Where Governance and Active Security Meet
This event addresses the common conundrum of “us vs them”
when it comes to the governance and active security realms.
The industry has generally accepted a split between typical Governance, Compliance, and Risk (GRC) functions and those of an operational and/or tactical nature. That traditional approach no longer works for the industry as a whole.
In today’s increasingly complex and threatening digital environment, the traditional separation between organizational governance and active security is no longer sustainable.
This webinar explores the critical convergence of these two essential functions. We will delve into why this integration is necessary, examining the drivers such as true remediation efforts, escalating cyber threats, evolving regulations, and the significant business impact of security incidents. By understanding the key areas of overlap, organizations can move beyond siloed approaches to build a more robust and resilient security posture.
This session will provide practical insights into how organizations can effectively bridge the gap between governance and active security.
We will discuss the benefits of a converged strategy, including improved risk management, enhanced compliance, and more efficient resource allocation. We will also address the challenges that organizations may face in achieving this integration and offer actionable steps to foster better collaboration, establish shared goals, and embed security considerations into the core of organizational governance.
Join to:
Convergence, as discussed by Andres Andreu, refers to the essential integration of traditionally fragmented functions like governance, risk, and compliance (GRC) with active cybersecurity operations. Historically, these areas have operated in silos, leading to disconnects and inefficiencies. The aim of convergence is to unite these functions to manage risk holistically across an organisation, moving away from a “throwing things over the fence” mentality to one of shared responsibility and proactive problem-solving. This alignment is no longer optional; it is crucial for an organisation’s future-proofing and survival in the face of evolving cyber threats.
The convergence of governance and active security is crucial now due to several environmental drivers. Firstly, there’s increasing stakeholder pressure from boards, regulators, and insurers who are demanding more integrated views of risk. Cyber insurance questionnaires, for example, have become much tougher, reflecting a desire to see cyber risk quantified and aligned with business priorities. Secondly, many businesses still fail to treat cyber threats as fundamental business risks, often isolating them within IT or finance. However, incidents like ransomware attacks demonstrate widespread impacts, affecting shareholder confidence, regulatory compliance, and exposing leadership gaps. Lastly, a significant challenge is the communication gap; CISOs, GRC leaders, and business professionals often “speak different languages”, hindering effective collaboration and setting up organisations for governance failure during crises. Bridging this gap with shared metrics and collaborative exercises is paramount.
The cases of Uber and Maersk provide stark contrasts regarding the impact of convergence. Uber, despite having an extensive and well-documented GRC apparatus, has experienced multiple breaches. This indicates an operational disconnect between their theoretical GRC framework and actual cybersecurity implementation, highlighting the risks of siloed approaches. The “paper compliance” did not translate into effective operational security. In contrast, Maersk demonstrated successful convergence during a major cyber incident, recovering in just 10 days from an event that should have taken months. Their leadership fostered immediate, forced collaboration across various functions to solve the problem, rather than allowing traditional silos to impede recovery. These examples underscore that success in managing cyber risk is less about tools and more about aligned leadership and a collaborative mindset.
Operational convergence within an organisation means shifting from a focus on structure or tools to behaviour and organisational culture. Practically, this can manifest in several ways:
Organisations typically fail in achieving convergence by mistakenly assuming it’s a tooling problem rather than a leadership and organisational culture issue. Silos persist because priorities are misaligned; compliance teams focus on reports and audits, while security teams chase active threats, often without shared goals or a common language. This creates communication gaps and “turf battles” over budgets and responsibilities. An inactive approach to addressing this fragmentation becomes extremely costly, especially during an incident when existing cracks widen. Another common failure is a lack of trust between different functions, as illustrated by auditors lacking practical experience yet being tasked with making recommendations. Leaders who accept the status quo and the existence of silos prevent the necessary collaborative pursuit of solutions.
CISOs must actively lead the shift towards convergence by leaning into the business leadership space, even if initially unwelcomed. Key steps include:
Identity risk intelligence serves as critical “connective tissue” between governance and security within the convergence model. Modern threat actors primarily exploit identities (e.g., through phishing, synthetic identities, credential abuse, or info stealer leaks that bypass MFA). Real-time visibility into identity exposure is crucial because it informs not only protective mechanisms but also policy development. Without this intelligence loop, organisations remain blind to a significant portion of their attack surface, hindering effective convergence. Since every part of an organisation involves identities, this intelligence brings together siloed information, sitting at the apex of the convergence zone to provide a holistic view of risk.
AI and automation should be leveraged as enablers of convergence, not just operational accelerators. They can significantly aid by:
To engage boardrooms, who often view security as a cost centre, CISOs must:
Link to the policy: GGA Privacy Policy 2021
The Good Governance Academy (“GGA”) strives for transparency and trust when it comes to protecting your privacy and we aim to clearly explain how we collect and process your information.
It’s important to us that you should enjoy using our products, services and website(s) without compromising your privacy in any way. The policy outlines how we collect and use different types of personal and behavioural information, and the reasons for doing so. You have the right to access, change or delete your personal information at any time and you can find out more about this and your rights by contacting the GGA, clicking on the “CONTACT” menu item or using the details at the bottom of the page.
The policy applies to “users” (or “you”) of the GGA website(s) or any GGA product or service; that is anyone attending, registering or interacting with any product or service from the GGA. This includes event attendees, participants, registrants, website users, app users and the like.
Our policies are updated from time-to-time. Please refer back regularly to keep yourself updated.
Dr Grebe is a chartered accountant and senior lecturer at the University of South Africa (Unisa).
She teaches postgraduate accounting sciences through blended learning using technology in distance education, and through face-to-face study schools throughout South Africa. During her employment at Unisa, she also acted as Coordinator: Master’s and Doctoral Degrees for the College of Accounting Sciences (CAS), chairperson of the research ethics committee and chairperson of the Gauteng North Region of the Southern African Accounting Association (SAAA).
Before joining Unisa as academic, she gained ten years’ experience in audit practice and in commerce.