About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

In his role as research director, Mr. Burris helps set the overall CIO role research agenda at Forrester, craft effective CIO research with our senior Forrester analysts, and ensure overall CIO research quality. His research team focuses on the evolving relationship between CIOs and CMOs, best practices in building and instituting an IT/BT strategy, BT innovation approaches to accelerate business outcomes, and social business and collaboration strategies.
His personal research includes the role of IT/BT in the age of the customer. He also contributes to the Forrester's research on social business, specifically focusing on the functional evolution of social computing tool sets and how they will be applied to conduct complex, marketing-facing work. Finally, he is a leading thinker on IT/BT adoption in business.
Mr. Burris joined Forrester in 2008. Prior to Forrester, he held numerous senior IT, marketing, and analyst jobs at leading organizations, including the DoD, HP, and Meta Group. At Meta Group, he jointly ran research, developing the advanced and broadly adopted "adaptive infrastructure" method for implementing plastic, services-based IT infrastructure.
Peter attended Yale University.
Among risk professionals who have successfully navigated their organization through a crisis, almost all will say that they had grossly underestimated the difficulty of communicating effectively...
Strategic Plan: The Governance, Risk, And Compliance Playbook
Governance, risk management, and compliance (GRC) are far too often positions of emergency response. What's worse, as you constantly rush to respond to new mandates, enforce policies, or pull...


As Leaders, BWise, MetricStream, IBM OpenPages, And RSA Archer Continue To Push The Envelope
Developing And Managing Efforts To Control Unacceptable Levels Of Risk
From understanding comes action. Your risk management efforts up to this point will have yielded a list of concerns; a measure of how much these concerns could affect objectives; and a decision of...

How are governance, risk, and compliance (GRC) platforms priced? What can I expect for implementation costs?
There has been an interesting PR battle in Washington over the last few weeks about the number of massive regulations still on the administration's agenda. House Minority Leader John Boehner...
Despite some speculation that today's Supreme Court ruling might overturn large portions of the Sarbanes-Oxley Act (if not all of it), the final opinion will likely have no significant impact on...
What would you see as the governance, risk, and compliance characteristics of each of the following groups: 1) laggards; 2) middle of the pack; and 3) early adopters? Are there any special...
This report outlines Forrester's solution for security and risk (S&R) professionals looking to establish a formal risk and compliance management program. We designed this report to help S&R...
We (IT security management) are currently discussing our tasks in relation to those of the auditing department. We would like to get advice about a typical or legally defined separation between the...
Guest post from Researcher Nick Hayes. If you had to go up one level in a train station, would you take the stairs or use the escalator? Most people would choose the escalator. But what if the...
Have you been having trouble getting your board of directors to care about information security? This weekend’s news that Nasdaq’s Directors Desk web application was...
After months of diligent product and vendor evaluations, today we published The Forrester Wave: Enterprise GRC Platforms, Q4 2011. In the next few days, we will also publish The Forrester Wave: IT...
Executive Overview: The Governance, Risk, And Compliance Playbook
Unexpected events are at best distracting and at worst catastrophic for an organization as it strives to meet its objectives. Risk and compliance professionals must help their colleagues anticipate...
How long does it take a company to move up a level of maturity in Forrester's Information Security Maturity Model?
Today IBM announced plans to acquire the Fitch Group’s Algorithmics, a heavy-hitter in financial risk management software and services market, for $387 million. Here are my initial...
Determining Whether, When, And How To Treat Risks
The goal of a risk management program is to drive effective decisions and actions based on an understanding of how uncertainty may affect objectives. However, even mature programs that have...
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
Estimating Levels Of Risk Exposure To Help Guide Informed Decisions
Opposition to adopting formal risk management tends to use the process of risk measurement as its attack target — it's too subjective, it's too complicated, or it's too much investment just to...
I recently recorded a podcast with Stephanie Balaouras, discussing the potential for increased collaboration between crisis communication, business continuity, and risk management functions....
After an in-depth survey of IT security and risk professionals, as well as our ongoing work with leaders in this field, Forrester recognized the need for a detailed, practical way to measure the...