GRC & Cyber Governance
Governance, risk, and compliance content on how organizations structure accountability for cyber risk -- including the GRCL Knowledge Hub and Cybersecurity Governance Hub.
Explore this pillar
GRCL Knowledge Hub
The Governance, Risk and Compliance Layered (GRCL) architecture -- Dr. Abeer Alshammari's doctoral research framework, explained and applied.
Cybersecurity Governance Hub
How boards and executives structure accountability for cyber risk, and how cybersecurity governance differs from IT governance.
Articles
The CRA Reporting Clock Started on 11 September — And Most Manufacturers Are Measuring It Wrong
The Cyber Resilience Act's 24-hour reporting duty and ENISA's Single Reporting Platform went live on 11 September 2026. The hard part is not the deadline: the clock starts on awareness, there is no API at launch, and the platform's own counter currently runs fast.
The Vendor Register Has Become the Audit: DORA and NIS2 Enforcement in 2026
DORA's second Register of Information cycle closed in April and NIS2 audit programmes are running across most of the EU. In both regimes, supervisors are now testing the completeness of your third-party record rather than the quality of your judgement.
Cybersecurity Governance vs IT Governance: Why Confusing the Two Weakens Organizational Resilience
IT governance and cybersecurity governance are often treated as the same function under a different name. They are not, and the gap between them is where major incidents start.
What Is the GRCL Framework? A Layered Approach to Governance, Risk and Compliance
GRCL is not an industry standard. It is Dr. Abeer Alshammari's own doctoral framework for structuring governance, risk, and compliance as connected layers instead of separate silos.
Cybersecurity Governance Frameworks Compared: NIST CSF, ISO 27001, and COBIT
NIST CSF, ISO 27001, and COBIT solve overlapping but distinct problems. Picking one, or combining them, depends on what you actually need a framework to do.
The CISO Reporting Line: Why Where Security Sits in the Org Chart Matters
Whether the CISO reports to the CIO, the CEO, or the board changes what gets prioritized, what gets funded, and what gets said out loud in a risk conversation.
Third-Party Risk Management: A GRC Practitioner's Framework for Vendor Security
A vendor security questionnaire is not a risk management program. Real third-party risk management requires ongoing ownership, not a one-time checklist at signing.