A practical guide to risk quantification: what it is, why to quantify by scenario rather than risk by risk, how Monte Carlo simulation works (VaR, TVaR, loss tail), and how to get started without perfect data.
Latest news and updates
How to Conduct an Internal Audit of an ISMS Based on ISO 27001
As part of the Information Security Management System (hereinafter ISMS) cycle of this international standard, organizations must carry out internal audits at planned intervals to provide information about whether the…
GlobalSuite Solutions new brand!
We transform change into an opportunity GlobalSuite Solutions was born with the aim of helping organizations comply with regulations and optimize their processes. All this through a pioneering GRC solution…
Why Involve Area Managers in our GRC System?
A GRC system helps optimize processes and reduce the uncertainty that corporate risks and the level of compliance can generate in organizations. Its goal is to make them more robust,…
ERM vs. GRC: do you know what the difference is?
Which is the best solution for your organization? In this blog we will look at two major approaches, or methodologies, in the field of risk management: ERM and GRC. But…
What are Systems for Internal Control over Financial Reporting (ICFRS)?
What is ICFRS and why is it important? The Internal Control over Financial Reporting System (ICFRS) is a framework of internal processes and controls designed to ensure the accuracy and…
5 Questions You should Ask Yourself to Select the Best GRC Software for your Company
A GRC system encompasses the areas of Corporate Governance, Risk analysis and management, and Regulatory and legal Compliance. It is an essential part of organizations, as it aligns business objectives…
The Importance of Cybersecurity Awareness and Training
Today we live in a digitalized world, both professionally and personally, which creates a favorable environment for “cybercriminals” to profit from their illicit activities on the Web. To put this…
What is Cybersecurity?
Today there are more and more connected devices, both at a business and personal level, which creates more attack vectors that must be protected and monitored through cybersecurity. Any user…
ISO Standards and Regulations for Improving Cybersecurity
In a market like today’s, organizations seek to demonstrate trust to their customers and a commitment to the security of the information they handle. To this end, holding a certification…
Synergies between Risk and Compliance Regulations
How do I manage such a wide variety of regulations? Since the Corporate Compliance model was established in Spain in 2015 with the reform of the Criminal Code, companies have…
Compliance with regulations NERC-CIP
What is the NERC-CIP standard? The NERC-CIP standard is the Cybersecurity standard applied by electricity companies in the USA and which are responsible for the production and management of electricity…
ISO 37002 – Whistleblowing management systems
Do you know what ISO 37002 Standard is? Recently has been published the ISO 37002:2021, relating to whistleblowing management systems(whistleblowing management systems) This standard complements and complements the requirements in…
What are ESG (Environmental, Social and Governance) criteria?
What are ESG (Environmental, Social, and Governance) Criteria? In a world where sustainability and corporate responsibility are increasingly relevant, ESG (Environmental, Social, and Governance) criteria have become a key reference…
Criminal compliance in the supply chain
With the reform of the Criminal Code of 2010, the criminal liability of legal personswas introduced for the first time in Spain. Since then, companies would be liable for those…
How to Consider Controls in a Risk Management Strategy
Controls in the risk management strategy All organizations should develop, maintain, and update a corporate risk map whose objective is to provide the company with the status of the situation…
















