---
title: "Compliance: Time for Companies to Raise Their Games"
description: ‘Governance, risk and compliance’. Three words that are senior managers' nightmares as the breadth and scope of this area continues to grow exponentially.
image: https://blog.wallix.com/hubfs/governance-risk-compliance-regulations-data-protection-reach-penalties-challenges.jpg
---

[![Wallix](https://blog.wallix.com/hs-fs/hubfs/LOGO_WALLIX_2024_black+orange-3.png?width=3108&height=827&name=LOGO_WALLIX_2024_black+orange-3.png "Wallix")](http://www.wallix.com/)

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/514643/6f69a618-d11c-44ef-ad26-88703b7dcab4.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/6f69a618-d11c-44ef-ad26-88703b7dcab4)

# Compliance: Time for Companies to Raise Their Games

[› › › BACK TO THE BLOG](https://blog.wallix.com)

 \[fa icon="calendar"\] Jun 8, 2016 6:30:00 AM / by [WALLIX](https://blog.wallix.com/author/wallix)

![](https://blog.wallix.com/hs-fs/hubfs/blog-files/WALLIX.png?width=35&name=WALLIX.png)

- [Tweet](https://twitter.com/share)

‘**Governance, risk and compliance**’. Three words that are the stuff of nightmares for senior managers. Not because they have done anything wrong, but because the breadth and scope of this area continues to grow exponentially.

 

![governance-risk-compliance-regulations-data-protection-reach-penalties-challenges.jpg](https://blog.wallix.com/hs-fs/hubfs/governance-risk-compliance-regulations-data-protection-reach-penalties-challenges.jpg?width=546&name=governance-risk-compliance-regulations-data-protection-reach-penalties-challenges.jpg)

 

 

# Higher Risks mean Increased Regulations... and Tougher Penalties

Their ability to get a good night’s sleep is not just affected by the ever-lengthening ‘to do’ lists associated with implementing **GRC**, but by the risks attached to their failing to do it properly.

According to a study carried out by [International Association of Privacy Professionals](https://iapp.org/news/a/study-at-least-28000-dpos-needed-to-meet-gdpr-requirements/) (IAPP), The new General Data Protection Regulation ([GDPR](https://blog.wallix.com/how-to-prepare-for-eu-standard-general-data-protection-regulation)) coming into force in the next two years will need **28,000 new dedicated data protection officers** in Europe alone. That’s a veritable army of new staff whose backgrounds will need to be thoroughly checked before being recruited, trained, sat somewhere, managed, fed and paid.

 

A fundamental part of these roles is to not just drive policies into the core of a business to avoid the repercussions, but also to **report in detail** should a breach occur. This reporting includes:

 

- The **nature of the personal data breach** including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

- A description of the likely **consequences** of the data breach;

- A description of the **measures** taken or proposed to be taken by the data controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

 

And this is on top of the 70,000 new jobs that the then head of financial stability at the Bank of England, Andy Haldane, predicted in 2012 would need to be employed in Europe by financial institutions [just to comply with the requirements](https://next.ft.com/content/cadd54a6-c3bd-11e3-a8e0-00144feabdc0) of the Basel III regime for banks.

 

The **penalties** for non-compliance are enough to induce insomnia too. Organisations can be fined **up to 4%** of their global turnover. This no longer represents a mere slap of the wrist but an almighty whack where it really hurts; on the bottom line.

 

## Tips for Successful Compliance

So what can companies do to [improve their performance in this area](https://contact.wallix.com/uk-wp-mazar-wallix)? As sports news has increasingly moved from the back pages to the front pages, let’s use a sporting analogy to guide us. High performing teams, we are told, need three things to succeed. They need:

1. the right **skills**
2. the right **structures** 
3. the right **attitude**

 If one of these three factors is missing, or weakened, then no amount of compensating the other two will suffice.

 

For those responsible for implementing GRC strategy, this translates as employing staff with an **appropriate level of knowledge**; for those staff to have appropriate (i.e. fit for purpose) systems, processes and procedures and, critically, for them to engender a relevant internal **cultural attitude** towards all aspects of GRC.

 

A simple, balanced scorecard approach will quickly identify which of these three factors is the weakest at any one time and can then drive the actions needed to rectify it. Continuously **measuring**, then **improving** these will drive up performance and ensure that the organisation’s GRC strategy is achieving its goals (as well as helping the CEO to get through the night).

 

## How We can Help

The[Wallix AdminBastion (WAB) Suite](http://www.scmagazine.com/wallix-adminbastion-suite/review/4532/)has a simple architecture designed for pervasive, sustainable deployment. It creates a single gateway with single sign-ons for access by system admins, controlling who goes where and also providing an audit trail.

