Many organizations proudly claim to have IT governance in place, yet when faced with audits, incidents, or transformation projects, weaknesses quickly surface. Governance often remains a paper exercise, detached from real operations. This gap between theory and practice undermines trust, slows innovation, and exposes enterprises to significant compliance and security risks.
The future of governance is not about more policies but about embedding technology into accountability. Automation, continuous monitoring, and integrated risk dashboards turn governance from a checkbox activity into a living framework. By linking compliance, strategy, and daily IT operations, companies can create models that are measurable, transparent, and adaptable to disruption.
Kai Boschert, Senior Advisor & Deputy CISO at KuppingerCole will challenge common misconceptions around IT governance. He will expose why traditional approaches fail, demonstrate how to balance regulatory requirements with business agility, and outline methods to make governance an enabler rather than a bottleneck. Kai will also share case insights on scalable, real-world governance practices.
Who Should Attend
CISOs, governance leaders, compliance managers, architects, and transformation officers seeking to align IT, security, and regulations with effective governance.
Welcome dear gentlemen and ladies to the webinar of Building Blocks of an Effective IT Governance Organization. My name is Kai Boschert, Senior Advisor and Deputy CISO at KuppingerCole and today I'm the presenter leading you through this presentation and through this very interesting and important topic of IT Governance Organization. Before we start and roll into the presentation, a few housekeeping rules. You are muted centrally, we are controlling this feature so no need from your side to do anything, so we are in control here. During this presentation we will roll out some polls.
I encourage all of you to really take part of the polls and give some answers. Those are very interesting and might lead to very interesting results. In the end we will have a Q&A session where we can discuss the results as well as questions which occur. Feel free to use the chat function of this presentation and as well don't hesitate to raise any questions which might be interesting for you during the presentation. I will have an eye on the questions.
If it's very interesting I might come to the question directly else we have the Q&A session in the end and finally we are recording this webinar so the recording and the presentation slide deck will be made available for download in the coming days so there's no need for you to take any screenshots and you will be able to receive the full presentation. The topics for today are sectioned in three general parts.
In the end the Q&A session which I already mentioned, beginning with the bridging operations and compliance, understanding where and why the organizational gap between performance and accountability occurs and how IT governance can bridge this one. Secondly, defining the vision and framework for IT governance and finally implementing and scaling governance. As you can see those are very interesting topics and be sure we will have very interesting discussions on that. Before we run into the presentation as I mentioned I prepared a small poll for you.
This poll will be open during the presentation. I encourage you again to really take part on the polls and give your answers here and then we can discuss it in the end. So the question here is have you already established an IT governance organization within your company? As you can see on the left side we have three times yes and the right side we have three times no and there are some distinctions between yes and no so go through carefully and provide your answer and during the presentation there's no need to rush yourself.
You have plenty of time to have this answered and I'm really looking forward to all of your answers here. So as I introduced already bridging operations and compliance there's usually or commonly a gap between IT operations and security and compliance. We have one on the left side the operational reality focusing on uptime efficiency and delivery driven highly by deadlines and cost pressures and trying always to reduce tool complexity in the environment.
So it is very the hands-on reality of the IT where we need to react to incidents and regulatory changes and have a lot or more sometimes at least fragmented documentation and the unclear ownership of processes and responsibilities. On the other side we have the regulatory and risk reality focusing highly on controls audits and risk reduction driven by regulatory obligations and requiring verifiable governance not just security measures and often disconnected from the actual operational reality the IT execution and their priorities.
So if we summarize those on the left side we have efficiency delivery and performance as the key topics and on the right side assurance accountability and risk reduction to break it a little bit down and then as always the question how can we in our organization somehow bridge the gap between those two realities and there the IT governance comes really into play and providing structure providing function processes roles as well as a roadmap for future readiness.
Bear with me we will come to all those statements during the presentation but just to give you a brief and a glimpse of the overview of the IT governance and how it bridges IT operations and security and compliance or at least how it could bridge those topics. Before we continue here I want to highlight a little bit different terminology of strategy governance and compliance. As you can see on the left side we have strategy which sets the direction of a company so it really defines what the organization aims to and gives the intent of the course.
Governance in the middle is more or less the framework between compliance and strategy. It defines how the organization ensures the strategic objectives and how it can achieve those responsibilities. It provides a framework of roles processes and controls that align with said strategy as well as giving the operations something to grasp on and really help to implement those the strategy.
