Blog tag

GRC Strategy & Implementation

Articles from the SimpleRisk blog tagged GRC Strategy & Implementation: governance, risk management, and compliance insights.

Collaborative cybersecurity team in action

We're Not Going to Pretend

Every GRC vendor is announcing AI capabilities right now. Here’s what we actually do, what we don’t do, and where we’re going; in plain language.

Navigating third-party risks with proper governance

Navigating Third-Party Risk with Robust Governance

Robust governance provides a sustainable way to mitigate third-party and supply-chain risk by establishing clear ownership, accountability, and transparency across all of the organization's vendor and partner relationships.
CISO presenting IT governance and business strategy alignment to enterprise leadership

IT Governance and Business Strategy: A CISO Playbook

With the right game plan, CISOs can turn IT governance from a perceived constraint into a driver of growth, resilience, and executive confidence. This nine-step playbook shows how to align security-centric governance with real business strategy.
Chaotic Assessments to Third-Party Risk Calm

From 16 Vendor RFIs to One Assessment

Tired of juggling 16 separate vendor RFIs every year? Discover how SimpleRisk transformed one client’s chaotic third-party assessments into a single, streamlined process.

ROI of Security Investment

The Boardroom Battle: Justifying Security Spend

For many CISOs, the hardest part of the job can be the business conversation that happens long before anything goes wrong. Learn the language of the boardroom to win over executive decision makers and justify security spending.

An old man with a grey beard sitting at a computer with soldiers at the castle gate

From Chaos to Control: Centralize Your GRC

If Excel were enough for risk management, the GRC industry wouldn’t exist. Here’s why relying on spreadsheets and generic SaaS tools can actually increase risk, and how centralization restores control.

Risk puzzle pieces containing IT Risk, Supply Chain Risk and Operational Risk

Why 2025 Needs One Complete Risk Assessment

Your IT, supply chain, and operations teams may all see the same risks—but they don’t measure them the same way. That gap could be the biggest security vulnerability in your organization today.

Risk Management is Like Camping But With Higher Stakes

Risk Management Is Just Like Camping—But With Higher Stakes

What do flash floods, frozen tents, and soggy sleeping bags have to do with business? Turns out, camping mishaps are full of risk management lessons every leader should know.

A cybersecurity analyst is reviewing a vendor risk assessment on a laptop screen

Third-Party Risk Lessons from the Rock Face

Choosing the right third-party vendors is a lot like picking a reliable climbing partner—technical skills matter, but alignment in risk mindset is just as crucial. Learn how a harrowing descent from a multi-pitch climb revealed key lessons in risk management, trust, and the value of security certifications.

A climber on a rock face with a background of office buildings creating a parallel between climbing risks and business risks

Luck Isn't a Strategy: Risk Lessons from Climbing

Risk management in business isn't about avoiding danger, it's about understanding and preparing for it. Just like a climber with the right gear, successful companies assess, train, and plan to face the unpredictable terrain ahead.

Cartoon hiker struggling to carry an overstuffed backpack on a rugged trail, symbolizing the burden of over-preparation.

GRC in the Wild: When Over-Preparation Becomes the Real Risk

Being prepared is crucial—but is there such a thing as being too prepared? My Big Bend backpacking misadventure taught me a valuable lesson about risk management, one that applies just as much to GRC as it does to the wilderness.

Combining GRC, HITRUST CSF and SCF for Streamlined Risk Management

Integrate HITRUST CSF and SCF in Your GRC Strategy

Struggling to align multiple compliance frameworks in your GRC program? Learn how to integrate HITRUST CSF and the Secure Controls Framework in SimpleRisk to streamline compliance, enhance security, and leverage AI for a more efficient risk management strategy.

Frustrated auditor not using SimpleRisk

From Audit Fatigue to Efficiency with SimpleRisk

Tired of audit fatigue and juggling multiple frameworks? Discover how SimpleRisk streamlines compliance by integrating the Secure Controls Framework (SCF) and centralizing audit activities, making it the ultimate tool for auditors seeking efficiency and precision.

