Cleveland, Ohio · Mon–Fri 8:30 AM – 6:00 PM ET
☎ (216) 832-6065  ·  security@graceandtaylor.com
Home / Insights

Field notes.

Short, plainly written observations from the practice — for operators, not compliance officers.

This Quarter

Six essays we published recently.

Compliance

Why your SOC 2 controls fail their second year.

The first year of a SOC 2 is a sprint. The second is a system. Most programs collapse in year two because they were built to pass an auditor, not to run a business.

March 2026 · 6 min read
Risk

The risk register no one reads.

If your executive team cannot describe the top five entries on your risk register from memory, you do not have a risk register — you have a spreadsheet.

February 2026 · 4 min read
Security

Tabletop exercises that survive contact with the real thing.

A good tabletop is uncomfortable. If everyone leaves the room feeling prepared, you designed it wrong. Here is what we look for.

January 2026 · 7 min read
Vendor Risk

The three questions every vendor questionnaire is missing.

Modern vendor DDQs ask 200 questions and answer none of them well. The three that actually matter never appear on the standard templates.

December 2025 · 5 min read
Board Advisory

Briefing a board that is afraid to ask.

Directors will not admit they do not understand your compliance program. Design the briefing so they do not have to.

November 2025 · 5 min read
Insider Threat

What insider threat programs get wrong about people.

Most insider threat programs are built by security teams and read by lawyers. The people they are meant to protect against never see them, and that is the problem.

October 2025 · 8 min read
Quarterly Letter

Four notes a year. Nothing else.

We publish a short letter each quarter. No promotions, no product pitches, no algorithmic sequences. Leave your address and you will receive one — and only one — email every three months.