Discussion about this post

User's avatar
Devin Ryder's avatar

Great write-up all around!

Expand full comment
Bill Frank's avatar

Your point about GRC is sad but true: "GRC platforms also fall into this category, ... but their role is to defend against auditors rather than attackers."

The reality is that GRC is Compliance. The risk management function is performed just to meet the compliance check box.

However, risk management can be reimagined to support defending against attackers. Then we'll move from grC to gRc. I call it Risk-Informed Defense.

Expand full comment
1 more comment...

No posts