Using Artificial Intelligence with FAIR

Using AI with FAIR for Precision and Scalability

Discover how combining the FAIR methodology with artificial intelligence revolutionizes risk management by providing precise, scalable, and data-driven insights. Learn how this powerful synergy enhances decision-making, optimizes resource allocation, and transforms how organizations approach risk quantification.

Boat Stranded on a River

The River Crisis That Taught Me to Always Have a Plan B

When our outboard motor failed in the middle of the Trinity River, leaving us adrift in a strong current, a cascade of unexpected challenges tested every backup plan we had. This story of quick thinking, layered preparedness, and lessons learned is a perfect metaphor for mastering risk management in life and business.

Policy Attestation

Annual Policy Attestation Made Easy with SimpleRisk

Struggling with ISO 27001 policy attestation and security awareness? Discover how a late-night epiphany turned SimpleRisk’s Assessment Extra into a seamless, auditable solution that even impressed our ISO auditor—no extra logins or fuss required!

Moving Beyond Leaky Faucets

Metrics That Matter: Proving Cybersecurity Value

How do you prove the value of your cybersecurity investments to the business? By shifting the focus from risk reduction to cybersecurity maturity, this post explores how to measure and communicate meaningful progress in building a stronger, more resilient organization.

Accidental Electrocution

Electrocuted on Thanksgiving: A Risk Management Lesson

A Thanksgiving mishap left me in the ER after a shocking encounter with some live wires—literally. This personal story of risk acceptance gone wrong is a reminder of why assessing and managing risks, both at home and in InfoSec, is so critical.

ISO 27001 Compliance in 18 Months

ISO 27001 Compliance in 18 Months

When a lost deal with the world’s largest healthcare company revealed a critical gap in SimpleRisk’s compliance posture, it set us on an 18-month journey to achieve ISO 27001 certification. From assessing our maturity and closing governance gaps to leveraging AI and tackling a rigorous third-party audit, we turned a challenge into an opportunity to enhance our operations and platform.

GRC 20/20 Solutions Perspective on SimpleRisk

Revolutionizing Risk Management: A GRC 20/20 View

In today’s complex business world, managing risks and compliance shouldn’t feel chaotic. Discover how SimpleRisk, as highlighted by Michael Rasmussen, the "Godfather of GRC," streamlines governance, risk, and compliance with efficiency and agility. Learn why organizations are switching to this game-changing platform in our latest blog post!

From Zero to ISO 27001 in 18 Months

Certified in 18 Months: Our ISO 27001 Journey

On September 26, 2024, SimpleRisk proudly earned its ISO 27001 certification after a focused 18-month effort to refine security practices and address control requirements. Despite personal hurdles, their journey highlights how dedication and the right tools make ambitious compliance goals achievable.

Barbed wire fence and security cameras in front of a building

Demystifying Residual Risk with SimpleRisk

Understanding residual risk is crucial in effective risk management, but calculating it can be complex, especially when considering multiple mitigating controls. In this post, we explore how SimpleRisk simplifies the process with an easy-to-understand mitigation percent approach that streamlines your risk reduction efforts.

Josh Sokol and Michael Rasmussen presenting on How to Model Security Maturity in Your Organization

Webinar Recap: Modeling Your Security Maturity

Check out this recap of the webinar, "How to Model Security Maturity in Your Organization," co-hosted by SimpleRisk and GRC 20/20. This webinar helped equip participants with a clear roadmap on how to establish a security maturity baseline within their own organizations, create a desired state of maturity, and identify where gaps exist in order to achieve their objectives.

A team of people planning out the strategy to mature their GRC program

7 Strategies to Mature Your GRC Program

Check out this guest blog from Michael Rasmussen of GRC 20/20 to learn about seven strategies to mature your existing GRC program for enhanced efficiency and effectiveness.

