Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Gartner Security Summit – Vendors are not offering GRC solutions, despite claiming that they do

by The Gurus
September 8, 2014
in Editor's News
Share on FacebookShare on Twitter

Vendors claim to be offering products and solutions in the governance, risk and compliance (GRC) space, but these rarely fit the analyst specification.
 
According to Paul Proctor, vice president, distinguished analyst and the chief of research for security and risk management at Gartner, there are plenty of vendors in the space who have their preference for some technologies, but often technologies do not fit into what it deems to be the GRC model.
 
Speaking at the Gartner Security and Risk Management summit in London, he said that in a new approach into insight, Gartner de-emphasised the differentiation of the presence and demonstrability of features and functions, and increased its weighting on implementation and production use of GRC products against specific use cases. This led to a number of vendor technologies being classified as “the posers list”.
 
He said: “I told them to ‘stop saying you do everything when you do not, and stop saying you do GRC when you do not’. You can call your product GRC if you want, but I have given up on the notion of what is and is not GRC.
 
“I am getting closer to giving up on the term, it is a great management and process term and I am a fan of risk-based stuff and decision and compliance about correct mandates. But everyone’s workflows are different, if you want to call it GRC, go for it, but there are specific guidelines for GRC and there may be something different for you to offer.”
 
He said that after sending out close to 600 surveys, and getting back 359 at the last count, of 78 vendors it spoke to about GRC, only half had an element of GRC in their product. “Lots of vendors said ‘we are leaders’ but did not produce references. Lots of vendors don’t agree with this as they do not support GRC, but do segregation of duties and enterprise resource planning,” he said. “That is a very specific set of technologies and they call it GRC, and can do it but it doesn’t fit, and we don’t call it GRC.”
 
He said that a number of technologies do not support the Gartner GRC use cases for IT risk management, operational risk management, vendor risk management, audit management, business continuity management, corporate compliance and oversight. He specifically named HP, McAfee, Microsoft, NetIQ, Oracle GRC, Qualys, Symantec and Trustwave in this section.
 
He said: “Some do something and call it GRC, but it doesn’t mark Gartner definitions. Just because we say it is great, doesn’t mean it is right for you.
 
“Many call me and say they do not do good risk management, so what should we buy? Tools automate good process; they do not create good process – everyone who tries to buy a box to solve a problem wastes money!”
 
He concluded by saying that the simple steps for success for GRC are to: build GRC use cases preparing for no more than ten; prioritise the list and focus on the first three; build good processes and workflow and match the use cases to tool functions.

ShareTweet
Previous Post

Gartner Security Summit: Correct controls between user and data can help with attack mitigation

Next Post

Gartner: 2014's top ten security technologies

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol