John Paul Tran John Paul Tran

Discord’s Vendor Breach Exposed More Than Data. It Exposed a Risk Every Business Faces

In early October, Discord disclosed that a third-party vendor supporting its customer service operations had been breached, exposing user data including names, emails, and government ID photos. The contractor, 5CA, provided age-verification services. Attackers accessed internal support systems, stealing images and metadata tied to verification requests.

Read More
John Paul Tran John Paul Tran

Google Dodged a Breakup, But GRC Will Decide What Happens Next

After years of legal wrangling, Alphabet—the parent company of Google—has emerged from the Justice Department’s antitrust case largely intact. The ruling stops short of breaking the company apart or banning its search dominance outright. But make no mistake, this isn’t a free pass. It’s a warning shot to every company sitting comfortably atop its market.

Read More
John Paul Tran John Paul Tran

No More Quarterly Reports? The SEC’s Gamble and What It Means for Risk

The U.S. Securities and Exchange Commission (SEC) is preparing to upend one of the most entrenched practices in corporate America: quarterly reporting. SEC Chair Paul Atkins has signaled his intent to fast-track the removal of the decades-old requirement that public companies issue quarterly earnings reports, a change that could redefine how markets, boards, and regulators think about corporate transparency.

Read More
John Paul Tran John Paul Tran

The Future of Risk Isn’t More Control. It’s More Intelligence.

Most companies don’t see their GRC platform as a productivity tool that can boost business. That needs to change. In an environment where regulatory complexity is growing and resources aren’t, governance, risk, and compliance systems must do more than just audits. They should be helping you…

Read More
John Paul Tran John Paul Tran

The Hacker Didn't Win. And That’s the Point

When news broke that Coinbase had suffered a major breach, with hackers demanding a $20 million ransom after compromising sensitive customer data, there was every reason to expect the usual corporate playbook: silence, damage control, maybe a quiet settlement. But that’s not what happened…

Read More
John Paul Tran John Paul Tran

A Wake-Up Call: What the Change Healthcare Breach Teaches Us About GRC

The Change Healthcare data breach in early 2024 stands out as one of the largest in U.S. history, affecting over 100 million individuals and exposing vast amounts of sensitive health data. It’s a sobering reminder of the risks organizations face when security investments lag behind business operations…

Read More
John Paul Tran John Paul Tran

Understanding the CrowdStrike Crash: Investor Insights

Last week, CrowdStrike faced a significant issue involving their Falcon platform for Windows systems. On July 19, 2024, a faulty content update intended for Windows systems caused numerous crashes and blue screens of death (BSOD) on millions of customer machines.

Read More
John Paul Tran John Paul Tran

Why Vendor Management is Critical

Vendor management is crucial in today's interconnected business landscape. As organizations increasingly rely on external vendors to provide essential services and technology solutions, the need to ensure their reliability and security becomes paramount.

Read More
John Paul Tran John Paul Tran

Women in Cybersecurity and Legal Services

For our latest podcast, All About Risk, our CEO Lily is joined by a selection of the greatest female minds managing GRC programs for leading US Law Firms. Today’s podcast covers…

Read More