High five between team members to celebrate creating a repeatable, scalable compliance program

6 Ways to Create a Repeatable, Scalable Compliance Program

Check out this guest blog from Michael Rasmussen of GRC 20/20 to learn about six core elements required to craft compliance programs that meet current standards and are adaptable and scalable to meet future compliance challenges and opportunities.

Stock market ticker

New SEC Cybersecurity Regulation – What to Know

The Security and Exchange Commission (SEC) released its final rule on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, effective mid-December 2023. Check out this blog to learn what this ruling entails, how this new regulation may impact your organization, and what your organization needs to do ensure compliance.

Woman frustrated by constantly changing regulations

How to Keep Up with Regulatory Change

This guest blog by Michael Rasmussen of GRC 20/20 outlines how to define a process for regulatory change management and leverage the right technology to ensure your organization stays compliant.

Person climbing the stairs to get their information security program off the ground

Getting Your Information Security Program Off the Ground

Struggling with where to begin with your Information Security Program?  Learn how taking a risk-centric approach can help accomplish your goals.

CIS Critical Security Controls

Using the CIS Critical Security Controls with SimpleRisk

We are frequently asked about using the CIS Critical Security Controls in SimpleRisk.  In this blog post you will learn about the different ways you can use their controls with our platform.

Putting the pieces together for an effective GRC program

8 Simple Ways to Effectively Launch Your GRC Program

Learn the 8 fundamentals we recommend to establish an effective Enterprise Risk Management process from the ground up, which will set the stage for a successful GRC program rollout.

An attacker assessing your third-party risk

The Right and Wrong Way to Assess Third-Party Risk

In this post, SimpleRisk's Founder and CEO walks us through the different approaches to assessing and managing third-party risks.

A person manually responding to a questionnaire instead of using risk assessments

Responding to Inbound Risk Assessments with SimpleRisk

Learn how to use our Risk Assessment Extra to manage inbound assessments within SimpleRisk. Create a repeatable process without purchasing a separate tool.

Keeping things simple b y using the Secure Controls Framework in SimpleRisk

Using the ISO 27001 Control Framework with SimpleRisk

ISO 27001 has become the most requested framework to use within SimpleRisk.  In this blog post you will learn about the different ways you can use their controls with our platform.

A bowling ball disrupting the pins like SimpleRisk does to GRC

5 Reasons Why SimpleRisk is Disrupting the GRC Space

How can a relatively new vendor enter a mature market that has a multitude of established players and, with no outside funding, differentiate itself from the competition to make a global impact? Read on to learn how SimpleRisk is doing just that. 

People celebrating together about the ease of using a Common Control Framework

The Benefits of a Common Control Framework for GRC

Struggling with managing compliance across multiple different control frameworks?  Learn how a common control framework can help you to simplify your compliance, saving you time and money.

Understanding the basic principles of governance

Governance 101: Back to Basics

Let’s go back to the basics and talk about what governance is and how you can use it to ensure that the information that reaches your executive team and other key stakeholders is complete, accurate and timely.

Measuring the effectiveness of risk mitigations

How To Calculate Inherent vs. Residual Risk

Learn how to minimize the level of effort required to track a risk’s progress over time and how to measure the effectiveness of your risk mitigation.

Understanding the basics of compliance

Compliance 101: Back to Basics

Let’s go back to the basics and break down what enterprise compliance is and how you can use it to ensure your organization is conforming with its stated requirements.

Risk management using spreadsheets is time consuming and painful

Why Spreadsheets Are Killing Your GRC Practice

Many of the prospects we speak with are currently using spreadsheets to manage their risks. In this blog post we explore why that is a bad idea and how SimpleRisk provides a simple, effective and affordable alternative.

Frustrated CISO because his integrated risk management isn't very integrated

These CISOs GRC is Failing Them And I Know Why

Today I attended a CISO roundtable where a number of the attendees talked about their GRC platforms that have taken over a year to "connect all the wires" and they're still in the process of implementing. I know why their GRCs are failing them and there is a better way.
SimpleRisk has flexible deployment models from free to fully-featured GRC

SimpleRisk Free and Open Source vs. Fully Featured Platform

Curious about SimpleRisk’s product offerings and available functionality? Read on to learn about our flexible deployment models – from free and open source to fully-featured GRC platform!

