Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-203 · AI Governance · 10 min

AI Systems Become High Risk Without Organizations Realizing It

The EU AI Act does not classify AI systems by what organizations intend them to do. It classifies them by what they actually do, and by the context in which they operate.

DTG-200 · Privacy Governance · 8 min

Privacy Programs Look Mature. Until You Test Them

Privacy program maturity assessments measure whether the right elements are in place: policies documented, processes defined, tools deployed, responsibilities assigned.

DTG-199 · Privacy Governance · 8 min

Privacy Metrics Are Reported. They Do Not Reflect Exposure

Privacy programs report on what they measure. They measure what they can count. What they can count is process activity: training completion rates, DPIA completion rates,…

DTG-196 · Privacy Governance · 8 min

Privacy Controls Are Designed. They Are Not Monitored

A privacy control that exists and functions is a governance achievement. A privacy control that exists and is not monitored for continued effectiveness is documentation o…

DTG-193 · Privacy Governance · 8 min

Third-Party Data Sharing Is Disclosed. It Is Not Controlled

Privacy notices disclose that data is shared with third parties. Data processing agreements govern how those parties are permitted to use data.

DTG-189 · Privacy Governance · 8 min

Deletion Requests Are Fulfilled. They Are Not Fully Completed

A deletion workflow that finds and removes data from the systems it was designed to search is a deletion workflow that works correctly within its defined scope.

DTG-187 · Privacy Governance · 11 min

Consent Is Captured. Usage Extends Beyond It

Consent creates a specific authorization for a specific processing activity. Organizations capture consent at a single point and then process data across dozens of system…

DTG-185 · Privacy Governance · 10 min

Data Minimization Is Declared. It Is Not Operationalized

Every privacy policy says it. Every framework requires it. Almost no enterprise has operationalized it at the level its operational data estate requires.

DTG-171 · NIST CSF in Practice · 8 min

Response Plans Exist. Execution Is Improvised

Incident response plans are one of the most universally documented governance artifacts in enterprise security. They are required by every major framework.

DTG-162 · NIST CSF in Practice · 8 min

Data Protection Controls Exist. They Don't Follow the Data

Data protection controls are implemented at known data locations. Data moves to unknown locations constantly: copied to analytics environments, exported to SaaS tools, ca…

DTG-151 · NIST CSF in Practice · 8 min

NIST CSF 2.0 Defines Governance Clearly. Execution Is Where It Breaks

NIST CSF 2.0 introduced a Govern function that sits above and connects Identify, Protect, Detect, Respond, and Recover. The governance mandate is clear: organizations mus…

DTG-142 · Board & Executive Governance · 11 min

Board Reports Highlight Activity. Not Exposure

Boards receive reports that describe what the security and privacy organization has done: incidents responded to, controls implemented, assessments completed, training de…

DTG-137 · Identity Governance · 8 min

Identity Governance in SaaS Is Fragmented by Design

Enterprise identity governance was built on the premise that identity is centralized: a directory, an IAM platform, a set of federation standards.

DTG-132 · Identity Governance · 8 min

Privilege Escalation Happens Within Approved Access

Privilege escalation is typically framed as a security concern about attackers gaining access beyond what they were authorized to have. The more common and more difficult…

DTG-128 · Identity Governance · 10 min

Access Provisioning Is Automated. Revocation Is Not

Organizations have built excellent infrastructure for giving people access. Joining triggers automation: account creation, group assignment, license provisioning, entitle…

DTG-126 · Identity Governance · 8 min

Privileged Access Expands Faster Than It Is Governed

Every system addition is a potential privileged access expansion. Every cloud resource provisioned, every SaaS application deployed, every microservice added creates a ne…

DTG-125 · Identity Governance · 10 min

Service Accounts Are the Most Overlooked Risk Surface

Service accounts are the identity type that enterprise governance programs most consistently underaddress. Human accounts are governed by HR processes, access reviews, an…

DTG-122 · Identity Governance · 10 min

Least Privilege Is a Principle. Not an Operational Reality

Least privilege is one of the most widely adopted access control principles in enterprise security. It is documented in every security framework, required by every compli…

DTG-121 · Identity Governance · 9 min

Access Control Works. Until Privilege Accumulates Over Time

Access controls are designed to enforce defined permissions at a point in time. They do not prevent permissions from accumulating over time as users change roles, join pr…

DTG-119 · GRC & Control Reality · 8 min

Audit Findings Reflect Gaps. Not Root Causes

An audit finding identifies what was observed: a control was absent, a process was not followed, evidence was missing, a configuration was incorrect.

DTG-116 · GRC & Control Reality · 11 min

Control Coverage Looks Complete. Until You Follow the Data

Governance programs map controls to systems. Data does not follow system boundaries. It moves between systems, through integrations, across vendor boundaries, and into en…

DTG-114 · GRC & Control Reality · 8 min

Your GRC Tool Tracks Controls. Not Reality

GRC platforms are excellent at tracking what organizations have documented about their control environments. They track policy assignments, control mappings, audit eviden…

DTG-109 · GRC & Control Reality · 8 min

Metrics Show Progress. But Hide Risk

Security and governance metrics are designed to show improvement over time. They measure training completion, patch coverage, vulnerability closure rates, and control ass…

DTG-108 · GRC & Control Reality · 8 min

Audit Readiness Creates a False Sense of Security

Audit readiness programs are designed to produce passing audit outcomes. They are effective at this objective. The governance problem is that passing an audit and having…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center