Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-G29 · GRC & Control Reality · 4 min

Inherited Risk Is Still Your Risk

Risk that enters an organization through acquisition, outsourcing, partnership, or technology adoption does not carry with it a reduced governance obligation.

DTG-G25 · GRC & Control Reality · 4 min

The Metrics Improved. The Risk Position Didn't

The quarterly governance report showed improvement across eight of twelve tracked metrics. Patching coverage up four percent. Training completion at 97 percent, a three-y…

DTG-G23 · GRC & Control Reality · 4 min

Why Governance Programs Fail at Scale

Governance programs are typically designed and validated in environments of manageable complexity: a defined set of systems, a stable organizational structure, a bounded…

DTG-G22 · GRC & Control Reality · 4 min

The Gap Between Policy Intent and System Behavior

Policy is written by humans reasoning about how systems should behave. Systems behave according to how they were configured, integrated, and deployed — which reflects the…

DTG-G17 · GRC & Control Reality · 4 min

The Illusion of Control in a Distributed Enterprise

Control frameworks describe how organizations should manage risk. They specify what controls should exist, how they should be designed, and what evidence should demonstra…

DTG-G15 · GRC & Control Reality · 4 min

Stop Measuring Governance Activity. Start Measuring Governance Outcome

Governance programs are measured on activity because activity is measurable. The number of controls assessed, the number of findings remediated, the number of training co…

DTG-G13 · GRC & Control Reality · 6 min

The Risk Score Said Low. The Incident Said Otherwise

The post-incident risk register still showed the affected system at a score of 2.3 out of 10. The scoring model had evaluated the system six months earlier against the st…

DTG-G11 · GRC & Control Reality · 4 min

Policy Ownership Without Operational Accountability Is Theater

Every significant governance policy in a mature organization has a named owner. The data protection policy is owned by the DPO. The information security policy is owned b…

DTG-G09 · GRC & Control Reality · 5 min

Every Governance Program Has a Blind Spot. Most Don't Know Where It Is

A governance program without a blind spot is not a governance program — it is a theoretical construct. Every program is built around what its designers knew, what the org…

DTG-G04 · GRC & Control Reality · 5 min

Your GRC Tool Is a Filing Cabinet, Not a Control Program

GRC platforms are sophisticated, expensive, and widely deployed. They link controls to frameworks, track evidence, manage findings, produce dashboards, and generate audit…

DTG-EG22 · Board & Executive Governance · 4 min

Accountability Without Visibility Is Just Blame With Extra Steps

Enterprise governance programs assign accountability with confidence. Risk owners are named. Control owners are documented. The RACI is populated and reviewed.

DTG-EG20 · Board & Executive Governance · 5 min

The Governance Program That Survived Every Audit and Failed One Incident

The governance program had a perfect audit record. No significant findings in four consecutive external audits. Internal audit consistently rated the security program as…

DTG-EG19 · Board & Executive Governance · 4 min

Hardest Problems in Enterprise Governance Don't Have Framework Answers

Governance frameworks are excellent tools for the governance problems they were designed to solve. NIST CSF provides structure for cybersecurity risk management.

DTG-EG16 · Board & Executive Governance · 4 min

The Incident That Revealed How Shallow the Governance Program Actually Was

The governance program had been in place for four years. It had passed external audits. It had received favorable board assessments. The maturity scores had improved cons…

DTG-EG13 · Board & Executive Governance · 5 min

The Quiet Accumulation of Risk That the Quarterly Report Never Captured

Risk accumulates in the space between reporting cycles. Not catastrophically — not in events that are unmistakable at the time. It accumulates through the incremental dec…

DTG-EG10 · Board & Executive Governance · 4 min

Strategic Risk Is Easy to Discuss. Operational Risk Is Where Leaders Go Quiet

Board discussions of strategic risk are substantive. The risk that a competitor deploys AI capabilities faster than the organization. The risk that regulatory change affe…

DTG-EG07 · Board & Executive Governance · 4 min

Delegating Risk Ownership Without Delegating Risk Visibility Is Not Governance

The board assigned risk ownership for cyber risk to the CISO. The CISO assigned ownership of specific risks to business unit leaders. Business unit leaders assigned opera…

DTG-EG05 · Board & Executive Governance · 4 min

Governance That Scales on Paper and Fragments Under Pressure

The governance framework covered the organization at its current scale. The risk committee structure, the control ownership model, and the reporting mechanisms were desig…

DTG-EG02 · Board & Executive Governance · 5 min

Everyone Owned the Risk. Nobody Got the Call at 2am

The incident started at 11:47pm on a Wednesday. The security operations team detected it at 12:14am. By 12:30am they needed a decision: contain the affected systems and a…

DTG-DV19 · Data Visibility · 4 min

Discovery at Machine Speed. Governance at Human Speed. The Gap Is the Risk

A modern data discovery platform can scan a petabyte-scale cloud environment in hours. It can identify thousands of sensitive data instances, classify them by type, assig…

DTG-DV11 · Data Visibility · 4 min

Classification Without Consequence Is Just Labeling

Data classification programs produce labels. Confidential. Restricted. Internal. Public. The labels are applied with effort and maintained with care.

DTG-DV08 · Data Visibility · 4 min

Visibility at the System Level and Blindness at the Data Level

Most security and governance programs have reasonably good visibility at the system level: the asset inventory captures the servers, the applications, the cloud resources…

DTG-DV07 · Data Visibility · 4 min

The Data Map and the Data Reality: How Wide Is the Gap in Your Organization?

Every organization with a privacy program has a data map of some kind. A record of processing activities. A data inventory. A system catalog with data categories.

DTG-DS25 · Data Security · 4 min

Protecting Data Across the Multicloud Is a Different Problem Than Protecting It in One Place

Enterprise data security programs were designed when data lived in defined places: the data center, the database, the file server. The security model was perimeter-based:…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center