Thank you for Subscribing to CIO Applications Weekly Brief
Thank you for Subscribing to CIO Applications Weekly Brief
Verterim has been recognized by CIO Applications Magazine as the exclusive recipient of “Top 25 GRC Technology Solution Companies- 2019,” based on our proprietary methodology, reflecting its position in the industry, and is also named among “,” reflecting its broader leadership. This profile has been developed by the CIO Applications research and editorial team based on insights from an interview with Peter Ridgley, Founder & President.
Peter Ridgley, Founder & PresidentTo revolutionize the GRC industry with a programmatic approach as opposed to a tech approach, Ridgley used his experience and knowledge to set the wheels in motion for Verterim in 2013. A Massachusetts-based company, Verterim today has established itself as a promising GRC solutions provider focused on four major areas: providing hosting and managed services, offering innovative GRC integrations with third party applications to enrich GRC content, reselling value-added GRC products, and delivering consultancy for implementation to ensure that the established GRC program lives and breathes into perpetuity. Having been on the customer side of the GRC Solution, the highly skilled consultants of the company have gained a competitive edge as they understand the business as well as the technology.
In an interview with CIO Applications, Peter Ridgley, founder and president of Verterim and Jennifer Pesci-Anderson, vice president, national practice lead give valuable insights about the company’s solutions and how Verterim is revolutionizing the GRC landscape by combining people, business processes, and technology.
1) Can you elaborate on the trends and challenges that you are helping your clients address in the market?
In today’s fast-paced digital world, increased regulatory and market scrutiny is driving organizations to adopt a structured approach to GRC. For instance, General Data Protection Regulation (GDPR) and the new California Privacy Act has raised the data protection bar for companies forcing them to partner with third parties to have comprehensive oversight into regulations and be able to implement better processes and technologies.
Data management is another aspect that has become a challenge for CIOs. Organizations currently are overwhelmed with data, and it is important to harness meaningful insights to transform the data into actionable information. An understanding of the trends that are impacting a client industry is required to make collected data more intelligent and relevant while ensuring that the systems work toward detecting, predicting, and responding to different risk indicators. As a first step, we take a look at the customers’ system and business environment during the pre-sales scoping and review process, understand their IT, Cyber and / or compliance posture from a risk perspective, and subsequently deliver scalable and sustainable solutions.
As a part of managed services, we offer GRC-as-a-Service. Through this offering, we truly understand industry-specific business processes while automating, integrating, and building workflows with appropriate notifications and dashboard measurements.
Organizations currently are overwhelmed with data, and it is important to harness meaningful insights to transform the data into actionable information
2) Can you tell us more about the unique approach Verterim follows?
We follow a phased delivery approach, where we combine the best of agile and waterfall methodology, coupled with our deep business experience to provide advisory services that translate into quick-time-to-value deployments. Our team can provide a clear-cut plan and intricate details about the entire process using this approach. We begin the process by asking a set of questions depending on the market and the process is automated to better understand the business process before implementing the appropriate tool.
Our role is to be an interpreter for our clients. As we work with clients who are mainly in legal and compliance departments and third-party risk and procurement, their knowledge of implementing technology may be limited. As an interpreter, our objective is to pull the best of the best from their business processes and integrate it with the appropriate process within the tools that we support. The major reason we have to be the interpreter is that more often than not, most CIOs look at GRC implementation through the lens of pure technology and businesses (end users) see through the lens of business process. This creates a language barrier that we can solve.
From a deployment perspective, we are very focused on the business needs of an organization to create efficiency and economy of scale. This helps them realize and achieve their desired goals. As a part of our engagement process, we mentor and educate our clients about GRC processes and technologies available in the market, which help them to become the interpreters for their companies as new people come on to the program.
3) Could you share a specific customer success story in which you helped your customer to unveil hidden threats?
I would like to share a scenario where we helped a few companies that were establishing a cyber rating system like a credit rating or credit score for strategic evaluation. This is specific to externally observable IP addresses used to determine vendor viability. We have developed a solution using GRC platforms and rating platforms, which collect quantitative security assessment valuations and integrate them with qualitative assessment capabilities inside a GRC vendor risk solution. The integration allows organizations to compare the quantitative risk ratings, similar to a credit score with other qualitative data providing clients a detailed perspective of their vendor and allowing a more profound and action-oriented conversation about the difference from what was said versus what was evaluated. With this integration ability, we have honed specific areas that help us in identifying and solving issues efficiently, which will, in turn, strengthen the customers’ security posture and enhance their relationships with their vendors.
Several customers and partners rely on our advanced GRC solutions. The areas in which we have driven the most success are those taking advantage of our hosting and managed services, integration practices and our advisory deployment strategy.
4) What does the roadmap hold for Verterim in the next 12-18 months in terms of your offerings?
We are very well grounded in the foundational elements of GRC, which helps us shape a better future. One of the things we are focused on going forward is the establishment of a reusable software development kit.
Unlike traditional SDK tools, this kit includes reusable code concepts, templates, and configuration elements that help consultants to pull well-established functions and reuse them. This makes the speed to deployment much faster and quicker than if you were to start from scratch and work on a time and expense basis with a dollar per hour value. Our clients reap the benefit as we standardize functional deployments in this fashion.
We always tell our customers that when you are working with us, you are not hiring a single consultant, but you are hiring the entire team behind you. It is a team that continually backs you up with a library of GRC features and functions that are well established, which makes the scoping of professional services engagements a lot more discreet.
We also intend to roll out GRC accelerator packs, enabling clients to get started with GRC more intuitively and quickly than conventional means. This quick start approach will become the foundation for building, integrating, and maturing their GRC program overtime at the pace that works for our clients. We will continue to transform how GRC is deployed and managed so our clients can focus on their core business and obtain the value from an integrated platform in an accelerated timeframe.
CIO Applications Weekly Brief
Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications
