How should a risk officer feel about taking risk? What is the ideal ‘risk attitude’?
I joke about what GRC means. Apart from the IIA (who talk about governance, risk, and controls), everybody knows that the acronym stands for Governance, Risk Management (or ERM), and Compliance.
Today’s post contrasts two recent pieces. PwC shared some very traditional thinking in Overseeing cyber risk: the board’s role.