GRC resources
Discover blogs, news, events and more from CoreStream GRC’s experts.

-

·
Too much faith in frameworks: The governance limits of industry standard certifications
Key takeaways Introduction: when GRC certification becomes destination At a recent CoreStream GRC webinar on the modern CISO’s compliance stack, the panel was asked a blunt question: are there any regulations, frameworks or certifications that organizations place too much faith in? Tom Cornelius, founder of the Secure Controls Framework and senior partner at ComplianceForge, didn’t hesitate. He named SOC 2 and ISO 27001 directly, and called the market that…
-

·
Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough
Key takeaways Introduction: failure to go beyond filing a risk report leads to an AML conviction In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…
-

·
Spotlight on Women in GRC: Emma Price on curiosity, creativity and why value-based GRC starts with better questions
In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague sits down with Emma Price, Partner at Brave, former Deloitte partner and one of the UK’s leading voices in risk and resilience. With more than 25 years of experience helping boards navigate uncertainty, Emma shares: Curiosity: The skill that launched a 25-year career in GRC and a…
-

·
CoreStream GRC 3.6 Release Notes
1.0 Document purpose This document provides a summary of the highlights of the CoreStream GRC Release 3.6 release. Major Platform releases are finalized every 2-3 months depending on client and strategic priorities. These release notes are part of CoreStream GRC’s approach to keeping clients and partners informed of the improvements we are delivering. This document…
-

·
Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart
Key takeaways How Fairlife’s cyberattack became a group governance issue On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…
-

·
Simplifying risk in a complex world to achieve business objectives – key findings from the Spotlight on Women in GRC
In this episode of CoreStream GRC’s Spotlight on Women in GRC podcast, Lucy Montague speaks with Sharon Sharples, Chief of Staff and Head of Operational Risk Governance and Insights at Barclays, about her journey from change management into risk leadership, the evolving role of GRC in modern organizations, and why curiosity, simplification, and flexibility will define the…
Ready to chat with our experts?
Contact us today!
This form may not be visible due to adblockers, or JavaScript not being enabled.