{"id":4014,"date":"2024-05-22T12:00:00","date_gmt":"2024-05-22T00:00:00","guid":{"rendered":"https:\/\/ostermanresearch.com\/?post_type=jetpack-portfolio&#038;p=4014"},"modified":"2025-01-13T15:33:53","modified_gmt":"2025-01-13T02:33:53","slug":"logicgate-grc-outcomes-2024","status":"publish","type":"jetpack-portfolio","link":"https:\/\/ostermanresearch.com\/portfolio\/logicgate-grc-outcomes-2024\/","title":{"rendered":"2024 GRC Strategies, Teams, and Outcomes Report &#8211; commissioned by LogicGate"},"content":{"rendered":"\n<p id=\"block-d94ad8e4-c7d6-4d0f-8409-da6fca21faf0\"><em>Commissioned by <strong>LogicGate<\/strong><\/em><\/p>\n\n\n\n<p id=\"block-00ec9827-b0f2-4913-bcec-7ef96b4de909\"><em>Published <strong>May 2024<\/strong><\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-5bb4b5b8-207d-4f71-bf62-5cf10dab9c0d\">Executive summary<\/h2>\n\n\n\n<p id=\"block-a7612fe9-9a1d-4f36-a91f-3eccc35d16e2\">Governance, risk, and compliance is a team sport \u2014 in a league where no two teams look alike. This diversity in team structures, responsibilities, and program resources makes GRC benchmarking across organizations and industries challenging \u2014 and objectively evaluating your program strategy even more difficult.<\/p>\n\n\n\n<p id=\"block-39ec44dd-77ed-43b2-97c6-fdcfc2e96faf\">To better enable GRC leaders with a clear understanding of what \u201cgood\u201d GRC looks like, we surveyed 350 risk, cybersecurity, and compliance leaders worldwide about their program objectives, team structures, processes, and technology investments \u2014 and aligned responses to a maturity model to gauge their GRC program maturity and success.<\/p>\n\n\n\n<p id=\"block-5eb81ba2-ee7e-4b29-81f5-adeff18c037d\">One finding stood out above all others: there is no silver bullet for running an effective GRC program. Good GRC practices are simply good business practices.<\/p>\n\n\n\n<p id=\"block-700c431e-bf66-40f3-8efa-809f16ae9ba3\">Team sizes, responsibilities, processes, and spending varied considerably across organization sizes, industries, and geographies. This suggests GRC leaders should first align their strategy and program to business objectives \u2014 and interpret peer benchmarks with several grains of salt.<\/p>\n\n\n\n<p id=\"block-de598fe6-3266-4567-b07f-de1890f8f547\">However, what successful GRC teams did have in common were collaborative processes, strong stakeholder engagement, and integrated data and systems.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-white-color has-vivid-purple-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/www.logicgate.com\/resources\/2024-grc-strategies-teams-outcomes-report\/\" target=\"_blank\" rel=\"noreferrer noopener\">Download from LogicGate<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In a study of 350 global risk, cybersecurity, and compliance leaders, it was found that there is no universal formula for a successful GRC program. Rather, aligning strategy with business objectives and fostering collaboration, stakeholder engagement, and integrated systems are key. Commissioned by LogicGate.<\/p>\n","protected":false},"author":384585,"featured_media":4072,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"jetpack-portfolio-type":[712027439],"jetpack-portfolio-tag":[712027445],"class_list":["post-4014","jetpack-portfolio","type-jetpack-portfolio","status-publish","format-standard","has-post-thumbnail","hentry","jetpack-portfolio-type-commissioned-research","jetpack-portfolio-tag-governance-risk-and-compliance"],"jetpack_publicize_connections":[],"jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/jetpack-portfolio"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4014"}],"version-history":[{"count":4,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4014\/revisions"}],"predecessor-version":[{"id":4139,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4014\/revisions\/4139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4072"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4014"}],"wp:term":[{"taxonomy":"jetpack-portfolio-type","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio-type?post=4014"},{"taxonomy":"jetpack-portfolio-tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio-tag?post=4014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}