About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Nick is a Researcher serving Security & Risk Professionals. His research is dedicated to the organizational and strategic elements of building a successful governance, risk management, and compliance (GRC) program, including a focus on culture, communications, and other human aspects of GRC. Specific areas of expertise include how organizations can improve corporate culture as well as best practices for dealing with the emerging risk and compliance challenges of social media.
Nick works with clients to understand industry benchmarking data and best practices to implement effective change. In addition to the focus areas described above, he has experience delivering consulting and advisory work in areas including enterprise and IT risk management, information security program effectiveness, security awareness, and security services.
Prior to his current role as a researcher, Nick was a senior research associate on Forrester's Security & Risk team. In that role, he interviewed hundreds of IT professionals and technology vendors while conducting primary and secondary research for Forrester reports and consulting engagements. Before joining Forrester, Nick studied government at Wesleyan University with a focus on international politics, working on topics such as international security and foreign policy.
Nick graduated from Wesleyan University with a B.A. in government.
For too long, creating security awareness has been an afterthought, something CISOs did in their spare time after putting out the operational fires that sprang up around them with alarming regul...
From frantic security operations problems to the changing threat landscape, CISOs, senior security leaders, and other IT risk management leaders consistently have trouble keeping up with key tre...

Year after year, when asked to name the top lessons learned from contingency plan invocations, organizations consistently cite that they underestimated how difficult it would be to communicate e...
Governance, risk, and compliance (GRC) encompass an incredibly broad set of functions for organizations in any geography, in any industry. In fact, almost all employees play some role in helping...

Unexpected events are at best distracting and at worst catastrophic for an organization as it strives to meet its objectives. Risk and compliance professionals must help their colleagues anticip...
The global downturn has constrained security budgets for several years now, and chief information security officers (CISOs) have become accustomed to taking on more responsibilities without corr...
When you're challenged by a constantly changing regulatory landscape, business environment, and risk profile, it's easy to overlook the critical role corporate culture plays in keeping complianc...
Social media is a security and risk nightmare — it's used everywhere, all the time, by everyone both outside and inside your organization. Although social media offers potentially great ma...

The goal of a risk management program is to drive effective decisions and actions based on an understanding of how uncertainty may affect objectives. However, even mature programs that have soph...
The governance, risk management, and compliance (GRC) technology market is one of fluctuation, confusion, and contention. Many technologies relevant for governance, risk management, and complian...

Failure of corporations to comply with regulations and to manage risks puts customers, employees, communities, and shareholders at risk on a daily basis.