Compliance as you all are aware of I'm sure ensures the adherence so it gives the assurance that activities are executed according to defined rules and obligations so it verifies adherence to internal policies standards and external regulatory requirements. So it comes from strategy goes to governance and then compliance or in other words from intent to framework to assurance. What is the key takeaway here already?
Governance connects strategic direction with operational accountability and is aligned with organizational objectives to maintain sustainable compliance transparency and control across the organization. So as you can see here already governance does bridge a lot of topics and is not only one-dimensional having operational and security but also connects strategy and compliance. Defining the vision and framework for IT governance. It's the next step so nothing can go without a vision.
So how can we provide something everybody can align on and really have a common course and can have the same direction within the company. Usually we give it with a vision where we all can align on and agree on. A common vision for IT governance is to act as the central bridge between operational IT functions and regulatory oversight as we already saw on the first slide and really manifesting this whole structure in a target operating model providing the structural foundation for IT governance.
So as you can see we have here a general concept bridging operational IT functions and regulatory oversight ensuring strategic regulatory and risk-running requirements and then putting them into a real operating model a target operating model providing the structural foundation within your company. Of course a vision without goals is no real vision so therefore five exemplary goals for the IT governance. Strengthen regulatory conformance, increase transparency, improve risk steering, enhance accountability, enable sustainable responsiveness.
So as you can see it really grabs all of those topics together bringing IT security and operations together as well as strategy and compliance. The target operating model really connects different disciplines within your organization. As you can see on the left side we have in the center the target operating model as the steering wheel between the organizational structure, processes, technology, the people, governance and procurement and sourcing for example. So what does the target operating model really provide you?
It is a representation of how an organization intends to operate across the different functions and disciplines to achieve a long-term objective and as you can see here already it's not just having a current challenge which we want to fix it's more a long-term strategic decision to build up the target operating model for IT governance to establishing a well foundation for your organization. It defines the clear vision of the desired future and bridges the gap between the organization current state as well as the strategic goals of the organizations.
So as you can already see it really always comes together that you want to achieve a bridging between different functions, different disciplines or different objectives and really putting everything together that everything is not decoupled and very well integrated into each other and by defining a target operating model organization can align the operational activities which strategic intentions ensure that every function and process contributes to the achievement of overarching objectives. As some of you might know if you can write down a problem you already solve the problem to 50 percent.
So same comes for this if you are able to define a target operating model you have already done a lot of work in the course of a strategic well put foundation. Speaking a lot of the target operating model I want to highlight you a target operating model from our side where you have three different categories to put it that way. Integration into the company, IT, governance, management, operations.
So you have the horizontal bars which have a common idea and put together different capabilities on the same topic and then within those bars you have different capabilities by themselves which covering all of the IT governance and if you have a common scope and an overall scope of the IT governance and the target operating model does give you this one you have already a good view on what do you need to achieve and have a proper IT governance within your company. Of course this is a standardized version of the target operating model.
Maybe digging a little bit into the details here into the for example integration into the company you have the authorities which give you directives and corporate audit as a capability category as well as you have the different control functions for example the internal audit as well as the external audit which is on the right side but also you have the different stakeholders here internal as well as external interests. Having a little bit more focus on the IT governance management of course we must provide some specification and guidance to the company as the IT governance.
IT compliance and regulatory frameworks as one big specification capability where we really give paperwork to everyone and really highlight what needs to be done in a language everybody can understand. In the same direction is the processes and structure management where we can define processes and have a common structure established for the IT governance within the organization as well as well-established processes for IT governance.
Then we might have a little bit more exotic functions like governance framework communication with different stakeholders as well as IT risk management, business continuity management, security management and so on and so forth. Depending on your organization not everything needs to be done by IT governance themselves. Some smaller companies might not have an IT governance department others might have a special risk management department where the IT risk management is already done.
On the bottom we have the operations where we want to realize whatever we define and manage within the IT governance so we can see the implementation and technical integration is one part. Sometimes IT governance can do it themselves but mostly and they rely on those hands-on work highly on the business and units themselves. Documentation so as well deep detailed documentation procedures usually is done by them who run the process and those are usually business departments.
As well as provision of information and we cannot just have all information by ourselves we are relying on information from the different departments and those come to us as the IT governance department and then we can manage documentation and provisioning of information and there you can see the capability categories on the right side. We have surveillance, specification management, interaction with stakeholders and implementation. On the example of documentation and provision of information you can see it's the dark blue colored so management as the capability category.
