About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Kate serves Application Development & Delivery Professionals. She is a leading expert on customer service strategies. Her research focuses on helping organizations establish and validate customer service strategies, prioritize and focus customer service projects, facilitate customer service vendor selection, and plan for project success.
Kate has extensive industry experience, with more than 10 years of leadership at customer service software companies, where she held senior product marketing and product management roles. She is also a published author on customer service trends and best practices.
Kate earned a Bachelor of Science from the University of Toronto and a Master of Science from the University of Pennsylvania.
Of all the client inquiries and advisories we get related to risk management, one of the most frequent topics of discussion continues to be the role of risk management. Who should be involved? How?...
Vision: The Governance, Risk, And Compliance Playbook
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working to build their organization's governance, risk, and compliance (GRC) program. We designed...
I’m proud to announce that this week Forrester launched our Governance, Risk, and Compliance Playbook, a collection of in-depth reports covering the critical information you need to implement a...

An Overwhelmingly Diverse Market Struggles For Definition, While Few Leaders Emerge
How are governance, risk, and compliance (GRC) platforms priced? What can I expect for implementation costs?
A few weeks ago, Stephanie Balaouras and I posted a podcast on a topic that has been a high priority for many of our customers — how to apply risk management techniques to IT security. We know...
Estimating Levels Of Risk Exposure To Help Guide Informed Decisions
Opposition to adopting formal risk management tends to use the process of risk measurement as its attack target — it's too subjective, it's too complicated, or it's too much investment just to...
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
On the heels of Forrester's GRC Market Overview last month, this week we published my Governance, Risk, And Compliance Predictions: 2011 And Beyond report. Based on our research...
Despite some speculation that today's Supreme Court ruling might overturn large portions of the Sarbanes-Oxley Act (if not all of it), the final opinion will likely have no significant impact on...
Determining Whether, When, And How To Treat Risks
The goal of a risk management program is to drive effective decisions and actions based on an understanding of how uncertainty may affect objectives. However, even mature programs that have...
Business Case: The Governance, Risk, And Compliance Playbook
As the governance, risk, and compliance (GRC) platform market matures, product vendors struggle to point to credible return on investment figures, and potential buyers similarly struggle when asked...
Rarely does vendor consolidation reflect such fragmentation of a market. Picking up on the recent acquisition trend of independent market leaders, IBM today announced plans to acquire long-time GRC...
In my new report, The Risk Manager's Handbook: How To Measure And Understand Risks, I present industry best practices and guidance on ways to articulate the extent or size of a risk. More than...
Documenting The Sources Of Uncertainty That Might Affect Your Organization, Project, Asset, Or Objective
Enterprise risk management (ERM) programs are helping to break down organizational silos so that executives can gain insight on the risks that may affect all aspects of their business. Unfortunately,...
Strategic Plan: The Governance, Risk, And Compliance Playbook
Governance, risk management, and compliance (GRC) are far too often positions of emergency response. What's worse, as you constantly rush to respond to new mandates, enforce policies, or pull...

We (IT security management) are currently discussing our tasks in relation to those of the auditing department. We would like to get advice about a typical or legally defined separation between the...
Have you been having trouble getting your board of directors to care about information security? This weekend’s news that Nasdaq’s Directors Desk web application was...
I recently recorded a podcast with Stephanie Balaouras, discussing the potential for increased collaboration between crisis communication, business continuity, and risk management functions....
This report outlines Forrester's solution for security and risk (S&R) professionals looking to establish a formal risk and compliance management program. We designed this report to help S&R...
Governance, risk, and compliance (GRC) as a concept continues its steady march toward recognition as an accepted business practice. And even if they aren't using the term, organizations around the...
As Leaders, BWise, MetricStream, IBM OpenPages, And RSA Archer Continue To Push The Envelope
Innovation among top enterprise GRC platform vendors has kept up an impressive pace as vendors aim to stay one step ahead of their customers' own advancements in governance, risk, and compliance...
