• Controls management: how to prove value, not just activity  

    Controls management: how to prove value, not just activity  

    Key takeaways  Introduction: why controls management needs to move beyond activity  Most organizations have controls in place. That is not the hard part.  The harder question is whether those controls are effective, current, owned by the right people, supported by evidence and connected to the risks that matter most. This is the proof burden now sitting behind…

  • 8 risk and compliance leaders to follow and learn from on LinkedIn 

    8 risk and compliance leaders to follow and learn from on LinkedIn 

    We’re shining a spotlight on the people shaping the future of governance, risk and compliance.  LinkedIn is one of the best places to find real conversations about risk leadership, compliance culture, internal audit, AI governance, operational resilience and the future of GRC.  In this blog, we’ve curated 8 GRC leaders worth following on LinkedIn. Their work spans:  From established analysts and community…

  • The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from this 

    The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from this 

    Key takeaways What happened at Novo Nordisk?  Reuters reported that cyber extortion group FulcrumSec claimed it spent more than 2 months inside Novo Nordisk’s network and stole more than 700,000 files, equal to roughly 1.3 terabytes of data. The group also claimed Novo Nordisk refused to pay a $25m extortion demand. Reuters said it could not immediately verify the authenticity of the data…

  • Why risk and compliance leaders should attend #RISK Expo Europe 2026  

    Why risk and compliance leaders should attend #RISK Expo Europe 2026  

    Introduction: why #RISK Europe 2026 should be on every risk leader’s radar  Risk is moving faster, crossing more business functions and creating pressure than ever before. Cyber risk now touches third-party oversight. Operational resilience depends on supplier visibility. AI governance is becoming a compliance, security and board reporting issue.   This means risk leaders and their teams have a lot to…

  • The Modern CISO’s Compliance Stack: Frameworks, Automation and AI webinar 

    The Modern CISO’s Compliance Stack: Frameworks, Automation and AI webinar 

    Introduction: What should a modern CISO compliance stack actually look like? CISOs are being asked to protect the business across more frameworks, more regulatory expectations and more third-party assessments than many compliance programs were built to handle.  The pressure is not theoretical. PwC’s Global Compliance Survey 2025 found that 85% of respondents said compliance requirements have become more complex in the last 3…

  • Spotlight on Women in GRC: Chief Compliance Officer on accountability, crisis management & leadership

    Spotlight on Women in GRC: Chief Compliance Officer on accountability, crisis management & leadership

    In the latest episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Grace Suleyman, Chief Compliance Officer at an asset management company servicing insurance clients.  Grace’s role spans legal, company secretarial, enterprise risk and compliance, giving her a broad view of what modern compliance leadership now requires. The discussion explores why senior GRC roles…