John Paul Tran John Paul Tran

Seven Deaths, One Lesson: GRC Is a Lifeline, Not a Checkbox

Most people look at a headline about faulty medical devices and see a manufacturing error. What they miss is the underlying story about governance, risk, and compliance. The recent FDA alert tied to Abbott’s FreeStyle Libre 3 and Libre 3 Plus sensors is a reminder that GRC isn’t a back-office function. When it fails, the impact reaches real people in real time.

Read More
John Paul Tran John Paul Tran

Miss CMMC 2.0 and You’ll Miss the Contract

In the world of defense contracting, cybersecurity is no longer an IT problem. It is a contract requirement and a competitive edge. The Department of Defense made that clear with CMMC 2.0, a major update that reshapes how companies protect government data and prove they can be trusted with it. If your business works with the DoD or supports someone who does, this is a critical moment.

Read More
John Paul Tran John Paul Tran

Escape the Compliance Maze

For many companies, “the compliance maze” isn’t a metaphor. It’s the daily reality of navigating overlapping regulations, vendor obligations, and shifting expectations for security and transparency. The way out isn’t about ticking more boxes, it’s about reframing compliance as a driver of risk management and business growth.

Read More
John Paul Tran John Paul Tran

Your Vendor Could Be Your Biggest Risk and Regulators Know It

The biggest threat to a financial firm’s cybersecurity might not be the hackers outside the gate, it’s the vendors already inside. A new wave of regulatory scrutiny, led by the New York Department of Financial Services (NYDFS), signals that weak third-party…

Read More
John Paul Tran John Paul Tran

It’s Time for Companies to Grow Up About Risk

By now, it shouldn’t be surprising to say that ignoring risk management is shortsighted. Yet, many organizations still treat it like a box to check or a budget line to trim. They’ll invest heavily in marketing campaigns, branding initiatives, or technology upgrades that promise speed and growth, while leaving their risk posture to luck. Then, when a data breach, compliance lapse, or system failure happens, it’s labeled “unexpected.”

Read More
John Paul Tran John Paul Tran

Discord’s Vendor Breach Exposed More Than Data. It Exposed a Risk Every Business Faces

In early October, Discord disclosed that a third-party vendor supporting its customer service operations had been breached, exposing user data including names, emails, and government ID photos. The contractor, 5CA, provided age-verification services. Attackers accessed internal support systems, stealing images and metadata tied to verification requests.

Read More
John Paul Tran John Paul Tran

Google Dodged a Breakup, But GRC Will Decide What Happens Next

After years of legal wrangling, Alphabet—the parent company of Google—has emerged from the Justice Department’s antitrust case largely intact. The ruling stops short of breaking the company apart or banning its search dominance outright. But make no mistake, this isn’t a free pass. It’s a warning shot to every company sitting comfortably atop its market.

Read More
John Paul Tran John Paul Tran

No More Quarterly Reports? The SEC’s Gamble and What It Means for Risk

The U.S. Securities and Exchange Commission (SEC) is preparing to upend one of the most entrenched practices in corporate America: quarterly reporting. SEC Chair Paul Atkins has signaled his intent to fast-track the removal of the decades-old requirement that public companies issue quarterly earnings reports, a change that could redefine how markets, boards, and regulators think about corporate transparency.

Read More
John Paul Tran John Paul Tran

The Future of Risk Isn’t More Control. It’s More Intelligence.

Most companies don’t see their GRC platform as a productivity tool that can boost business. That needs to change. In an environment where regulatory complexity is growing and resources aren’t, governance, risk, and compliance systems must do more than just audits. They should be helping you…

Read More
John Paul Tran John Paul Tran

The Hacker Didn't Win. And That’s the Point

When news broke that Coinbase had suffered a major breach, with hackers demanding a $20 million ransom after compromising sensitive customer data, there was every reason to expect the usual corporate playbook: silence, damage control, maybe a quiet settlement. But that’s not what happened…

Read More
John Paul Tran John Paul Tran

A Wake-Up Call: What the Change Healthcare Breach Teaches Us About GRC

The Change Healthcare data breach in early 2024 stands out as one of the largest in U.S. history, affecting over 100 million individuals and exposing vast amounts of sensitive health data. It’s a sobering reminder of the risks organizations face when security investments lag behind business operations…

Read More
John Paul Tran John Paul Tran

Understanding the CrowdStrike Crash: Investor Insights

Last week, CrowdStrike faced a significant issue involving their Falcon platform for Windows systems. On July 19, 2024, a faulty content update intended for Windows systems caused numerous crashes and blue screens of death (BSOD) on millions of customer machines.

Read More