Ensuring customer success without the need for professional services

Why SimpleRisk Doesn’t Require Professional Services

This blog details how our approach varies from that of our competitor’s and how we ensure customer success without including professional services in our pricing model.

Managing users in SimpleRisk

How To: Manage Personnel Changes in SimpleRisk

Explore your options for managing personnel changes in SimpleRisk.

Understanding the basics of risk management

Risk Management 101: Back to Basics

Let’s go back to the basics and break down what enterprise risk management is and how you can use it to mitigate the risks that threaten your organization.

Fist bump between SimpleRisk and a partner for GRC as a Service

What is GRC-as-a-Service?

SimpleRisk partners with various MSSP providers to give customers a one-stop "GRC-as-a-Service" offering.  Learn more about how this works and whether the SimpleRisk GRCaaS platform may be a good fit for your organization.

Custom Development

How SimpleRisk Can Meet Your Custom GRC Requirements

Risk management isn’t one-size-fits-all—it’s about finding your way. At SimpleRisk, we ensure our platform adapts to your unique needs, even offering Custom Development to deliver the exact functionality your organization requires, all while staying intuitive and cost-effective.

OWASP Risk Rating Methodology

The OWASP Risk Rating Methodology and SimpleRisk

Risk scoring methodologies vary widely, but understanding how to prioritize risks is key to managing them effectively. In this post, we take a deep dive into the OWASP Risk Rating Methodology, clarifying how it’s calculated in SimpleRisk and addressing common misconceptions.

Two Plus Two Equals Five

Normalizing Risk Scoring Across Different Methodologies

Risk scoring often involves complex matrices, but prioritizing risks effectively is key. In this post, we explore how SimpleRisk’s Classic Risk Scoring methodology ensures consistency across various scoring systems, allowing you to prioritize risks on a uniform scale.

Using the NIST Cybersecurity Framework in SimpleRisk

Simplifying the NIST Cybersecurity Framework with SimpleRisk

Learn how to use SimpleRisk's Import-Export and Risk Assessment Extras in order to efficiently use the NIST Cybersecurity Framework's controls to assess your organization's risks and perform a control gap analysis.

Risk Management for Dummies

Risk Management for Dummies

Explaining risk management to someone new to the concept can be a challenge, but it’s a skill we use daily without realizing it. Learn how a conversation about home security turned into a practical analogy for understanding risks and how SimpleRisk helps prioritize and address them.

The Security of Open Source vs Closed Source Software

The Security of Open Source vs Closed Source Software

When it comes to software security, is open source or closed source the safer choice? Dive into the pros and cons of transparency, community collaboration, and bug detection to see why SimpleRisk embraces open source for its core while prioritizing security at every step.

SimpleRisk's Plan for COVID-19

SimpleRisk's Plan for COVID-19

During these challenging times, SimpleRisk remains steadfast in our commitment to supporting you, with business continuity plans built on redundancy and resilience. Our remote operations, secure AWS hosting, and unwavering customer support ensure uninterrupted service so you can focus on what matters most.

On-Premise vs Hosted

SimpleRisk On-Premise or Hosted: Which Is Right?

Is your data safer in your own hands or hosted in the cloud? In this post, we explore how SimpleRisk's On-Premise and Hosted solutions empower organizations to balance security, simplicity, and ROI—helping you focus on managing risk, not just your GRC system.

new features

What features do you want to see added to SimpleRisk?

In 2013, SimpleRisk started as a solo project tracked on a Trello board filled with feature ideas to simplify risk management. Today, we’re inviting our community to shape the future of SimpleRisk through our new Suggest a Feature page—where your ideas and votes will help prioritize what matters most.

