WELCOME !  

                                                                                                                                 

VisionGroup Consulting is an Association of consultants, auditors and partners that provide Advisory Services in Governance, Risk Management, Compliance and CyberSecurity Governance.

VisionGroup Governance is a business unit with focus to offer advisory services in CyberSecurity Governance thru of governance culture (Enterprise Security Risk Management - ESRM) in continuous steps to promote and build priority in the board members agenda to take more control of the business rules, competences, responsibilities - RACI , legal requirements and in the same time wake up top managers for motivation in the organization to prioritize GRC best practices. And that will start and set Risk Management activities in the company agenda to arouse interest a regular behaviour in Compliance and Security.

In this way we expect that a long term GRC program could be prioritize more goals to achieve more and more trust in the management processes in the company for the high competitive market share challenge to face their business goal. This is the mainly mission of GRC, i.e, plan, build scenarios, development and control a business opportunities with performance and in a safe business environment. That will assure more control about frauds, local / global legal requirement, information security, third parties risk, digital challenge, business risk and others internal procedures for business continuity.

This Governance unit has established challenges and target to achieve their business goals and in this way efforts will focused in convince the companhy board member and shareholders, to invest in do business philosophy of continual improvement that is waves and steps of the a long term planning aiming obtain effectual business results thru best pratices of GRC, that will in the same time assure their information actives and will preserve their business reputation.

We believe that CyberSecurity processes will produce best result after had invested efforts to achieve a Governance environment that prioritize their culture in Risk Management, Information Security, Internal Control, Internal Audit and Compliance.

There is not easy, simple way or magic touch to do, if the company choose long term this will require continuos improvement of the management systems, setting goals for GRC integration and dedicate more time of the board of directors to the company culture gaps and keep your mind and eyes to assure company aims. There are some FCS like behaviours, internal controls, metrics, credibility, directors commited are crucial to became natural behaviour with a new situation that means adjust planning frequently for the GRC goals and expectations, Management, Information Security and Compliance.

Remember that there is an element crucial that is DNA and natural attitudes in all corporate structure to produce results, in the other way some funcional areas will run more than others and will find much more obstacles without assure that will achieve the same result. Now, think about the new challenger Security aims without define scope and scenario for new world with Digital demands, social media worries, third parties ...

Before approve a purchase request that you believe that will solve a problem and their expectation also, remember that there are not easy way and even if the company select the best technological solution their problems and demands will not disappear. There are many companies that approve complex procedures for procurement management, marketing, cybersecurity and etc, skipping many steps to discuss and to define which will be adherent for the risk tolerance scenario. The Board and Top managers must be sure of the real demand or even if this will conflict with others initiative, and evenwithout be sure that the organizational culture will support business risk and if is the right moment to adopt this solution.

ENTERPRISE SECURITY RISK MANAGEMENT (ESRM) uses risk-management principles to manage security-related risks across an  enterprise.

The Goals of ESRM are to establish organizational policies, procedures, best  practices, and capabilities to identify and manage security risks to the enterprise in an effective, consistent, and efficient manner.

 

Finding ways to encourage a Governance, RIisk Management and Compliance  culture !

Silvio R. Pereira

CyberSecurity Governance Dir.

CRISC CRA CRC