About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Alex serves CIO Professionals. His coverage includes business technology strategies, business sustainability, business-driven governance frameworks, process-oriented organizational design, change management, and continuous improvement. He is also a leading expert on best practices for making technology organizations more effective and business relevant through the implementation of service-oriented structures and process frameworks.
Alex helps clients partner with business peers to drive growth and customer engagement; develop business technology people and processes for future success; and adopt business process management (BPM), Lean, and Six Sigma to deliver business outcomes.
Prior to taking on his current role, Alex focused his research on Business Process Professionals' challenges, such as the development of business process architectures, portfolio management capabilities, centers of excellence, and deployment of change management programs. Before joining Forrester in 2005, Alex developed the IT consolidation program and managed the data center of a large European automotive company. Previously, he spent 10 years at IBM and EDS as an executive senior consultant and led several international customer projects in areas such as mergers and acquisitions, IT shared services, sourcing, organizational change, process, and technology management. Alex also worked for five years as a research scientist in the area of high-performance computing at the IBM Scientific Center Heidelberg, publishing in refereed journals and co-editing three proceeding books.
Alex received a master's degree in engineering from the Civil Engineering Institute in Bucharest, Romania, and a Ph.D. in engineering from the Technical University Aachen, Germany. He received a postdoctoral fellowship from Princeton University.
I'm proud to say that we published my report "Market Overview: GRC Platforms" earlier today. It will come as little surprise to most of you that the overall GRC market is still saturated with...

Practical Steps To Start Uncovering And Treating The Hidden Risks In Third-Party Relationships
This week we published the first in a series of reports I'll be writing to help clients calculate the return on investment of GRC technologies. This report, How To Measure The ROI Of A GRC...
As Leaders, BWise, MetricStream, IBM OpenPages, And RSA Archer Continue To Push The Envelope
Innovation among top enterprise GRC platform vendors has kept up an impressive pace as vendors aim to stay one step ahead of their customers' own advancements in governance, risk, and compliance...

Developing And Managing Efforts To Control Unacceptable Levels Of Risk
From understanding comes action. Your risk management efforts up to this point will have yielded a list of concerns; a measure of how much these concerns could affect objectives; and a decision of...

Guest post from Researcher Nick Hayes. If you had to go up one level in a train station, would you take the stairs or use the escalator? Most people would choose the escalator. But what if the...
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
What would you see as the governance, risk, and compliance characteristics of each of the following groups: 1) laggards; 2) middle of the pack; and 3) early adopters? Are there any special...
This report outlines Forrester's solution for security and risk (S&R) professionals looking to establish a formal risk and compliance management program. We designed this report to help S&R...
Of all the client inquiries and advisories we get related to risk management, one of the most frequent topics of discussion continues to be the role of risk management. Who should be involved? How?...
We're looking for software that assists with the management and auditing of gifts that our employees receive from customers and suppliers.
Governance, risk, and compliance (GRC) as a concept continues its steady march toward recognition as an accepted business practice. And even if they aren't using the term, organizations around the...
Practical Steps To Start Uncovering And Treating The Hidden Risks In Third-Party Relationships
The growing reliance on third-party providers is an increasingly uncomfortable trend for security and risk professionals. Financial pressures and efficient delivery models create great incentives for...
In my ongoing work with risk management professionals, I've been encouraged to see how quickly the role is growing in influence and responsibility in today's...
I’m proud to announce that this week Forrester launched our Governance, Risk, and Compliance Playbook, a collection of in-depth reports covering the critical information you need to implement a...
Road Map: The Governance, Risk, And Compliance Playbook
The governance, risk management, and compliance (GRC) technology market is one of fluctuation, confusion, and contention. Many technologies relevant for governance, risk management, and compliance...

Forrester's Security and Risk Management clients often describe the frustration they feel when they are not included in important initiatives until after decisions have been made. Lately, this...
Assessment Framework: The S&R Practice Playbook
This report outlines the assessment framework associated with Forrester's solution for security and risk (S&R) executives. The report is designed to help CISOs as they continue working their way...

Continuous Improvement: The Governance, Risk, And Compliance Playbook
When you're challenged by a constantly changing regulatory landscape, business environment, and risk profile, it's easy to overlook the critical role corporate culture plays in keeping compliance and...
Today IBM announced plans to acquire the Fitch Group’s Algorithmics, a heavy-hitter in financial risk management software and services market, for $387 million. Here are my initial...
Executive Overview: The Governance, Risk, And Compliance Playbook
Unexpected events are at best distracting and at worst catastrophic for an organization as it strives to meet its objectives. Risk and compliance professionals must help their colleagues anticipate...
We (IT security management) are currently discussing our tasks in relation to those of the auditing department. We would like to get advice about a typical or legally defined separation between the...
How long does it take a company to move up a level of maturity in Forrester's Information Security Maturity Model?