The Dialed In Podcast with Kyle Burt

Josh Sokol Featured on the 'Dialed In' Podcast

I joined Kyle Burt's "Dialed In" podcast to discuss cybersecurity topics like Bluekeep, career paths, and improving personal security. Missed it live? Watch the replay for an hour of insights and tips!

Quantitative Risk Assessment in SimpleRisk

There is Nothing Simple About FAIR

Is precision worth the time? In this blog, we explore how SimpleRisk balances simplicity and effectiveness in risk assessment, offering a quantitative approach without the complexity of methodologies like FAIR, so you can focus more on managing risks than analyzing them.

Risk Assessments with SimpleRisk

How to Perform Risk Assessments (with SimpleRisk)

Curious about how SimpleRisk simplifies internal and third-party risk assessments? Check out this quick 1-minute animated video showcasing our key capabilities in action!

The Evolving Risk of Bluekeep

How to Manage the Evolving Risk of Bluekeep (with SimpleRisk)

Ever wondered how risks evolve over time? Dive into this blog post to see how SimpleRisk tracks and manages the changing threat landscape, using the infamous 'Bluekeep' vulnerability as a real-world example!

Assessing Vendor Security Risks

Assessing Vendor Security Risks (with SimpleRisk)

Struggling to streamline vendor security assessments? Discover how the SimpleRisk Risk Assessment Extra transforms a complex process into a seamless experience, saving time while keeping your organization secure!

Customize Your Risk Management Program

Quickly Customize Your Risk Program in SimpleRisk

SimpleRisk started as three PHP pages and evolved into a flexible risk management tool for any industry. With the Customization Extra, users can easily tailor workflows to meet their unique needs—simplifying complex requirements!

Assess Your Organization's Cybersecurity Maturity

Assess Cybersecurity Maturity with the NIST CSF

Discover how we used the NIST Cybersecurity Framework (CSF) to assess maturity, identify risks, and build a strategic roadmap for National Instruments’ cybersecurity program. Learn how SimpleRisk streamlined this process to turn insights into actionable results!

GRC is Dead

GRC is Dead, Long Live GRC!

Gartner’s John A. Wheeler highlights the decline of GRC and the rise of Integrated Risk Management (IRM)—a shift I’ve seen firsthand. Learn how SimpleRisk is revolutionizing risk management with a simple, intuitive approach.

Vulnerabilities vs Risks

Should Vulnerabilities and Risks be Managed in the Same Place?

Should vulnerabilities be managed as risks? While both are essential to cybersecurity, understanding their differences and how they complement each other is key to deciding whether to track them together in a single risk management system.

Pricing Integrity

Pricing Integrity and Why We Won't Play the Pricing Games

At SimpleRisk, we believe in transparent pricing and cutting out the games vendors play with discounts. Our goal is to provide affordable, straightforward risk management solutions so you can focus on what matters—managing your risks, not negotiating prices.

Risk Management Program

Why Management Doesn't Understand Your Security Woes

Feeling overwhelmed by security vulnerabilities that seem beyond your control? Learn how implementing a formal risk management program can help you communicate more effectively with management and shift the focus to actionable risk mitigation strategies.

Role Playing and Risk Management

What do Role Playing and Risk Management have in common?

Curious about how Table Top Exercises (TTX) can improve your organization's security incident response? Discover the valuable lessons learned from a first-hand TTX experience and why it's an essential tool for identifying gaps and enhancing preparedness.

Complex vs Simplified Asset Valuation

How Does an Asset's Value Affect Your Risk?

Is asset valuation complicating your risk management process? Discover how SimpleRisk simplifies asset valuation with a streamlined approach that balances practicality and effectiveness, empowering organizations to prioritize risk mitigation without unnecessary complexity.

The Origin of SimpleRisk

The Origin of SimpleRisk - A Founder's Story

Every superhero has an origin story, and so does SimpleRisk—born out of a need for better risk management tools. Discover how a simple web form turned into a powerful, open-source solution that’s now revolutionizing risk management for organizations everywhere.