adoption does not carry with it a reduced governance obligation.

DTG-G25 · GRC & Control Reality · 4 min

The Metrics Improved. The Risk Position Didn't

The quarterly governance report showed improvement across eight of twelve tracked metrics. Patching coverage up four percent. Training completion at 97 percent, a three-y…

DTG-G23 · GRC & Control Reality · 4 min

Why Governance Programs Fail at Scale

Governance programs are typically designed and validated in environments of manageable complexity: a defined set of systems, a stable organizational structure, a bounded…

DTG-G22 · GRC & Control Reality · 4 min

The Gap Between Policy Intent and System Behavior

Policy is written by humans reasoning about how systems should behave. Systems behave according to how they were configured, integrated, and deployed — which reflects the…

DTG-G17 · GRC & Control Reality · 4 min

The Illusion of Control in a Distributed Enterprise

Control frameworks describe how organizations should manage risk. They specify what controls should exist, how they should be designed, and what evidence should demonstra…

DTG-G15 · GRC & Control Reality · 4 min

Stop Measuring Governance Activity. Start Measuring Governance Outcome

Governance programs are measured on activity because activity is measurable. The number of controls assessed, the number of findings remediated, the number of training co…

DTG-G13 · GRC & Control Reality · 6 min

The Risk Score Said Low. The Incident Said Otherwise

The post-incident risk register still showed the affected system at a score of 2.3 out of 10. The scoring model had evaluated the system six months earlier against the st…

DTG-G11 · GRC & Control Reality · 4 min

Policy Ownership Without Operational Accountability Is Theater

Every significant governance policy in a mature organization has a named owner. The data protection policy is owned by the DPO. The information security policy is owned b…

DTG-G09 · GRC & Control Reality · 5 min

Every Governance Program Has a Blind Spot. Most Don't Know Where It Is

A governance program without a blind spot is not a governance program — it is a theoretical construct. Every program is built around what its designers knew, what the org…

DTG-G04 · GRC & Control Reality · 5 min

Your GRC Tool Is a Filing Cabinet, Not a Control Program

GRC platforms are sophisticated, expensive, and widely deployed. They link controls to frameworks, track evidence, manage findings, produce dashboards, and generate audit…

DTG-382 · GRC & Control Reality · 10 min

Control Implementation Does Not Equal Control Effectiveness

A control that exists is not a control that works. Enterprise governance programs measure control implementation: whether a control has been defined, deployed, and docume…

DTG-312 · GRC & Control Reality · 9 min

Evidence Is Point-in-Time. Risk Is Continuous

Compliance evidence documents the state of controls at the time evidence was collected. Risk accumulates in the space between evidence collection events.

DTG-303 · GRC & Control Reality · 8 min

Audits Confirm Compliance. Not Effectiveness

An audit that confirms compliance confirms that the required elements exist. It does not confirm that those elements produce the intended outcomes.

DTG-229 · GRC & Control Reality · 7 min

Compliance Is Point-in-Time. Risk Is Continuous

Every compliance assessment produces a result that was accurate when it was produced. The environment that assessment described has continued changing from the moment it…

DTG-119 · GRC & Control Reality · 8 min

Audit Findings Reflect Gaps. Not Root Causes

An audit finding identifies what was observed: a control was absent, a process was not followed, evidence was missing, a configuration was incorrect.

DTG-116 · GRC & Control Reality · 11 min

Control Coverage Looks Complete. Until You Follow the Data

Governance programs map controls to systems. Data does not follow system boundaries. It moves between systems, through integrations, across vendor boundaries, and into en…

DTG-114 · GRC & Control Reality · 8 min

Your GRC Tool Tracks Controls. Not Reality

GRC platforms are excellent at tracking what organizations have documented about their control environments. They track policy assignments, control mappings, audit eviden…

DTG-109 · GRC & Control Reality · 8 min

Metrics Show Progress. But Hide Risk

Security and governance metrics are designed to show improvement over time. They measure training completion, patch coverage, vulnerability closure rates, and control ass…

DTG-108 · GRC & Control Reality · 8 min

Audit Readiness Creates a False Sense of Security

Audit readiness programs are designed to produce passing audit outcomes. They are effective at this objective. The governance problem is that passing an audit and having…

DTG-107 · GRC & Control Reality · 8 min

Control Testing Stops Where Complexity Begins

Control testing programs are designed around the controls that can be tested within defined timeframes, with available tooling, and against stable system configurations.

DTG-106 · GRC & Control Reality · 9 min

Most Risk Registers Capture Opinions, Not Exposure

Risk registers document the risks that were identified during risk assessments conducted by the people who were in the room when the risk assessment was conducted.

DTG-105 · GRC & Control Reality · 8 min

Your Governance Framework Doesn't Match Your Architecture

Governance frameworks describe how organizations should control their information assets. Enterprise architectures describe how organizations actually operate their infor…

DTG-104 · GRC & Control Reality · 8 min

Control Effectiveness Is Assumed. Rarely Proven

The difference between a control that works and a control that is assumed to work is the gap between governance that reduces risk and governance that documents the intent…

DTG-103 · GRC & Control Reality · 9 min

Evidence Collection Is Broken Long Before the Audit Begins

Audit readiness programs treat evidence collection as something that happens before an audit. In reality, the conditions that make evidence collection possible, or imposs…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center