Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Risk & Resilience

The Risk of Technology Dependence: What Happens When Your Organization Can No Longer Use the Technology It Relies On?

Most organizations know what they would do if a critical system went down. There are incident response plans, disaster recovery arrangements and business continuity procedures designed for exactly that scenario. But there is another question we don't ask nearly as often: What happens if the technology hasn't failed, but your organization can no longer use it?

ENISA Warns Digital Dependencies Are Widening Europe’s Cyber Attack Surface

More than half of the cyber incidents recorded by the European Union’s cybersecurity agency last year were distributed denial-of-service attacks. Most were not especially damaging, but they were, however, remarkably easy to summon. A political statement, an election, a protest or another turn in the war in Ukraine could be enough. Hacktivist groups claimed 4,709 attacks against EU Member States during 2025, according to ENISA’s latest Threat Landscape report, and more than 89% involved DDoS attacks. Public administrations bore much of it.

The Missing Fifth Transformation in WEF’s Vision for Risk Management

The World Economic Forum’s new Risk Management, Reimagined: Outlook to 2035 is one of the more thoughtful critiques of traditional risk management I have read in some time. It also stops one important step short.

EU Firms Redesign Supply Chains as Geopolitical Risk Becomes the New Normal

The problems that kept European supply-chain managers awake a few years ago have become considerably less troublesome. Raw materials are easier to secure, semiconductors are less scarce, goods are moving, but the trouble has migrated elsewhere.Between 2023 and 2025, the share of EU firms reporting raw materials as a supply-chain obstacle fell from 27% to 8%, according to a new study from the European Investment Bank (EIB) and European Commission. Semiconductor concerns dropped from 15% to 3%, while logistics obstacles fell from 28% to 12%.

Dancing With the Gray Rhino: Why Obvious Risks Still Destroy Organizations

In risk management, we tend to obsess over black swans. Rare, unpredictable, high impact shocks that arrive without warning and rewrite the narrative overnight. Yet most organizational failures are not born from surprise. They emerge from visible, accelerating threats that were identified, debated, scored, and then quietly deprioritized because mitigation was inconvenient, expensive, or politically uncomfortable. These are gray rhinos. High probability, high impact risks charging directly at the organization. The breakdown is not foresight. It is governance.

AWS Unable to Restore Bahrain Cloud Region After War Damage

Amazon Web Services has spent months trying to recover cloud infrastructure damaged during the war with Iran. In Bahrain, it has reached the end of that effort. AWS cannot restore access to its Bahrain cloud region or to resources and data held exclusively in one of its three availability zones in the United Arab Emirates, according to a company status update seen by Reuters. Reuters first reported the development Tuesday.

CBUAE, Mastercard Build Fraud Risk Capabilities to Strengthen Financial Resilience

The Central Bank of the UAE and Mastercard have completed a four-day program designed to sharpen the central bank’s expertise in fraud risk management, with 25 CBUAE employees receiving training on the risks emerging alongside new forms of digital payments and commerce.