Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Governance

Cyber-GRC

Cyber-GRC (cyber governance, risk and compliance) is the discipline that manages an organization’s cybersecurity risk, its regulatory and contractual obligations, and the decisions of its leadership as one connected system rather than three separate functions. Its output is a defensible posture: risks scored against an approved appetite, controls proven by evidence, third parties graded, and every exception owned and dated.

Why the three letters belong together

Governance sets the appetite and the accountability; risk management measures exposure against that appetite; compliance proves that the controls the risk analysis asked for actually operate. Run apart, the three drift: the register scores a risk the audit never checks, the audit certifies a control no risk asked for, and the board reads a report that neither produced. Cyber-GRC keeps them on the same facts, so a change in one moves the other two. The register, the audit and the board then read one posture, and disagree about nothing the evidence has already settled.

What changed with NIS2 and DORA

The European texts turned Cyber-GRC from a good practice into a legal design. NIS2 makes management bodies responsible for approving and overseeing risk-management measures; DORA asks financial entities to keep ICT risk, incident reporting, resilience testing and third-party risk in one framework. Both expect proof of effectiveness, not a documented intention. A GRC that produces PDFs once a year cannot answer them; one that verifies continuously can.

From declarations to verification

The historical GRC tool is a form: questionnaires, attestations, screenshots filed as evidence. The current generation replaces the declaration with the verified fact: a control status computed from live evidence, a supplier grade that moves with its signals, a risk score that inherits the residual risk of its controls. That is the shift Mindlapse builds on, and the one the glossary’s other terms describe piece by piece.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.