grc-manifest.org DE

From GRC to Resilience

Cyber security has never mattered more. A pragmatic wake-up call for a secure future in Germany, Austria and Switzerland.

00 Preamble

Jobs depend on companies, and industries carry the supply of what people need to live: energy, water, health, finance, communication, public administration. Whoever attacks an organization hits the people who depend on it.

In 2008, Germany's Federal Constitutional Court recognized a fundamental right to the guarantee of the confidentiality and integrity of information technology systems, as an expression of the general right of personality. It protects people against state access to their systems. The right belongs to persons, not machines, and no duty to secure those systems follows from it yet. That duty, to guarantee confidentiality, integrity and availability in operation, was created by Europe: for the entities NIS2 covers, from energy supply to public administration, and for the operators of critical entities under the CER Directive. An organization that does not secure its operation does not just let a service fail. It takes from the people who depend on it the ground they stand on.

Today's model of governance, risk and compliance has in many places drifted away from this task. Too often it produces evidence instead of security, documentation instead of understanding, dependence instead of capability. Not because it has to, but because that is how it is rewarded. The yardstick it must be measured against should be a different one: whether it actually makes the operation more resilient.

I What we observe

01The threat accelerates, the defense stays on an annual cycle.

The time between vulnerability and attack is shrinking. In its incident investigations, Mandiant now observes exploitation, on average, seven days before the patch appears. Germany's Federal Office for Information Security (BSI) warns that artificial intelligence substantially lowers the effort, time and entry barriers for attacks. Yet the steering of the defense still organizes itself in audit cycles, annual reports and periodic reviews.

The rules have long demanded both, the regular and the event-driven review:

  • DORA for the ICT risk management framework at least once a year and after every major incident,
  • ISO/IEC 27001 at planned intervals and on significant change,
  • NIS2 with no fixed rhythm but proportionate to the risk.

What is readily lived is the annual date. The trigger sits in no calendar, and so the event-driven review often does not happen at all. Whoever assesses risks only once a year assesses risks that may no longer exist in that form, and overlooks those that have arisen since.

02Risk is thought in silos.

Information security, data protection, artificial intelligence, business continuity, suppliers and third parties: each discipline looks at risk with its own methods, at its own moments. The result is a patchwork of isolated views. Information security rates the cloud provider by its certificates, business continuity management (BCM) rates the same provider by its downtime. Both send it a questionnaire, both keep their own lists of measures. The same dependency is surveyed twice, maintained twice and, when it counts, handled twice. Between the silos lie the risks nobody sees: two providers hanging on the same cloud are one provider when it fails.

What has to be shared is the facts, not the verdict. For operations the service may be available, and from the data protection view the processing may still be unlawful. Both assessments may differ. What must not differ is the facts they rest on.

03Processes are documented, not lived.

Process documentation is written once and stays static. Organizations, though, change constantly, and documented processes and actual work drift apart.

Processes are the foundation: they map an organization's flow of information, and on them hang the dependencies on systems, suppliers and other processes. Whoever does not know their actual processes and dependencies cannot know their risks. And whoever does not know their risks cannot be resilient.

04GRC has become an end in itself.

The term is ambiguous: financial risk for some, cyber security for others, compliance administration for a third group. By GRC we mean the function that organizes governance, risk management and compliance as an apparatus of its own, with its own processes, roles and tools, not the three tasks themselves. For these remain necessary, for resilience more than ever. What weighs heavier is that this apparatus has turned from a serving support function into a bureaucratic end in itself: it leads a life of its own, shapes the organization around its needs and forgets whom it serves. Where the apparatus does not exist, in the municipality with half a position or the company with one head of IT, the same end in itself arrives from outside: as questionnaire, attestation and consulting contract.

05Regulation has overtaken the old model.

The GDPR, NIS2, DORA, the Cyber Resilience Act and the AI Act apply at the same time, and on top come the standards that customers and supervisors demand. No standard covers a regulation on its own, no legal act exhausts the obligations on its own. In law these are separate duties, in operation, however, everything lands on the same table: separate evidence obligations, separate auditors, separate cycles, and the same control is documented once more for each of them. The consequence: ever more resources for a support function, without the organization fulfilling its purpose any better or more securely.