So what does this mean? The documentation is not provided by the IT governance but it is managed by them. So we have a standardized format of documentation. We have a centralized folder where all the documentation is available to everyone who needs to be having access to this documentation and then we have a standardized version of the documentation for the processes. And there you can see it's a lot of standardization and having everything in one place so everybody can really see and get the information they need to have.
Talking a lot about standardization and harmonization, the right side of the operations the lowest horizontal bar we have template development which directly pays into the to develop all those templates by ourselves depending on do we have the capability and manpower to do so or can we have and manage it. So it really relies on manpower which we have and we will have in the future as well as analysis and evaluation monitoring. So that's the implementation.
We don't need to implement it but we need to have analysis and evaluation and monitoring capabilities to have the information at hand to be efficient and be compliant in the end. So this one was a very brief and quick run through the target operating model. I'm aware of this. There's a lot more detail to it but it would really extend this webinar to go too much into detail. I hope I covered a lot of it and to give you a brief glimpse of it.
If not, feel free to use the questions as I said earlier and then we might have a chance to really discuss it discuss about it in the end or else you can contact me in person and then we can discuss about the target operating model after the webinar. So this one so this one is yes so implementing and scaling governance building scalable structures rules and responsibilities step by step. So let's see how the IT governance integrates into organizational lines of defense. Depending on the organization as I already introduced a little bit the IT governance department is either not established yet.
It's somehow established depending on the organization and maybe we will see in the poll that there are different states of the IT governance. So one common model which you're probably most aware of are the three lines of defense model and where you have the first line of defense with the hands on the day-to-day business second line of defense where all the compliance risk management data protection is is located and the third line of defense internal audit external audit bodies.
So there we come again back to the first slide where we really can see between the first line of defense and the second line of defense sometimes there is a gap or a misunderstanding or just not speaking the right language and there we can introduce the IT governance as the one and a half line of defense and where we really use IT governance to translate strategic guidelines from the second line of defense into applicable standards processes and tools for the first line of defense. So we really are a mitigator and bridging tool between the second and the first line of defense. How can we do it?
We can do it with providing a central IT risk register templates and guidelines where we can put every information into and have it in a consolidated way in a central place where everybody who needs to have access again has access to it. We need to implement operational specialist controls, review of compliance with measures, business continuity management tests and so on and so forth and have central reporting to the second line and management. So what does this mean?
Having a central reporting to the second line does make life easier for the second line of defense because they know the sub and stages and they really are aware of what happens in the organization in the first line of defense and if you don't have standardized reportings and on a central place then people cannot understand it very easily and might be misinterpreted because there are different standards.
So having a central reporting, a standardized central reporting does make life easier for everybody because in the operation if you do have to fill out five different reports for the same issue then you have a lot of overload and if you have just one standardized format you can utilize the same format again and again and have a nice reporting in a standardized way which everybody can see and use very quickly. And then as well as the IT governance not only supporting the second line of defense providing feedback but also advising the first line of defense how to implement compliant solutions.
So it's really a two-way street advising the first line of defense as well as providing feedback to the second line of defense. Speaking of that we had now a brief view on different paths what can IT governance do in general and then I want to introduce you to the 12 areas which we identified for IT governance in general being important and can be done or covered by IT governance. So I'm not reading through all of those but as you can see IT risk management, compliance and regulatory requirements, security management, process and structure management.
We already covered a lot of those topics during this webinar already and we need to figure out for our specific company and organization which requirements and which areas of responsibility we need to be covering or which need to be covered by the IT governance. So it's not a universal concept which you can apply to your own company and say ah well let's take those 12 bullets implement them and then we are good to go.
No it's really high effort but it is worth to spend this effort to have a proper requirement analysis helping the organization to define the specific IT governance responsibilities and engaging all the required stakeholders through interviews or different communication channels depending on your organizational culture.
Involving the stakeholders to have the same course and be on board in the right direction to establish shared understanding of relevant governance areas and then you really can put it together and say okay for the IT governance we select a few of those 12 topics and go into the details and work those out and set up a proper foundation for our specific needs in our company for the IT governance. Speaking a lot of those 12 different areas I want to ask you in the second poll which of those 12 different areas do you attach to IT governance? So in your company what does IT governance do?
