In May 2024, members of the CyberRisk Collaborative organized a task force to address the complexities faced by CISOs in implementing and maturing GRC programs. This task force aimed to develop a shared understanding of GRC, create a framework for a mature GRC program, and provide practical steps and tools for organizations at various stages of their GRC journey.In the task force, members created a cohesive and comprehensive definition of GRC, discussed their experiences, challenges, and best practices in the organization, administration, and developed guidance on how to enhance their programs. This document aims to help organizations, regardless of size, industry, or maturity level in building or benchmarking their GRC functions.What follows is an excerpt from the full report, which is available to members of the collaborative. Click here for details on how to join and access content like this.
A spokesperson for Palo Alto Networks affirmed the company's commitment to high standards of business conduct and security, stating that the review has no impact on their ability to support customers or deliver services in the region.
The UK's data protection regulator criticized the Metropolitan Police Service (MPS) for significant data handling failures, including sharing a stalking victim's new contact details with her abuser and a separate incident exposing the email addresses of 18 individuals connected to Parliament.