06Compliance replaces security culture, and an industry lives off it.

Documentation and evidence say little about an organization's actual resilience. There are houses with patchy documentation and working emergency processes, and there are complete bodies of evidence behind which nobody acts correctly when it counts. The second is what gets rewarded, because paper is what gets audited: whoever writes, stays. What a legal act explicitly demands, the report within the deadline, the legal basis for processing, remains an obligation whether the culture is right or not. A paper tiger meets it. It protects nobody.

The rules often demand the right thing, the model rewards the wrong one. Consulting is bought for the evidence, because the evidence is what gets audited, and it delivers what was ordered. Whoever is paid by consulting days and tool licenses earns from the cycle, not from the client's own responsibility. Recurring demand alone does not prove that: some expertise an organization does need again and again, and sensibly from outside, too. We impute intent to no one. We name a structure and a yardstick: can the organization judge more competently for itself after the consulting than before?

What is missing is a lived security culture. It needs the backing of leadership and a culture of error in which someone reports a weakness without fearing for it. Only then do weaknesses come to light before an attacker finds them.

07Sovereignty is demanded, non-sovereignty is cultivated.

Digital sovereignty is negotiated as a matter of states, cloud providers and vendors, and there it has so far remained a slogan. Inside the organizations, where it would have to emerge, dependence is cultivated. In three relationships they answer for themselves: They delegate not only operations but also the ability to understand their own processes, risks and systems to consultants and providers. Leadership decides on processes, tools and security far from the people who do the work. Whoever selects the operating system, the cloud and the network components, no matter whether procurement or a business unit, determines whose law, whose update cycle and whose power to switch off apply, usually even before security and BCM are asked.

Whoever cannot recognize their own dependencies has no room to act. They have a risk.

Sovereignty is the question of capability at every level. It demands neither in-house development nor in-house operation. It demands the ability to judge, steer and change dependencies oneself. Whoever hands over operations must not hand over the ability to judge with it.

08The blind spot: communication and change.

Communication and change are the road on which enablement and cultural change happen at all. Because everyone is involved, nobody is in charge of it: no planning, no owners, no success criteria. What belongs to nobody gets passed on when it counts and ends in nobody being responsible. But when things get tight, this work is the first to go, and nobody has to justify that. Without it, every principle stays on paper.

II What we stand for

We propose replacing GRC with Resilience where the protection of the operation is concerned. Not as a new word for the same work, but as a yardstick: GRC must be measured by whether it actually makes the operation more resilient.

Resilience means an organization's ability to fulfill its purpose under disruption, attack and change, to recover from it and to learn from it, and with that to protect the people who depend on that purpose. Keeping going at any price is not what is meant. Sometimes safe emergency operation or a controlled shutdown is the right decision. Resilience becomes measurable in the service people need: how long it may fail, what minimum operation must stand, and how long recovery may take. What is meant is the operational resilience of the business, not personal resilience.

A term that means everything means as little in the end as GRC.

Resilience is a term from the human sciences: the ability to absorb shocks in the short term and to adapt in the long term. The whole organization needs that ability, financial planning too when the investor climate turns, and enterprise risk when supply chains or visa conditions for skilled workers tip. We do not claim the term for everything. That is why we draw a line. Enterprise risk management, corporate governance, financial compliance and general legal compliance remain instruments of steering the organization. The legal acts on the security of the operation belong to resilience. Data protection and AI governance also protect the rights of the people whose data is processed and about whom decisions are made. Resilience bundles them without replacing that purpose. Both fields share a process and risk base, some risks sit on both sides, the loss of skilled staff for one, and they answer different questions: one, whether the organization does the right thing, the other, whether it can keep doing it under disruption.

Resilience bundles

resilience/
├── information-security
├── data-protection *
├── artificial-intelligence *
├── business-continuity
└── suppliers-and-third-parties
* own protection goals

Stays steering of the organization

steering/
├── enterprise-risk-management
├── corporate-governance
└── financial-and-legal-compliance

Between the two this firm connection is needed, otherwise dissolving the silos creates two new ones. A shared table decides nothing yet. In the end one person carries the remaining risk and releases the means, and the legal acts now name that person: the management.

