GRC блог

Ideas about GRC and Information Security

Analysis and opinion from Kordon on the security issues, operating models, and emerging changes that deserve a closer look.

6 публікаційОстаннє: серпень 2026 р.

  1. Illustration of policies, controls, risks, evidence, and tasks connected in one GRC system.
    Останнє

    What Is a GRC Tool? A Guide to the GRC Software Landscape

    GRC tool, GRC software, GRC platform — same category, different vendors. What they do, the three types on the market, and how to pick the right one.

  2. Two security leaders seen from behind: one struggling with scattered GRC documents and unidentified archive boxes, and the other using an organised, connected GRC system.

    Why your GRC platform might matter more to the CEO than the CISO

    A GRC platform does more than help the security team manage compliance. It protects institutional knowledge and keeps the security program running when people change.

  3. Hero image for No Warrant, No Problem: How Governments Are Building the Surveillance Super App.

    No Warrant, No Problem: How Governments Are Building the Surveillance Super App

    The U.S. Government is building a super app to monitor everyone without warrants. Where are they getting the data from and how can we protect ourselves?

  4. Illustration for an article about spam bombing and social engineering.

    How an Attacker Used 'Spam Bombing' to Gain Remote Access

    A short breakdown of how spam bombing can be used in social engineering and what teams can do to spot and resist it.

  5. Illustration for an article about security leaders being forced into reminder duty.

    You're an InfoSec Professional Not a Kinderkarten Teacher

    Every minute you spend chasing other people for security work is a minute stolen from actual security work.

  6. Illustration representing a likely direction from NIS2 toward broader NIS3-style expectations.

    NIS 2 Just Came Out But We Already Know What NIS 3 Will Bring

    NIS 2 is already shifting expectations for smaller organizations. Based on current regulatory and resilience trends, we can already see what a likely NIS 3 direction would demand from SMBs.

Керуйте своєю GRC-програмою з ясністю

Починайте безкоштовно та зведіть заходи, ризики і завдання в одну робочу систему.