Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Risk & Resilience

Dancing With the Gray Rhino: Why Obvious Risks Still Destroy Organizations

In risk management, we tend to obsess over black swans. Rare, unpredictable, high impact shocks that arrive without warning and rewrite the narrative overnight. Yet most organizational failures are not born from surprise. They emerge from visible, accelerating threats that were identified, debated, scored, and then quietly deprioritized because mitigation was inconvenient, expensive, or politically uncomfortable. These are gray rhinos. High probability, high impact risks charging directly at the organization. The breakdown is not foresight. It is governance.

AWS Unable to Restore Bahrain Cloud Region After War Damage

Amazon Web Services has spent months trying to recover cloud infrastructure damaged during the war with Iran. In Bahrain, it has reached the end of that effort. AWS cannot restore access to its Bahrain cloud region or to resources and data held exclusively in one of its three availability zones in the United Arab Emirates, according to a company status update seen by Reuters. Reuters first reported the development Tuesday.

CBUAE, Mastercard Build Fraud Risk Capabilities to Strengthen Financial Resilience

The Central Bank of the UAE and Mastercard have completed a four-day program designed to sharpen the central bank’s expertise in fraud risk management, with 25 CBUAE employees receiving training on the risks emerging alongside new forms of digital payments and commerce.

Basel Committee Finds Familiar Weaknesses Behind Bank Technology Failures

The Basel Committee on Banking Supervision is turning its attention to the technology failures that can disrupt banks without a cyberattack ever taking place, highlighting weaknesses in change management, system testing and third-party dependencies as persistent sources of operational risk.

APRA, ASIC Press Superannuation CEOs on AI, Cyber Risk & Crisis Preparedness

At two CEO roundtables in June, the Australian Prudential Regulation Authority and Australian Securities and Investments Commission asked industry leaders to consider cyberattacks complicated by artificial intelligence, failures at critical service providers and crises that spill across organizational boundaries. The regulators published notes from the discussions Tuesday.

The Hidden GRC Risk in Every M&A Deal: What Happens When Business Processes Collide

Not long ago, a CFO at one of the world's largest pharmaceutical companies said something that has stayed with me. We were discussing a major acquisition his company had just completed, and I asked what kept him up at night during the integration. His answer was not about valuation, synergies, or headcount. It was about business processes.

ASIC & APRA Tell Financial Firms to Act on Frontier AI Risks

The Australian Securities and Investments Commission and Australian Prudential Regulation Authority have urged financial market entities to move beyond awareness of frontier AI risks and begin preparing for their consequences. The regulators said increasingly capable AI models are accelerating cyber threats while adding pressure to the technology and operational risks financial institutions already face.