The Two Factors Killing GRC Practices

Jean-Christophe Gaillard Jean-Christophe Gaillard
September 7, 2019 Big Data, Cloud & DevOps

Excessive complexity and lack of first line integration render many GRC metrics useless

Many CISOs complain of communication problems with their business. They are not being listened to. They are not getting the budget they think they should get. They feel their business prioritises against security too often.

It has been a recurring theme amongst information security professionals for the best part of the last 15 years, and it is rooted in a wide range of factors, amongst which the profile of the CISO is often a dominant limitation.

Many CISOs are simply too technical: They know they need to bridge the gap with their business, but they often return to their comfort zone at the first opportunity: For them, “threats” is often translated into malware, phishing and hackers, while the business wants to hear insider fraud or intellectual property theft.

This often leads to the CISO role being ringfenced and limited to its first line technical remit, while GRC functions develop in second line of defence.

But those functions themselves very often struggle to develop meaningful conversations with their business around cyber security.

GRC teams tend to have an ivory-towered view of the problem and to rely on ready-made overly complex methodologies, loosely related to the reality of first line activities.

They rush into buying some tech platform which is supposed to “enable” the GRC process, but in reality, the jargon of those products and methodologies is often meaningless to the business. Impact assessments and risk assessments can be inextricably complex. The quality of the data collected is often questionable as a result, and many of those approaches never scale up for good in large firms due to the sheer human cost of deploying them.

The lack of hard-wiring to first line activities make the GRC metrics produced artificial, and unusable in practice to recommend, justify or manage first line investment. If, in addition, the scope covered is limited due to deployment or acceptance issues, the overall value of such metrics can be highly disputable – beyond the proverbial “tick-in-the-box” which they will invariably provide.

None of that helps the business understand and manage their cyber risk posture. Over time, distrust sets in and, as the “when-not-if” paradigm around cyber-attacks takes root in the boardroom, senior executives need to find a way out.

It can only involve refocusing GRC practices towards simplicity so they can be effectively and efficiently deployed on a large scale across the real breadth of the firm – and possibly towards its supply chain.

It will also involve refocusing GRC practices towards a proper and meaningful integration with first line cyber security data, so that GRC metrics reflect the reality of the first line of defence.

The “when-not-if” paradigm makes the Board increasingly willing to invest to ensure the protection of the firm from cyber threats, but it also shifts priorities towards measuring progress and ensuring things get done.

In many firms, the equation between Governance, Risk and Compliance around cyber security is becoming heavily weighted towards the G, and GRC functions must adjust as a result, both in terms of internal structures and in terms of interactions with other stakeholders.

In particular, first line and second line must work together on this. They must trust each other and look beyond absurd and arbitrary “separation of duties” concepts, to produce meaningful data for the business, around which meaningful decisions will be made to protect the firm.

  • Experfy Insights

    Top articles, research, podcasts, webinars and more delivered to you monthly.

  • Jean-Christophe Gaillard

    Tags
    Fraud & Risk
    Leave a Comment
    Next Post
    How Data Science teams can be more methodical – Part 1

    How Data Science teams can be more methodical – Part 1

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    More in Big Data, Cloud & DevOps
    Big Data, Cloud & DevOps
    Cognitive Load Of Being On Call: 6 Tips To Address It

    If you’ve ever been on call, you’ve probably experienced the pain of being woken up at 4 a.m., unactionable alerts, alerts going to the wrong team, and other unfortunate events. But, there’s an aspect of being on call that is less talked about, but even more ubiquitous – the cognitive load. “Cognitive load” has perhaps

    5 MINUTES READ Continue Reading »
    Big Data, Cloud & DevOps
    How To Refine 360 Customer View With Next Generation Data Matching

    Knowing your customer in the digital age Want to know more about your customers? About their demographics, personal choices, and preferable buying journey? Who do you think is the best source for such insights? You’re right. The customer. But, in a fast-paced world, it is almost impossible to extract all relevant information about a customer

    4 MINUTES READ Continue Reading »
    Big Data, Cloud & DevOps
    3 Ways Businesses Can Use Cloud Computing To The Fullest

    Cloud computing is the anytime, anywhere delivery of IT services like compute, storage, networking, and application software over the internet to end-users. The underlying physical resources, as well as processes, are masked to the end-user, who accesses only the files and apps they want. Companies (usually) pay for only the cloud computing services they use,

    7 MINUTES READ Continue Reading »

    About Us

    Incubated in Harvard Innovation Lab, Experfy specializes in pipelining and deploying the world's best AI and engineering talent at breakneck speed, with exceptional focus on quality and compliance. Enterprises and governments also leverage our award-winning SaaS platform to build their own customized future of work solutions such as talent clouds.

    Join Us At

    Contact Us

    1700 West Park Drive, Suite 190
    Westborough, MA 01581

    Email: support@experfy.com

    Toll Free: (844) EXPERFY or
    (844) 397-3739

    © 2023, Experfy Inc. All rights reserved.