When we talk to information security and data protection professionals, one fact pops up again and again.
Non-professionals are key to a sustainable GRC programme.
It’s not just about awareness training.
If you want to build a great, sustainable GRC programme for your data protection and information security, these people are the key to making it work, we found.
To understand that, we need to take a step back and look at the problems of centralised data protection and information security.
If you find yourself in a centralised GRC function, you will experience one or more of the 5 problems:
{{factbox-dark}}
The thing is: Most GRC professionals realise this.
It is, however, difficult to come up with a solution. After all, we still need a lot of deep knowledge about information security and data protection to make it work.
Here’s what we’ve seen work.
The hybrid organisation is one that combines deep knowledge of information security and data protection with the practical knowledge of strategies and processes within the business. The first part is a (probably centralised) information security and data protection function.
This is where the professionals with in-depth knowledge of compliance, privacy and information security sit.
They should:
Moreover, you need operators within the business or departments of the organisation, responsible for parts of data protection and information security. They must know enough about privacy and infosec, however, their main task is knowing about the business.
They should:
We see more and more organisations build hybrid GRC programmes.
It’s like a honeymoon.
However, they quickly realise that collaboration is great … but difficult.
Two things happen.
The non-compliance people feel that it is difficult to contribute. When they are asked to review a processing activity, they have no idea what to do. When they are asked for information on a new system, they don’t know what information is necessary.
On the other hand, the GRC pro’s have a hard time keeping track of what is happening in the hybrid organisation. What tasks are being carried out, which one are overdue and is everything going to plan. Build for collaboration. That’s why we think a GRC solution must be built for collaboration.
Our solution is:
The trends are:
Trend #1 From centralised authority to company-wide collaboration
Trend #2 From tick-the-box compliance to balanced decision-making
Trend #3 From problem-oriented to solution-oriented
Trend #4 From legal thinking to strategic involvement
Trend #5 From managing data subject to caring about people
Our Sustainable Compliance Newsletter is dedicated to compliance professionals working with compliance, GDPR, and information security. We provide insights from experts, discuss the latest trends, learnings, and advice within the field of compliance. We also explore how we can reshape the way we think and organise around compliance, in order to pave a sustainable and viable path for processes.