INSIGHTS
Practical perspectives on governance, risk, compliance and certification, from the SimpliGRC team.
April 30, 2026
Continuous Learning Through Certifications Why This Matters Now The external landscape is changing faster than most programs can update a playbook. Emerging technologies (AI, cloud-native, OT
October 8, 2025
Supporting Your Strategy and Operations with Certifications In last month’s blog, we explored the challenges of sustaining a GRC program in dynamic environments. This month, we’re
August 27, 2025
Breaking Silos: Converging Compliance and Operational Programs In many organizations, compliance and operational programs have evolved as distinct entities. This separation is often intentional, rooted in
August 6, 2025
Sustainable Controls: The Missing Link in GRC Program Success Why do so many GRC programs struggle to operate as intended even after successful implementation? The answer
July 1, 2025
The Strategic Value of Process Mapping In today’s complex and fast-paced cybersecurity landscape, the strategic value of process mapping may be seen as a necessary evil
June 4, 2025
The Versatility of NIST CSF In today’s dynamic threat landscape, organizations require structured, adaptable, and measurable approaches to cybersecurity and risk management. Among the many standards
May 7, 2025
Synergies Between CSA z246.1 and ISO 27001 As of May 31, 2025, CSA Z246.1 will be in effect in Alberta, joining British Columbia where it is
March 25, 2025
Identifying Risks in CIP Programs Every regulation has its unique set of requirements, outcomes, regulators, consequences, and culture. Identifying risks in CIP programs is no different.
February 26, 2025
Contrasting ISO/IEC 27001 and PMBOK By contrasting the ISO/IEC 27001 Information Security Management System (ISMS) and Project Management Book of Knowledge (PMBOK), you will realize there
January 27, 2025
Navigating Supply Chain Risk Management Compliance Supply Chain Risk Management (SCRM) assesses risk for vendor products or services to your organization’s critical assets. Various regulations and
November 27, 2024
In today’s competitive job market, the value of professional certifications have become increasingly important. They are meant to serve as a testament to an individual’s skills,
October 29, 2024
Common Vulnerabilities and Exposures (CVE) are a crucial source of information on cyber vulnerabilities for organizations and malicious actors alike. The CVE Numbering Authorities (CNA), CVE.org,
September 25, 2024
In today’s constantly and rapidly changing business world, the terms “Fear”, “Uncertainty”, and “Doubt” (FUD) are often used to describe the emotional and psychological barriers that
August 29, 2024
Why GRC programs fail have many sources to investigate. How often have you seen your Governance, Risk, and Compliance (GRC) program fail to achieve your expected
July 29, 2024
What is IT/OT Convergence? Adopting IT/OT Convergence is an industry term that became more prominent with the Industry 4.0 movement. The introduction of Industrial Internet of