 

WAB’s **agent-less** architecture is lightweight, making the solution **inexpensive** and **easy to deploy** and adapt. The agent-less approach mitigates the risk that changes in protected systems will require extensive revamping of the PAM solution.

 

[WAB](http://www.wallix.com/wallix-adminbastion-suite-privileged-access-management-solution/) has a simple architecture, but a sophisticated and rich feature set that can scale with even the largest organisations. WAB gives you the tools to make PAM an **enduring, pervasive and consistent** part of your security program.

 

Remember, the [best PAM solution is the PAM solution everyone uses](https://blog.wallix.com/the-best-privileged-access-management-is-the-one-with-100-utilization).

 

For more information about the Wallix AdminBastion, visit [www.wallix.com](http://www.wallix.com) or click below. 

 

[![Get our FREE DEMO to manage and monitor privileged access](https://no-cache.hubspot.com/cta/default/514643/6524372a-8dc1-4142-967d-da244db57c0a.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/6524372a-8dc1-4142-967d-da244db57c0a)

 Topics: [Reaching IT Compliance](https://blog.wallix.com/topic/reaching-it-compliance)

![WALLIX](https://blog.wallix.com/hs-fs/hubfs/blog-files/WALLIX.png?width=100&height=100&name=WALLIX.png)

#### Written by [WALLIX](https://blog.wallix.com/author/wallix)

### SIGN UP to receive our best articles!

## [![Get Access to our white paper : The Insider Threats Comic Book](https://no-cache.hubspot.com/cta/default/514643/21e4442a-b1c5-4e98-a7c1-54de89072624.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/21e4442a-b1c5-4e98-a7c1-54de89072624)

- Recent
- Popular
- Categories

### Lists by Topic

- [Preventing Insider Threat (91)](https://blog.wallix.com/topic/preventing-insider-threat)
- [Mitigating External Attacks (81)](https://blog.wallix.com/topic/mitigating-external-attacks)
- [Reaching IT Compliance (58)](https://blog.wallix.com/topic/reaching-it-compliance)
- [Controlling Third Party Access (33)](https://blog.wallix.com/topic/controlling-third-party-access)
- [WALLIX Products (29)](https://blog.wallix.com/topic/wallix-products)
- [Optimizing Cyber-Insurance (15)](https://blog.wallix.com/topic/optimizing-cyber-insurance)
- [Improving Cybersecurity (8)](https://blog.wallix.com/topic/improving-cybersecurity)
- [Cloud Security (4)](https://blog.wallix.com/topic/cloud-security)
- [Events (2)](https://blog.wallix.com/topic/events)

[![Get Access to our White paper : Major misconceptions about IT security](https://no-cache.hubspot.com/cta/default/514643/ce3632c6-744e-4bca-919e-6795f7c73b63.png)](https://cta-redirect.hubspot.com/cta/redirect/514643/ce3632c6-744e-4bca-919e-6795f7c73b63)

### Posts by Topic

- [Preventing Insider Threat (91)](https://blog.wallix.com/topic/preventing-insider-threat)
- [Mitigating External Attacks (81)](https://blog.wallix.com/topic/mitigating-external-attacks)
- [Reaching IT Compliance (58)](https://blog.wallix.com/topic/reaching-it-compliance)
- [Controlling Third Party Access (33)](https://blog.wallix.com/topic/controlling-third-party-access)
- [WALLIX Products (29)](https://blog.wallix.com/topic/wallix-products)
- [Optimizing Cyber-Insurance (15)](https://blog.wallix.com/topic/optimizing-cyber-insurance)
- [Improving Cybersecurity (8)](https://blog.wallix.com/topic/improving-cybersecurity)
- [Cloud Security (4)](https://blog.wallix.com/topic/cloud-security)
- [Events (2)](https://blog.wallix.com/topic/events)

see all

#### About Us

WALLIX is a software company offering privileged access management solutions to help enterprises, public organizations and cloud service providers protect their critical IT assets including data, servers, terminals and connected devices.

#### More Links

- [Homepage](http://www.wallix.com/)
- [Blog](https://blog.wallix.com/)
- [Wallix](http://www.wallix.com/company/)

#### Contact us

\[fa icon="phone"\] [Get the right number](http://www.wallix.com/contact/)

\[fa icon="envelope"\] [sales@wallix.com](mailto:sales@wallix.com)

\[fa icon="home"\] [Find the right location](http://www.wallix.com/contact/)

#### Follow Us

<https://twitter.com/wallixcom><https://www.linkedin.com/company/wallix><https://www.youtube.com/channel/UCKT58VqricukJJxBTlLonAw>

 Copyright® 2026 | Wallix - Trace, Audit & Trust

\[fa icon="chevron-up"\]

![](https://googleads.g.doubleclick.net/pagead/viewthroughconversion/880438901/?value=0&guid=ON&script=0)