About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Vikram leads the forecast team, which is responsible for producing all forecasts within M&S research. He is focused on the consumer commerce areas including retail, travel, and financial services. He is keenly involved in understanding the evolution of consumers' online behavior and technology adoption.
Vikram came to Forrester Research through its acquisition of Jupiter Research, where he started in July 2000. Prior to Jupiter, Vikram worked at IRI, a leading market research company, where he worked closely with some of the leading CPG companies.
Vikram often appears on TV, radio, and comments in the press on the US online retail and travel industry. He has been quoted in The L.A. Times, Business Week, The New York Times, CNN Money, and American Banker. He has also appeared on CNBC, Bloomberg TV, and Radio, NPR, Fox Business News, and ABC.
Vikram earned an M.B.A. from Virginia Tech and a B.Com from N.M College in Mumbai, India.
Rethinking Data Discovery And Classification For Data Security
Defining data via data discovery and classification is an often overlooked, yet critical, component of data security and control. Security and risk (S&R) pros can't expect to adequately protect data...

Strategic Plan: The Governance, Risk, And Compliance Playbook
Governance, risk management, and compliance (GRC) are far too often positions of emergency response. What's worse, as you constantly rush to respond to new mandates, enforce policies, or pull...

Organizations continue to face risk for security breaches. Normally, we talk about the risk of security breaches being fines and other costs around loss of PII, per California Senate Bill 1386 and...

Many organizations today get caught up in what I call the “social media binary,” where there are only two options to social media control: 1) Allow unrestricted access to social networks,...
How do retailer websites handle login expiration? Is it session-based, login-persisted, 30-day cookie, and so on? What is the norm or best practice?
Estimating Levels Of Risk Exposure To Help Guide Informed Decisions
Opposition to adopting formal risk management tends to use the process of risk measurement as its attack target — it's too subjective, it's too complicated, or it's too much investment just to...
SaaS Values Are Established, And Vendors Move Quickly To Capture Market Share
Content security products enable organizations to protect against email- and web-borne threats, enforce acceptable use policies, and guard against data leak risks. SaaS delivery has been a game...
Even though it is not specific to security, this idea came to me while attending Dell’s Annual Analyst Conference (DAAC) in Austin, Texas two weeks ago. One of the hot topics discussed at...
We're looking for current best practices and recommendations for Active Directory (AD) password policies.
Business Case: The Governance, Risk, And Compliance Playbook
As the governance, risk, and compliance (GRC) platform market matures, product vendors struggle to point to credible return on investment figures, and potential buyers similarly struggle when asked...
Protect Yourself From Hacktivists And Other Cybercriminals
Until recently, distributed denial of service (DDoS) attacks had been part of infosec lore: something you heard about but rarely experienced. With the rise of hacktivist groups and other...
Companies often demand to know what their peers in a particular vertical market are doing within the realm of information security before making new decisions. “We’re in retail” or...
We hear a lot about cloud IAM vendors offering metadirectories or user repositories in the cloud. We predict that in 1-2 years we'll see AD being moved from on-premises installations into cloud...
In a recent Forrester/DRJ joint survey on BC preparedness, of organizations that have invoked a BC plan in the last five years, 37% said that their BC plans had not adequately addressed...
Business Impact: The Data Security And Privacy Playbook
Protecting customer data such as credit card information, log-in credentials, and personally identifiable information is an important part of enterprise IT security. Such data fuels a large and...

How does Forrester define Advanced Persistent Threat?
Policy And Procedures: The S&R Practice Playbook
Over recent years, the information security industry has matured nicely; experts and associations have documented many best practice models, and their adoption has been widespread. It's disconcerting...
What Security Professionals Need To Know Today About Smart City Initiatives
With the promise of improved citizen services and more efficient use of scarce resources, the smart city trend is picking up momentum across the globe. A "smart city" integrates technology with...
This report provides insight into corporate mobility adoption trends based on results from Forrester's Forrsights surveys of IT mobility decision-makers and end user workers in North American and...
What is the size of the governance, risk, and compliance (GRC) market, and what is the market growth rate in India? Who are the major GRC vendors in India, and what are the areas of opportunity?
Protecting Information Consistently With Identity Context (PICWIC) Is A Must
According to Forrester survey data, "trusted" insiders and business partners, intentionally or unintentionally, are responsible for 43% of security breaches. The recent WikiLeaks breach illustrates...

We would like to know, in the event of a disaster: 1) Whom should we call; 2) what format is best; 3) what kind of information/instructions should we provide on the call; and 4) what kind of...
Greetings everyone. My name is Andrew Jaquith, and I serve security and risk professionals. Normally I blog over on the S&R analyst team blog. But because Forrester has been receiving so many...