175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
Risk that enters an organization through acquisition, outsourcing, partnership, or technology adoption does not carry with it a reduced governance obligation.
The quarterly governance report showed improvement across eight of twelve tracked metrics. Patching coverage up four percent. Training completion at 97 percent, a three-y…
Governance programs are typically designed and validated in environments of manageable complexity: a defined set of systems, a stable organizational structure, a bounded…
Policy is written by humans reasoning about how systems should behave. Systems behave according to how they were configured, integrated, and deployed — which reflects the…
Control frameworks describe how organizations should manage risk. They specify what controls should exist, how they should be designed, and what evidence should demonstra…
Governance programs are measured on activity because activity is measurable. The number of controls assessed, the number of findings remediated, the number of training co…
The post-incident risk register still showed the affected system at a score of 2.3 out of 10. The scoring model had evaluated the system six months earlier against the st…
Every significant governance policy in a mature organization has a named owner. The data protection policy is owned by the DPO. The information security policy is owned b…
A governance program without a blind spot is not a governance program — it is a theoretical construct. Every program is built around what its designers knew, what the org…
GRC platforms are sophisticated, expensive, and widely deployed. They link controls to frameworks, track evidence, manage findings, produce dashboards, and generate audit…
Enterprise governance programs assign accountability with confidence. Risk owners are named. Control owners are documented. The RACI is populated and reviewed.
The governance program had a perfect audit record. No significant findings in four consecutive external audits. Internal audit consistently rated the security program as…
Governance frameworks are excellent tools for the governance problems they were designed to solve. NIST CSF provides structure for cybersecurity risk management.
The governance program had been in place for four years. It had passed external audits. It had received favorable board assessments. The maturity scores had improved cons…
Risk accumulates in the space between reporting cycles. Not catastrophically — not in events that are unmistakable at the time. It accumulates through the incremental dec…
Board discussions of strategic risk are substantive. The risk that a competitor deploys AI capabilities faster than the organization. The risk that regulatory change affe…
The board assigned risk ownership for cyber risk to the CISO. The CISO assigned ownership of specific risks to business unit leaders. Business unit leaders assigned opera…
The governance framework covered the organization at its current scale. The risk committee structure, the control ownership model, and the reporting mechanisms were desig…
The incident started at 11:47pm on a Wednesday. The security operations team detected it at 12:14am. By 12:30am they needed a decision: contain the affected systems and a…
A modern data discovery platform can scan a petabyte-scale cloud environment in hours. It can identify thousands of sensitive data instances, classify them by type, assig…
Data classification programs produce labels. Confidential. Restricted. Internal. Public. The labels are applied with effort and maintained with care.
Most security and governance programs have reasonably good visibility at the system level: the asset inventory captures the servers, the applications, the cloud resources…
Every organization with a privacy program has a data map of some kind. A record of processing activities. A data inventory. A system catalog with data categories.
Enterprise data security programs were designed when data lived in defined places: the data center, the database, the file server. The security model was perimeter-based:…