Governance, risk, and compliance content on how organizations structure accountability for cyber risk -- including the GRCL Knowledge Hub and Cybersecurity Governance Hub.
The Governance, Risk and Compliance Layered (GRCL) architecture -- Dr. Abeer Alshammari's doctoral research framework, explained and applied.
How boards and executives structure accountability for cyber risk, and how cybersecurity governance differs from IT governance.
The Cyber Resilience Act's 24-hour reporting duty and ENISA's Single Reporting Platform went live on 11 September 2026. The hard part is not the deadline: the clock starts on awareness, there is no API at launch, and the platform's own counter currently runs fast.
DORA's second Register of Information cycle closed in April and NIS2 audit programmes are running across most of the EU. In both regimes, supervisors are now testing the completeness of your third-party record rather than the quality of your judgement.
IT governance and cybersecurity governance are often treated as the same function under a different name. They are not, and the gap between them is where major incidents start.
GRCL is not an industry standard. It is Dr. Abeer Alshammari's own doctoral framework for structuring governance, risk, and compliance as connected layers instead of separate silos.
NIST CSF, ISO 27001, and COBIT solve overlapping but distinct problems. Picking one, or combining them, depends on what you actually need a framework to do.
Whether the CISO reports to the CIO, the CEO, or the board changes what gets prioritized, what gets funded, and what gets said out loud in a risk conversation.
A vendor security questionnaire is not a risk management program. Real third-party risk management requires ongoing ownership, not a one-time checklist at signing.