Does it only do the IT compliance and regulatory requirements 2.5 or is IT governance a lot more and does the IT performance management and so on and so forth. So I really encourage you click all of those 12 which really are covered by IT governance within your company. If you don't have IT governance at all in your company or you're just building it up you don't need to click whatever you want just leave this poll out and then we can discuss in the end which might be interesting for you to have as a focus point and to start with for IT governance.
Take your time with those polls I think those will be open for the rest of the webinar so you can take your time and select whatever occurs and applies to you. So defining the core governance area step by step as I already introduced you to the 12 core areas we really want to make sure that we have the right strategy the right core areas defined and selected for the next phases and building up a proper baseline for the IT governance. How can we do this? As I already introduced you to the interviews as one possible version to gather perspectives from your stakeholders.
To do the interviews it's very critical to have the right stakeholders at hand so you need to do proper stakeholder analysis then you can gather the right perspectives and examine where governance functionality actually creates added value and not just what you would think would help you in the long run but really addresses real pain points in the company. As a next step we want to start with an MVP. What does it mean?
We don't, as I already stated, we don't want to cover the whole cake in the beginning.
We want to take it piece by piece and have a reduced but functional set of governance areas identified for ourselves so we can take two to three maybe four to five really depends on your company and in the end on your stakeholder analysis and on the budget you have and then we want to dig into it and as a starting combination for example I put you together the IT risk management for measurable risk control and early success monitoring compliance and regulatory alignment IT security management and communication and stakeholder management for example so it's really up to your business how you identify your MVP and then after you successfully rule out your MVP and have the right requirements you gradually add further control areas so it's as I already stated in the beginning it's not just by a solution and then you are set for life no it's starting now and then building up on it so you have really the goal of a sustainable scaling of the governance structure without excessive complexity and then if you build it up from a simple MVP and building it up you don't have this big complexity where you want to cover everything in the beginning and end up in a mess because it was too complex in the end so as a key takeaway instead of addressing all governance issues at once we use interviews and analysis to identify the most important core areas and start with a focused MVP ensuring the impact acceptance and scalability from the start so having now a core set clear roles and responsibilities are essential to make governance work so whatever plan you have it doesn't help you if you cannot really transport it into the company and this transport it into the organization.
Rusky model for more detail so as I let me just go back again so key roles and responsibilities are essential to make governance work how can we identify key roles and responsibilities usually we come up with the Iraqi matrix and this one works very well what we figured out in our last project if you you really need to have proper support in IT governance and the proper support comes in the Iraqi matrix usually with the consultant but people tend to if you're just put as consulted and then everybody needs to ask me otherwise I don't provide any information and if you do it over the responsible as a support function and you have a lot of person in Iraqi matrix which doesn't work out as well so we came up to use the more enhanced Rusky model to provide a little bit more detail and have this extra supportive function there and where we state okay supportive function means actively supporting implementation providing resources expertise operation operational assistance but does not have primary responsibility so we can really stay in the model and say okay we have one accountable person or institution one responsible person once and then a lot of supportive consulted and informed stakeholders so this one gets really more detail and clear distinction between the operational execution and supportive activities as I already stated increasing transparency and highlight and reducing complex structures by writing them down and providing everybody the same information and since you cannot really just throw a Rusky matrix into the organization you are already forced to talk with the different stakeholders to align on the Rusky matrix and this is already half of the rent providing or having this discussions about who is responsible who supports and who's accountable and so on and so forth so we have not only the discussions and setting the responsible persons and the supportive functions we improve traceability in governance and audit and through such a risky matrix because everybody is aware what needs to be done when and where and how so this one gives really the foundation for more precise role profiles and resource planning and strengthening as I already said the cross development department collaboration since you really need to discuss and ask who can work together on a specific task and how can we achieve a proper result for this one just to stress the topic a little bit more we need a clear role separation and clear accountability as I already stated having seen a lot of Rusky matrices where a lot of accountability and responsible stakeholders were mentioned within one task it really blows my mind and such a thing doesn't help anyone really to achieve this task because then finger pointing starts and nobody really feels responsible for anything so therefore we should really split it up and have it governance responsible in a sense of structure and methodical responsibility for the entire governance framework defining specification control guides reviews and so on and so forth and being responsible for their eligibility and controllability it governance then is responsible for implementing the target operating model in regulated it structures so it governance really holds the responsibility of the target operating model while business units function as the supporting stakeholders and instances in the sense of to the