Knowledge BaseRisk Map Operating Model Templates Services About Work With Me
● Practitioner-Led GRC & Resilience

Governance That Runs Like
a Business

Every risk program is eventually asked to defend itself, in an exam, an outage, a board meeting, or a vendor incident. I build programs that hold up in that moment: advisory, templates, and practitioner writing from twenty years of enterprise risk, operational resilience, and governance work across global fintech, SaaS, and enterprise technology.

Programs built at
Fintech & Financial Services
SaaS
Enterprise Tech & Infrastructure
Featured, Free Prototype

The Risk Intelligence Map

A live world map of natural hazard, public cloud region health, country advisories, and cyber signal, every figure named, dated, and one click from the agency that published it. Type any address to score a site on the same 5×5 scale your register already uses, or paste a list to rank a whole estate. Incident and crisis teams watch it, risk teams score against it, and with your estate on it, risk leaders run it as a living BIA and dependency analysis.

  • 118 AWS, Azure & Google Cloud regions mapped
  • 9 live public feeds, each named and dated
  • 5×5 scoring on your existing register scale
  • 0 servers of mine in the path, nothing stored
Live Now

Every Signal, Traced to Its Source

Nothing loads until you press the button. Then each feed is fetched straight from the publishing agency to your browser, no server of mine in the path, and nothing stored.

Incident & Crisis Teams

Monitor events as they happen

During a live event the picture is scattered across agency sites, status pages, and news tabs. This is one watch screen for storms, outages, advisories, and cyber signal, each item named and dated, so the team sees what is moving near your footprint and briefs leadership from a source it can cite.

Risk Teams

Score impacts from live intelligence

Most 5×5 impact ratings rest on last year's judgment. Here the impact side is driven by current intelligence, geopolitical advisories, natural hazard, cloud region health, and rolls up to a screening score on the scale your register already uses. When someone asks where the number came from, it shows its arithmetic.

Risk Leaders

Run it as your BIA and dependency analysis

Your BIA, vendor register, and recovery plan describe the same geography and never share a coordinate. The private build puts your estate on the map, so what depends on what, where it runs, and where it recovers is one living picture, used day to day by operational teams and defensible in front of the board.

This public map is the working prototype, free to use, and it stays that way. Geospatial intelligence is an active investment area for the practice: the map keeps growing with customer feedback and best-practice research, and clients who engage now shape where it goes next. The paid engagement is the private build, the same console with your estate integrated, event monitoring and alerts for your teams, delivered on a platform that meets your security and privacy requirements.

Open the Full Map → See How That Works
The Idea

Where a Register Cannot Help You

Registers are lists of independent rows, and real losses cluster geographically. Three questions no register answers, and a map does.

🗺

Your sites and recovery targets

A BIA names a primary and an alternate in two text fields. Only a coordinate knows they are four miles apart, on the same grid, in the same flood plain.

Your vendors and their regions

Four diversified SaaS vendors in one cloud region are not four risks. They are one region risk with four names on it, and no vendor register will ever show you that.

👥

Your people

Duty of care is a geography question before it is a policy question. The map reports how many people live inside every exposure zone you score.

This is one part of a broader practice, alongside operating model design, resilience program builds, ERM, and regulatory readiness. Location and concentration risk is simply the part that finally has a decent interface.

See It Working Why Traceability Matters
20+
Years building GRC programs
8
Global organizations
20+
Compliance frameworks unified
$20B+
Federal revenue opportunity unlocked at Zayo
Templates & Tools

Stop Building From a Blank Page

Every template here is built for a moment of scrutiny: the rating an auditor challenges, the control mapping an examiner pulls, the continuity plan someone opens at 2am. Twenty years of program work, in workbooks that connect to each other, so a risk, its controls, and its recovery plan stay one lookup apart instead of three separate files.

  • Integrated Risk & Control Register, the flagship connected workbook
  • GRC Operating Model Canvas
  • Risk Register with Quantitative Scoring Model
  • Business Impact Analysis Template
  • Vendor Risk Assessment Questionnaire
  • Tabletop Exercise Playbook
  • Unified Control Framework Mapping
See All Templates →
Template Bundle
$1,797
All 7 tools, including the flagship Integrated Risk & Control Register. One-time purchase.
Save $750 vs. buying individually
Get the Bundle Or purchase individually from $197
Knowledge Base

What the Best Programs Get Right

Practitioner writing on the decisions, structures, and operating choices that make GRC programs perform, not just produce documents.

Operating Models

The GRC Operating Model Is the Program

You can have the best control library in the industry and still underperform. Here's why the operating model determines whether governance actually works.

Operational Resilience

Operational Resilience Is an Ownership Problem, Not a Framework Problem

Every major regulatory framework says roughly the same thing. Most programs still fall apart in a real incident. The frameworks aren't the problem.

ERM

Board Risk Reporting That Actually Drives Decisions

Most board risk reports are written to inform. The best ones are written to decide. That distinction sounds subtle. The operational difference is significant.

Customer Trust

Customer Trust Is a Revenue Function

Security teams have been saying security is a business enabler for years. The ones where it's actually true built a Customer Trust function and treated it like a sales asset.

ERM

Building an ERM Program From Scratch Without It Becoming a Checkbox Exercise

The framework isn't wrong, but leading with it almost guarantees you'll build something that looks like a compliance program instead of a risk management program.

AI & Automation

AI in GRC: What's Actually Useful Right Now

There's a lot of noise about AI transforming GRC. Most of it is vendor marketing. Here's what I've actually found useful, and where the hype is still running ahead of reality.

View All Articles
Signature Practice

GRC Operating Model Design

Most governance programs are built around frameworks. The ones that perform are built around operating models: clear ownership, defined workflows, and governance structures that reflect how the organization actually makes decisions. When an examiner asks who decides what, the answer should be one page, not a meeting. This is where I spend most of my time.

Learn the Approach Talk About Your Program
Weekly Dispatch

Practical GRC. No fluff.

One article per week on what makes risk programs defensible when they are questioned, written from inside real ones. No vendor pitches.