Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

KEY CAPABILITY · GRCOPS

GRCOps: governance conducted continuously, not certified once a year.

GRCOps is a way of running governance, not another module. An audit tells you what was true one day; the approach covers the other days: you catch a gap as it opens, turn it into an owned and dated action, drive it through one lifecycle to a closure verified by evidence, and measure security work against the service levels you set.

GRCOps · derogation flow Illustrative data
  1. Draft
  2. Submitted
  3. Approved
  4. Effective
  5. Expired / closed

DER-042

Legacy TLS on the HR portal

Scope: HR portal · IT & Digital

Waives: NIS2 Art. 21 · ISO 27001 A.8.24

Expires: Nov 15, 2026

Residual risk: high

Approval chain BU CISO → Group CISO · approved, trail attached

Compensating actions

  • Reinforced MFA on admin access applied
  • Network segmentation in progress
  • Extended logging & alerting planned

Coverage: partially applied

One lane of the queue: approved at the right level, compensated by tracked actions, weighed in posture until it expires.

AUDIT DAY VS EVERY DAY

The audit is a photograph. The posture is the film.

Left: what an audit certifies, valid the day it is signed. Right: what GRCOps runs the other days.

Illustrative data

Point-in-time audit Signed 12 March

  • MFA enforced on admin access
  • Supplier access reviewed
  • TLS 1.0 disabled on the HR portal
  • Backups tested quarterly

Six months later Two of these have drifted. The report still says green.

Runtime

  1. 09:41 MFA drift detected on sso-core
  2. 09:42 Action A-2291 created · owner IAM · SLA 72 h
  3. D+1 Escalated: 48 h without acknowledgement
  4. D+2 Closed on evidence · re-verified · 31 h, within SLA
Within SLA this month 94 %

WHAT YOU RUN WITH IT

Seven things you run with GRCOps.

Open one. The scene beside it shows what moves in the queue.

Sound familiar? A posture frozen on audit day Security work has no clock Exceptions that never expire Done without proof
01 Detect gaps at runtime

Continuous gap analysis on connected signals and verified controls: a control that drifts, a supplier answer that contradicts a fact, an advisory that matches your stack raises a finding the moment it happens, not at the next campaign.

  • Drift detected on connected signals, not declared
  • Findings raised where they happen, with the object kept
  • The posture moves the same hour
02 One queue for every security action

Risk treatments, control gaps, supplier remediation items, derogation compensating measures, audit findings and advisory matches all land in the same queue, each carrying the object it came from.

  • One queue, every source
  • Each action linked to the risk, control or supplier behind it
  • Nothing lives in an e-mail any more
03 A lifecycle, not a status field

Captured, qualified, assigned, in progress, awaiting verification, closed: every transition is an explicit decision with a trail, never a dropdown quietly changed.

  • Explicit transitions, each with a trail
  • Verification is a step, not a checkbox
  • The same lifecycle for every lane
04 Service levels, ageing and escalation

Every action carries a clock: a time to acknowledge and a time to close per criticality and per organization. Ageing and overdue work surface on their own, and what stalls escalates instead of sinking to the bottom of a list.

  • SLA per criticality and per organization
  • Ageing and overdue visible without asking
  • Escalation when the clock runs out
05 Derogations as a governed lane

Exceptions keep everything they had: a risk assessment at the gate, approval at the right level, compensating measures as tracked actions, scored coverage and an expiry that forces the conversation again.

  • Approval at the right level, trail attached
  • Compensating measures as tracked actions
  • Expiry that reopens the decision
06 Closure verified by evidence

An action closes on proof: the changed control, the attached artefact, the re-scored risk. “Done” means verified, and the trail says by whom.

  • Closure gated on evidence and re-scoring
  • Who verified what, recorded
  • The audit finds a trail, not a promise
07 Wired to where work happens

Actions sync both ways with the ticketing and messaging connectors from the marketplace, so teams work where they already are and the queue stays true.

  • Two-way sync with ticketing and messaging
  • Teams keep their tools
  • The queue keeps the truth
Inside GRCOps Action queue Lifecycle board Derogation lane SLA scoreboard Evidence trail

THE RUN

Posture is not what the audit found. It is what you closed since.

The audit report is a photograph; the posture is the film. Between two audits, controls drift, suppliers change, exceptions age. GRCOps treats security as operations: gaps are detected when they open, every action carries a service level, delivery is measured, and the posture moves because something was fixed, not because a box was ticked.

  1. 01

    Detect

    Gaps are raised where they open: from a drifting control, a supplier assessment, a derogation request, a matched advisory or an audit point, with the link kept.

  2. 02

    Drive

    Owners, dates and service levels are set, work moves through the lifecycle, ageing and overdue items surface, and stalled ones escalate.

  3. 03

    Prove

    Closure is gated on evidence and re-scoring; the trail records who verified what. The posture updates because something changed, not because a box was ticked.

THE RUN, MEASURED

Delivery performance, the way operations teams read it.

Security work gets a service level like any other operation: time to acknowledge, time to close, per criticality. GRCOps reads delivery against it.

GRCOps · delivery performance Illustrative data

Within SLA

94 %

Median time to close

6 d

Overdue

3

Escalated this week

2

Time to close against SLA, by criticality

Critical 72 h
High 7 d
Medium 30 d
Low 90 d

Each bar is the median time to close as a share of the service level; past the line is a breach. Ageing, overdue and escalation are the honest side of the posture, and the board reads them too.

FAQ

GRCOps, in practice

Is GRCOps a ticketing tool?

No. Tickets are where a task gets executed; GRCOps is where a security action is governed: its origin, its owner, its clock, its lifecycle, its proof of closure and its effect on the posture. The two sync both ways, so teams keep their tools and the queue keeps the truth.

What service levels can we set?

A time to acknowledge and a time to close, per criticality and per organization, with escalation when the clock runs out. Delivery is then read against those levels: within SLA, ageing, overdue, escalated.

What happened to Derogations?

They are a lane of GRCOps. Everything the derogation register did is still there: the risk assessment at the gate, the approval chain per organization, compensating measures as tracked actions, scored coverage, the expiry timeline and the weight on posture. They simply live with the other actions now.

How is closure verified?

An action closes on proof: the changed control, the attached artefact, the re-scored risk. The step before closure is a verification, and the trail records who did it.

Who sees the queue?

Everyone at their level: owners see their actions, managers their team’s backlog and ageing, the CISO the full view by organization, and the board the closure rate and SLA delivery the reporting derives from it.

FROM AUDIT DAY TO EVERY DAY

Bring your last audit report. Watch it become a queue.

A live session: findings captured, given a clock, driven and closed on proof, the posture moving in the same hour.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.