content by providing the necessary information so providing reports providing detailed process descriptions so it cannot be that the IT governance writes the process description of a very detailed process because they never work with it but the man or the woman who works with it day to day really can highlight all the details of this process so therefore the business units need to get involved and provide their knowledge to IT governance and IT governance being the managing instance above it and helping to have it consolidated so the business unit is responsible for keeping information up to date and are required to cooperate in internal and external audits so ensuring the practical applicability of governance requirement through feedback and technical expertise as I already stated so knowledge comes from the business units and IT governance provides the framework and the structure where everything can be put in a central place from what to who we already spoke about 12 core tasks of IT governance if we select the core areas the 12 core areas we have a lot of different tasks in those areas and those core tasks can be divided into two task categories in terms of activities to be performed on the one side where a lot of design thinking is needed and then on the other side where the execution comes really into place so the hands-on mentality therefore you will have two different types of profiles automatically we call the one lead or architect where we have high demands on creative work and independent work where all the designs are done and created and then on the other side we have an analyst or coordinator depending on job level so that's not that important but the important thing here is that those are focusing on an efficient and goal-oriented work what do we do with this split of course one we have the design and one we have the execution and if we split them in this regards apart we can create job profiles which can be combined in two different positions or job postings and therefore we really reduce the complexity from the core tasks in what needs to be done we need a little bit of design and a lot of execution and then scaling it up we really come close together to what we really need in terms of job profile and what kind of job postings do we need to publish so using profiles enables us to easy scalability and allow specific bottlenecks and key tasks to be affected effectively addressed so again here reducing complexity through writing down the problem again how do we build a scalable it governance well let's put it in three phases to keep it simple here again we have the phase one development of the it of the it governance as i already said create the MVP have it created and established a sustainable governance framework we need to consolidate system requirements from guidelines and transfer to documentation schemes as well as recording of all applications and prioritization in terms of criticality and business relevance and there you can see again we go on business relevance and criticality to prioritize what needs to be done in the first phase in the second phase we want to scale up of course and we want to bring idea of governance into operations so we select and implement suitable tools define processes and responsibilities and really get into going so this doesn't need to be done just by internal resources we can use external resources to really scale up and shorten this duration of the second phase and really highlight and bring or come up to speed of course utilizing external resources always helps for documentation purposes for example it is a lot of effort to have proper documentation but i cannot stress it enough proper documentation does help in the long run and in phase three we have operation so now we are scaled up we have everything operationalized and now we went we go to our operations so we want to transition the whole it governance into an established organization wide governance model we want to be aligned with the business strategy and the risk appetite and we want to be embedded in terms of accountability and transparency in the organizational routines therefore we introduce continuous improvement mechanisms and maturity assessments to keep being up to date and don't implement something and let it die in the long run we want to be on the pulse of time and being up to date the whole time so we can institutionalize governance as driver for performance and trust trying to give it a wrap and i spoke a lot about it governance now and i tried and i hope you are still bearing with me but it governance at a glance um it governance the strategic anchor in your organization in your organization as the one and a half line of defense um how can we you have achieved this as i already said using rasci matrix to document interfaces and clarify shared responsibilities so you really establish the first one and a half line of defense and then use the rasci model to really document the things you agreed on and then you can work with those second identify core tasks provide clarity about areas of control and responsibility review role clarity at least annually to prevent overlaps as organization evolves again here don't set something up and don't touch it ever again you need to be up to to really prevent those dying documents which doesn't help anyone third core tasks combine regulatory and operational requirements we want to establish a control library as i said document in a central repository that everything is coming together and mapping on the one side regulatory controls and on the other side having the operation procedures and kpa eyes in place for the interface with it strategy is critical to its success and must be coordinated so introduce a regular strategy to governance between cio czo and governance lead to really be on touch with the strategy and be aligned with the it strategy so you have the same course not only in the operation and security but also governance and it strategy and as the last point the model enhances transparency efficiency and implementation capability so visualize key governance indicator risk status compliance coverage and so on and so forth to control maturity in a single reporting tool so again as you can see it it comes together having something on a central place which can be understood by everybody and can be utilized by everybody so everybody really can benefit from it so to give it a wrap this is where it governance turns structure into impact and the effective governance is more than just compliance it's the foundation for clarity accountability and sustainable it performance so let's shape a governance model that