Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >Keeping IT GRC simple by getting IT SaaSed!
    Technology

    Keeping IT Grc Simple by Getting IT SaaSed!

    Published by Gbaf News

    Posted on March 20, 2013

    6 min read

    Last updated: January 22, 2026

    Add as preferred source on Google
    Richard Hibbert, CEO of SureCloud, addresses the complexities of IT Governance, Risk, and Compliance (GRC) in modern organizations, emphasizing the need for agile solutions to tackle cyber security challenges.
    Richard Hibbert discussing IT GRC solutions for cyber security risks - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Richard-HibbertOrganisations big and small need a collaborative approach to compliance, with affordable entry points and a more agile alternative to managing risk says Richard Hibbert, CEO of SureCloud

    21st century organisations are exposed to increasing levels of cyber threat as corporate boundaries are extended through the increased adoption of ecommerce platforms, the outsourcing of business processes to cloud-based providers, and employees’ use of personal devices and social networks in the workplace. As a result, the number of organisations reporting a security breach is growing all the time. In response a plethora of information security standards designed to mitigate risks have been introduced. These standards originate from multiple sources – internal governance teams, trading partners and regulatory bodies – as each takes steps to protect their interests. Even though these standards proffer similar practices and procedures, there is no common or unified approach frequently leaving organisations burdened with multiple, overlapping compliance standards. Furthermore, compliance involves many stakeholders: trading partners, regulatory bodies, external auditors, as well as an organisation’s own people such as the compliance, IT and executive teams. As such compliance cannot be viewed as a single internal process; it can be extremely complex, crossing businesses functions, and transcending corporate boundaries and processes, and needs to consider the different interests and objectives of each stakeholder.

    A market with more challenges than answers

    Even when it comes to an area driven by regulatory requirements – as Governance, Risk and Compliance (GRC) is – IT spend is kept under careful scrutiny. This creates a recurring problem for most of today’s leading enterprise IT GRC solutions. They are comprehensive in nature and require organisations to adapt internal processes to meet proscriptive software that demands best practice at every level. Their all-or-nothing quality makes it difficult to pilot solutions. Valuable resources are tied up managing multiple point solutions and projects inevitably suffer from lengthy implementation timeframes. And there is a direct correlation between implementation time and the potential for project failure. Another reason for failure is that the software licences are too complicated for what organisations need.

    In the absence of automated GRC applications the only real alternative left to IT and compliance teams is to rely on the next best tools for the job – spreadsheets. Spreadsheets are regularly used for such risk assessment activities as asset registers, compliance audits, project planning, risk treatment, records management, 3rd party assurance, user awareness questionnaires, incident responses, gap analysis and management reporting. It is not uncommon to find 100’s if not 1000’s of spreadsheets in circulation between multiple internal and external stakeholders from internal auditors, HR and IT to external auditors, trading partners and suppliers. Process and workflow management, however, tends to be manual rather than automated leading to a scatter-gun approach that is inefficient, labour intensive and complicated. An over-dependence on spreadsheets makes the compliance process extremely time consuming, inefficient and prone to human error. Such inefficiencies have hidden costs and run the risk of delivering results that are not fit for purpose.

    Simplifying compliance the SaaS way

    SureCloud advocates a collaborative approach to compliance using a Software-as-a-Service model. This approach has key advantages. First, it is much simpler. Immediate compliance goals can be met with a short-term project for just a few thousand pounds rather than having to commit hundreds of thousands to doing everything over a much longer period. Second, starting small and evolving processes to suit specific solutions or use cases over time results in greater agility and considerably reduces the risk of IT GRC project failures. By adhering to four central pillars – agility, accountability, connectivity and scalability – it is possible to automate any IT GRC process. At the heart of the solution are a set of standard template forms – designed in collaboration with hundreds of partners – for all of the key standards that give users the ability to define any input according to fields, lists, formulae or any other type of system object. Single tasks can be built up easily into projects. A central library (with links to SharePoint) stores all documentation and connects to the compliance process. Customer data can either reside within SureCloud or stay on-premise and merely link to the solution. There is a powerful records management facility with granular permissions. Evidence and records can only be approved or removed with the appropriate authorisation allowing organisations to demonstrate their compliance with requisite rules and regulations. Additionally in-built workflows, reports and dashboards help users deliver management and operational information (or they can develop their own if they choose to). Internal and external groups are given access control and the status of their individual input is reflect on the dashboard giving the customer actionable intelligence about they meet compliance, where they do not and where suppliers are posing a risk.

    Collaborative compliance in action

    SureCloud is able to point to hundreds of financial, retail and central & local government organisations who are benefiting from its approach. One leading UK debt collection agency is typical. Their clients, comprising leading financial institutions, expect a demonstrable a level of compliance with standards such as the Payment Card Industry Data Security Standard (PCI DSS), the Data Protection Act and ISO27001. The collaborative compliance approach has allowed this customer to consolidate multiple solutions into one platform and gain a clear picture of security status and demonstrable compliance with PCI-DSS. Plus

    • Reduced TCO with multiple point solutions in a single platform
    • Clear user interface – easy access to information
    • High quality penetration testing services
    • Highly responsive customer support – product and security related.

    Conclusion

    Information security compliance is designed to help, not hinder. It recognises the significant value of corporate information assets and the need to safeguard them, both for competitive advantage and to protect personal privacy. With a simpler, streamlined approach that enables collaborative working, every touch point in your information value chain can contribute to your information security programmes, ensuring that compliance is achieved, and maintained, in a cost effective manner. Collaborative compliance embraces multiple internal teams and systems, as well as external stakeholders, to bring together the fragmented compliance landscape and streamline IT GRC processes. With SaaS underpinning the delivery and commercial model, collaborative compliance is the way ahead for organisation seeking visibility and control of their information security programmes, at a price point that encourages trial and de-risks enterprise rollouts.
    Most organisations today are seriously under-estimating how easy achieving demonstrable compliance can be.

    SureCloud is exhibiting at Infosecurity Europe 2012, the No. 1 industry event in Europe held on 24th – 26th April 2012 at the prestigious venue of Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

     

     

    More from Technology

    Explore more articles in the Technology category

    Image for Nominations Open for Technology Awards 2026
    Nominations Open for Technology Awards 2026
    Image for Nominations Open for Innovation Awards 2026
    Nominations Open for Innovation Awards 2026
    Image for Archie earns industry recognition across G2, Capterra, and SoftwareReviews
    Archie Earns Industry Recognition Across G2, Capterra, and SoftwareReviews
    Image for The Bankaool Transformation: How a Regional Mexican Bank Became a Fintech Disruptor
    The Bankaool Transformation: How a Regional Mexican Bank Became a FinTech Disruptor
    Image for Submit Your Entry Today for Digital Banking Awards 2026
    Submit Your Entry Today for Digital Banking Awards 2026
    Image for Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Image for Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Image for Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Image for Entrepreneurial Discipline in the AI Economy: Insights from Dmytro Lavryniuk
    Entrepreneurial Discipline in the AI Economy: Insights From Dmytro Lavryniuk
    Image for Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Image for Call for Entries: Best Digital Wallet 2026
    Call for Entries: Best Digital Wallet 2026
    Image for Nominations Open for Brand of the Year Technology 2026
    Nominations Open for Brand of the Year Technology 2026
    View All Technology Posts
    Previous Technology PostSystem State Intelligence and the Intrusion Kill Chain
    Next Technology PostThe Ciso as the Man-in-the-Middle