Are You Ready For A Cloud Security Officer?

Analysis
Oct 19, 20123 mins

TraceCSO wants to bring GRC downmarket.

GRC has always been a solution for big companies. Governance, Risk and Compliance pulls together lots of disparate data and seeks to give a broader picture of an organization’s Risk posture, where it stands on compliance with various rules and regulations and its own thresholds for security. The problem is putting all of that together is a big job that only a big company could handle. Now TraceCSO wants to bring GRC to the mid-market.

TraceCSO is a cloud-delivered GRC-as-a-Service solution, if you will. Its solution covers all aspects of GRC, including Risk, Vulnerability, Compliance, Training, Policies and Audit controls. What’s more is Trace’s solution comes with Trace’s own expertise and services included. It is meant to be a standalone solution that does not require any additional third- party solutions. It even has its own vulnerability scanning engine built in.

Let’s be clear though, GRC is still a big bite to chew. While Trace seems to have the pieces all there, they still have some dots to connect. That is what I found out speaking to my friend Lori MacVittie of F5 Networks, who blogged about it. Lori was very impressed that for a new product TraceCSO had so many pieces of the GRC puzzle in place. She felt it bore watching going forward to see if it all came together.

Another question is, does the mid-market really need GRC? There are those who say no. There are others that say of course they do. Mid-market companies are subject to many of the same compliance rules and regulations as larger companies. They also want better insight into their risk, vulnerabilities and policies. The question is whether they have the resources and staff to make use of it. Even taking Trace at their word that their product makes it really easy and that they will help their customers understand it, for many mid-markets the question is then what. It may very well be that GRC is a big company solution for a reason.

I spoke with the folks at Trace Security and they have done a lot of research on the market. They think at the price point they have established (starting at about 5k) it is a great fit for the mid-market. They acknowledge that as a service they will be adding rapid additions and improvements over time, but what they have right now they believe is more than enough for most mid-market companies to fulfill their GRC needs.

I question them on having their own scanning engine. In my experience, most organizations already have a vulnerability scanning solution. Trace is working on building importers for most of the leading engines so that organizations will be able to leverage their previous investments in vulnerability and pen-testing solutions.

All in all, I am in the same boat as my friend Lori. I think Trace Security has done a good job with TraceCSO. The mid-market has nothing like it today. It will be interesting to see how it continues to expand and fill in some of the white space that is still there.