fits your organization and makes control the driver of success and not just being something which flies around your organization and nobody pays attention to just giving it a wrap and bringing me to the q a session so i hope everybody is still bearing with and maybe we can have a look at the polls so let me double check so we can really dig into it so let's see let's let's start with the overall areas of it governance and with a whopping 60 16 percent it business continuity management is part of the it governance function in your organization so those of you who have it governance and it business continuity management does pay a lot of focus in it governance which is not that surprising but still it's a very nice point a little bit surprising for me but maybe it's just on the on the wording a communication and stakeholder management has zero votes to itself so i'm not sure maybe it's just misunderstanding but hopefully nobody of you is just doing its it governance by themselves and not communicating it to the stakeholders and the question also which occurs to me is how do you raise your requirements if you have no proper communication to your stakeholders and a proper management of it but i'm sure this one is more of a misunderstanding of this point but if not i would be very interested in discussing this point with you face to face so if you are interested in having such a discussion reach out to me and then we can can have very nice discussion on this one same counts of course for each and every area of it governance so having the other poll have you ever already established an it governance organization within your company at least no one does not have it planned yet even though it would be required so that's a good point surprisingly that is that there is for some no requirement to establish an it governance organization again here i would love to discuss this one i assume the functions might be covered in a different department but nonetheless i assume the area would be covered at least no but implementation is planned okay that's nice just make sure that you have proper planning and the right stakeholders identified so then there is nothing which which hinders a proper it governance organization within your company and then we have a lot of yeses that there is already one established as well as there is already the implementation started so that's great of course so then we have some questions at least in in the chat so i think we have a little bit of time to at least address a few of those let's start with what does it take to successfully implement it governance as the one and a half line of defense so that's that's quite an interesting question um let me skip this one um so implementing it governance as the one and a half line of defense require more than just documentation but as i already stated documentation is one part of it um but it's really about connections so the one and a half line of defense links the oversight and directly into a daily process so the success depends highly on defined functions um and defined ownership for transparent reporting and structural framework so um this really allows governance to add value without slowing down the delivery so if you have set up a proper baseline you really can benefit from a higher effort in the beginning and utilize the higher effort and a proper baseline to scale in the end and being very performant i hope this one answers your question and then maybe the last question before we wrap this one up how do you decide which governance area to prioritize first so um this one again um as i already stated the governance prioritization should start small as i said the mvp so focus on the high are high focus and critical areas with a high impact for you uh this could be it risk management and compliance alignment um which are more or less probably the best entry points because they provide quick visibility and measurable outcomes and once these are stable organization can in really expand through structural and performance governance and the principle is start with what measures most and scale what works as always so um i hope um we have another question um how would you compare the it governance practice to center of excellence it is kind of alliance with the coe objective with maybe the exception of reporting lines uh i i would assume that this might or could be a little bit more on the terminology side um so as a center of excellence um it might be a little too much on the institution which is just asked uh and not too much of an initiative advisory function with it i hope i i understood your question correctly otherwise you can always ask again or ask me directly after the webinar and so i would assume that the feedback culture with an center of excellence might be a little bit less um which you already stated with the exception of reporting lines so um it really depends in the end on your company how you set up your center of excellence as well as how do you set up the it governance organization in the end so um you really it doesn't really matter who actually does the it governance more it matters that the areas of it governance are somehow or and somewhere covered within your organization so if you do it with the center of expertise and excellence then that's that's no problem at all and you just need to make sure that the it governance capabilities are really covered in the end and then you can achieve this one with a simple raski matrix for example and then the center of excellence would be as a responsible institution for different capabilities and tasks and um those would receive the support the necessary support from the uh from the business if necessary so i hope i covered your question so far um else just feel free to reach out to me again and then we can discuss it a little bit more um else i would say it's already close to five o'clock um and i would like um to give this one um a wrap um just let me highlight the eic next year as well as on november 6th the identity centric cyber security impact day which would be very interesting because a lot of people will talk about it governance on the impact day in november so um just make sure that you will uh come there and then i am pretty sure you will have a lot of fruitful discussions um on the impact day on security but as well as on it governance so thanks for all of you who stayed with me until the end if you have any questions please feel free to reach out to me and i'm happy to discuss further on the it governance topic with all of you thanks for joining today's webinar and take care and enjoy the rest of your day
See All Locations
See All Locations