This is written for organizations that have to meet several obligations at once and still keep the business running: for public administration, for the operators of critical infrastructure (KRITIS) and for the Mittelstand, in Germany, Austria and Switzerland. Several obligations, one operation, one table. That holds in all three, with different density.

Our values

III Our principles

  1. 01Assess by currency and by risk, do not collect periodically.

    Controls are checked continuously, on change, on events, or at justified intervals. The audit frequency follows the risk. Checking more often is not yet an improvement: a check is only complete when the bad result has an owner and a date. We argue against the cycle as the only trigger, not against the cycle.

  2. 02Resilience starts at the beginning, not at the end.

    Security, privacy and risk requirements belong in requirements, procurement, development and every change process, not first in audit preparation. That has been called security by design for decades, and it is not new. What would be new is doing it: the security review is part of the change, not its afterthought.

  3. 03Evidence comes from the work itself.

    Evidence is the trace that work leaves: the ticket, the approval, the log. The trace holds up when it says what was done, on which system, with what result. A ticket without that answer is just another checkbox, a screenshot with it more than a snapshot. For measures that only take effect in an emergency, the exercise is the work, and its measure is how quickly the people involved master the procedure without a handbook. A tested backup has a recovery time, a merely existing one has a hope. What gets restored is not the server but the service that hangs on it.

    The exercise does not end with the report but with the change that follows from it, and with the next exercise that shows whether it worked. Where a check runs automated or with artificial intelligence, someone checks its result, and missing data counts as a finding, not as calm. Without such traces nothing is auditable, and without auditability every commitment stays on paper.

  4. 04Comply once, prove many times.

    One shared process and control foundation is mapped onto all applicable regulations and standards. Every control carries the reference to every requirement it serves, and every auditor gets their own view of the same body. What a legal act demands beyond that extends the foundation instead of duplicating it. A new requirement is first checked against what exists. Often a new reference is enough, sometimes a new procedure or a technical change is needed. A new document is rarely needed.

  5. 05Living processes are the foundation.

    Processes are kept current by the people who run them, in one place all disciplines use. That is work and needs a place: one owner per process and a slot in the meeting that already exists. A shared place does not mean everyone sees everything. Vulnerabilities and personal data stay with those who need them. Assessment builds on the real processes and their dependencies, not on documentation from three years ago.

  6. 06Threat-driven, not catalog-driven.

    Controls and risk assessments follow a current, fact-based understanding of the threats. Threat does not only mean attack: operator error, loss of staff, fire, power failure and the failure of a provider belong to it. Standards are the starting point.

  7. 07Enable, do not create dependence.

    Knowledge is built inside the organization. External advice is measured by whether the organization can judge and decide more for itself afterwards than before. Independent audit stays untouched by that. Where people of one's own are missing, one starts with outside people and writes the building of one's own into the contract. Every tender, every contract asks for knowledge transfer, exit capability and open interfaces. How much those answers weigh against the price is for the organization to decide. Unweighted, they lose to it.

    Exit capability only counts once the switch has been rehearsed, and two providers with the same subcontractor are one. Where the market leaves no choice, in operational technology (OT) and at many critical installations for instance, the dependency remains a risk that is named, assessed and carried deliberately, not one that is simply accepted.

  8. 08Security culture is the goal, compliance the result.

    The rules say what should apply. Whether it applies is decided by collaboration. We create the conditions under which it emerges, and then prove the compliance. Not the other way around. Some things a legal act demands regardless of culture, the report within the deadline, the legal basis for processing. That remains an obligation. Culture does not replace it, it makes sure someone takes it seriously before the auditor arrives.

    Whether culture holds shows in everyday work: what happens when security endangers a deadline. If leadership then decides for the deadline, it has revoked the culture, and no communication plan brings that back.

  9. 09Communication and change are a discipline, not an afterthought.

    They are part of every resilience effort, with their own planning, their own owners and their own success criteria. That change needs support is what every large consultancy sells. The difference lies in execution: one owner, one budget and one criterion by which, at year's end, it shows whether anything has changed. Talking alone implements nothing.

  10. 10Context decides.

    Agile or classic, automated or by hand, bought or built: we take what holds in the organization at hand, and we justify the choice. These ten principles, too, are no catalog to tick off.