GRC блог
Ideas about GRC and Information Security
Analysis and opinion from Kordon on the security issues, operating models, and emerging changes that deserve a closer look.

Why your GRC platform might matter more to the CEO than the CISO
A GRC platform does more than help the security team manage compliance. It protects institutional knowledge and keeps the security program running when people change.

No Warrant, No Problem: How Governments Are Building the Surveillance Super App
The U.S. Government is building a super app to monitor everyone without warrants. Where are they getting the data from and how can we protect ourselves?

How an Attacker Used 'Spam Bombing' to Gain Remote Access
A short breakdown of how spam bombing can be used in social engineering and what teams can do to spot and resist it.

You're an InfoSec Professional Not a Kinderkarten Teacher
Every minute you spend chasing other people for security work is a minute stolen from actual security work.

NIS 2 Just Came Out But We Already Know What NIS 3 Will Bring
NIS 2 is already shifting expectations for smaller organizations. Based on current regulatory and resilience trends, we can already see what a likely NIS 3 direction would demand from SMBs.
Керуйте своєю GRC-програмою з ясністю
Починайте безкоштовно та зведіть заходи, ризики і завдання в одну робочу систему.