INSIGHTS

SimpliGRC blog

Practical perspectives on governance, risk, compliance and certification, from the SimpliGRC team.

April 30, 2026

Continuous Learning Through Certifications

Continuous Learning Through Certifications Why This Matters Now The external landscape is changing faster than most programs can update a playbook. Emerging technologies (AI, cloud-native, OT

Read more →

October 8, 2025

Supporting Your Strategy and Operations with Certifications

Supporting Your Strategy and Operations with Certifications In last month’s blog, we explored the challenges of sustaining a GRC program in dynamic environments. This month, we’re

Read more →

August 27, 2025

Breaking Silos: Converging Compliance and Operational Programs

Breaking Silos: Converging Compliance and Operational Programs In many organizations, compliance and operational programs have evolved as distinct entities. This separation is often intentional, rooted in

Read more →

August 6, 2025

Sustainable Controls: The Missing Link in GRC Program Success

Sustainable Controls: The Missing Link in GRC Program Success Why do so many GRC programs struggle to operate as intended even after successful implementation? The answer

Read more →

July 1, 2025

The Strategic Value of Process Mapping

The Strategic Value of Process Mapping In today’s complex and fast-paced cybersecurity landscape, the strategic value of process mapping may be seen as a necessary evil

Read more →

June 4, 2025

The Versatility of NIST Cybersecurity Framework

The Versatility of NIST CSF In today’s dynamic threat landscape, organizations require structured, adaptable, and measurable approaches to cybersecurity and risk management. Among the many standards

Read more →

May 7, 2025

Synergies Between CSA z246.1 and ISO 27001

Synergies Between CSA z246.1 and ISO 27001 As of May 31, 2025, CSA Z246.1 will be in effect in Alberta, joining British Columbia where it is

Read more →

A person climbing a cliff Description automatically generated

March 25, 2025

Identifying Risks in CIP Programs

Identifying Risks in CIP Programs Every regulation has its unique set of requirements, outcomes, regulators, consequences, and culture. Identifying risks in CIP programs is no different.

Read more →

February 26, 2025

Contrasting ISO/IEC 27001 and PMBOK

Contrasting ISO/IEC 27001 and PMBOK By contrasting the ISO/IEC 27001 Information Security Management System (ISMS) and Project Management Book of Knowledge (PMBOK), you will realize there

Read more →

Supply Chain Management System

January 27, 2025

Supply Chain Risk Management Compliance

Navigating Supply Chain Risk Management Compliance Supply Chain Risk Management (SCRM) assesses risk for vendor products or services to your organization’s critical assets. Various regulations and

Read more →

November 27, 2024

Value of Professional Certifications

In today’s competitive job market, the value of professional certifications have become increasingly important. They are meant to serve as a testament to an individual’s skills,

Read more →

GRC controls represented as a shield

October 29, 2024

GRC Controls for the NVD Issue 

Common Vulnerabilities and Exposures (CVE) are a crucial source of information on cyber vulnerabilities for organizations and malicious actors alike. The CVE Numbering Authorities (CNA), CVE.org,

Read more →

September 25, 2024

What Is FUD?

In today’s constantly and rapidly changing business world, the terms “Fear”, “Uncertainty”, and “Doubt” (FUD) are often used to describe the emotional and psychological barriers that

Read more →

August 29, 2024

Why GRC Programs Fail

Why GRC programs fail have many sources to investigate. How often have you seen your Governance, Risk, and Compliance (GRC) program fail to achieve your expected

Read more →

Some roads may converge and others may not but still same direction

July 29, 2024

Adopting IT/OT Convergence

What is IT/OT Convergence? Adopting IT/OT Convergence is an industry term that became more prominent with the Industry 4.0 movement. The introduction of Industrial Internet of

Read more →