staycool_ceo (1)
  • Agentic AI
  • 25th Sep 2026
  • 1 min read

Why GRC Teams Need Leverage Not More Capacity

sc2026_nick
  • Written by
Nick Rafferty
CEO and Co-Founder
View my profile on
In Short..
  1. Boards have asked GRC functions to do more with less for two decades. That challenge has only got harder: DORA, NIS2 and the UK's own Cyber Security and Resilience Bill are all adding new obligations at once.
  2. The global average cost of a data breach hit an all-time high this year, and the multi-year trend of getting faster at containing breaches has just reversed.
  3. Supply chains are the biggest blind spot. The average organisation now works with 286 vendors, and a compromised supplier is tied for the slowest kind of breach to contain, and the single most expensive.
  4. Most GRC technology still only makes the pressure visible. It does not relieve it. What's missing is a system of action, not another system of record.

SureCloud's Gracie AI answers this as a virtual team: Agents that complete work on your behalf, Skills that apply your own codified expertise consistently, and Personas that bring the context to make decisions the way your programme actually works. This is what staying cool actually looks like.

The Temperature Is Rising

In May I wrote that boards have spent two decades asking GRC functions to do more with less, and that the request had quietly become mathematically impossible. Four months later, I had expected to be writing about something else. Instead, the evidence has only accumulated faster.

The pressure was never going to ease immediately. DORA was a big change to UK risk since before I made that argument in May, and it with NIS2 and UK’s own Cyber Security and Resilience Bill are carrying new expectations for controls, new reporting requirements and new financial consequences.

But regulations are just governance that sit above what practitioners are already feeling.

In July, IBM’s 2026 Cost of a Data Breach Report pointed at an average breach cost of $4.99 million this year, an all-time high, after last year's decline. Containment time tells a similar story: it had been falling for five straight years, from 287 days in 2021 to 241 last year, and this year it rose again, to 247. The impacts are higher and yet teams are stretched when facing them.

Supply chains explain a good part of why. Industry research consistently shows vendor portfolios growing year on year, with many organisations now working with hundreds of third parties. Every new vendor is another blind spot: breaches and disruption caused by a compromised supplier took as long to identify and contain as any risk this year. They were also the single most expensive factor pushing costs up, adding US$227,250 on average, more than any other factor IBM measured. Organisations have little time for their internal posture and even less for their third-parties.

On top of this, AI governance has appeared as a growing concern pushed by boards at the same time they as they drive its adoption. AI acts as both an internal risk but also an external one with more than one in four organisations that suffered a malicious attack saying it was AI-driven. Teams have little understanding how it's being used and how to control it.

It is clear the temperature is rising. The question is no longer whether the pressure is real, it is whether your operating model was built to withstand it.

How rising temperatures affect the day-to-day

Speak to enough CISOs, CROs and compliance leaders and the same four impacts surface on repeat, regardless of industry, size or geography.

Capacity without headcount

Teams are being asked to cover more frameworks, more risk domains and more regulatory scrutiny with the same headcount they had two years ago. The math does not work, they cannot complete the work they receive, let alone build on their programme. They know what they should do, but the volume keeps growing and their expertise cannot scale to match it. Teams need to look beyond hiring, because adding more of this expertise means competing for scarce and expensive candidates.

Audit readiness as a permanent headache

When an audit approaches, evidence continues to sit scattered across systems, spreadsheets and inboxes that nobody has time to reconcile. And each audit has overlaps, differences and its own reporting requirements. The work all exists. It is simply not readily accessible at the moment it is needed, in the format that’s asked for.

Third-party risk as a bottleneck

Technology adoption and suppliers are the backbone of modern businesses. Each team asks for new tools that arrive faster than any team can properly assess them. And these assessments just represent a point in time view on a vendor’s risk with the gaps between reassessment growing larger and larger as the number of vendors increases. The volume and frequency is what kills this scaling. You can't get through it all before the cycle starts again.

AI risk arriving uninvited in the shadows

AI tools spread through the business and rarely reach a risk register until something has already gone wrong. By the time a control framework catches up, the exposure has been live for months.

None of these are new problems. What has changed is that they are all rising together, continuously, at a volume that cannot rely on just people. The operating model has to change through technology.

The GRC brief
New frameworks and control changes, monthly.

Teams keep reaching for the wrong fix

The instinct, when a GRC function is under pressure, or has faced an incident, is to find a tool that provides better visibility into the problem. The result, is an industry still trying to solve this with systems of record: better dashboards, better ways to collect evidence and better ways to present the past.

This system is necessary to ensure structure and explainability but it does nothing to change the jobs to be done. Visibility is not the same as resolution.

A risk manager who enriches their risk data with public feeds still must record and mitigate those risks. A compliance lead who can track every framework against their controls, still must collect the evidence associated with it and review it accordingly.

"The gap is not information. The gap is applying expertise at the pace the regulatory environment now demands, in spite of low capacity."

This is the distinction that most GRC technology has not yet crossed. The category has built better and better instruments for measuring pressure. It has not, until recently, built anything that actually relieves it.

What GRC teams need alongside those systems of record are systems of action. Platforms executing rather than simply describing. That distinction is becoming the industry's own dividing line, not just mine.

However finding the right system of action is becoming harder, even as new AI in GRC emerges. Since we launched Gracie AI ourselves in May we are seeing buyers be let down by bolted-on systems and overpromises that have clouded what can actually be delivered. Few vendors truly explain what their AI really does, what authority it holds, or what happens when it gets something wrong.

The answer needs to be a platform that acts as both that system of record and system of action. Gracie AI answers this with GRC’s first virtual team that works together to get complete control of the programme, not just a clearer view of it.

That means Agents that can complete work on your behalf, whether that is reviewing evidence or kicking off assessments. It also means doing those tasks consistently, anytime, using your own codified expertise via Skills, not just when the right senior person happens to be available. Finally, it means providing a deep context layer enriching Personas, virtual specialists with knowledge from the individual user, the business and the wider market to drive meaningful decisions based not just on generic advice but how your programme actually works.

Together this is a system that extends your reach, scales your expertise and improves the individual’s own role.

To deal with the rising temperatures, modern GRC capability should scale with the volume of work arriving, rather than with the size of the team processing it.

Staying Cool is not ‘hoping the problem solves itself’

GRC has stayed static for too long, the landscape is changing, and now more than ever teams cannot sit still and wait for their problems to resolve.

When I said the operating model needed to change, I did not think that SureCloud would be the only answer. For many organisations, particularly large enterprises, significant time will need to be spent on cultural challenges, on breaking down barriers and educating around the true value of the risk and compliance function. But since customers have got their hands on Gracie AI, for the first time in my career, we have seen the potential for GRC teams to change in weeks. To go from chaos to confidence. To stay cool.

Nick Rafferty is CEO of SureCloud. Visit SureCloud at the Gartner Enterprise Risk, Audit and Compliance Conference in London, 28–29 September 2026.

See it in action

See how Gracie AI scales your output and expertise

Google preferred sources
Found this useful?

Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.

Your next step
PRICING

See what SureCloud costs

A short form, no sales call. Pricing built around your GRC estate.

Get Pricing
4.2 / 5 · 46 reviews on G2
ANALYST REPORT

IDC names SureCloud the industry's first cross-domain agentic GRC platform

Read the independent analyst view on how SureCloud is redefining risk and compliance.

Download for free