The lack of a formal corporate risk program continues to be a major challenge to cyber GRC.
A 2021 McKinsey survey of 100 organizations across industries found that a mere 10% aimed at reducing cyber risk. Almost 70% tackled cyber security challenges by filling security gaps as and when it was needed.