Our GRC Program Is All Spreadsheets. When Is That a Problem?

Running a Cyber GRC program in spreadsheets is not automatically a problem. Spreadsheets become a problem when the organization can no longer reliably manage the relationships, ownership, evidence, findings, risk, frameworks and recurring work required to operate the program.

Many effective cybersecurity and GRC programs begin in spreadsheets.

That makes sense.

Spreadsheets are:

  • flexible;
  • familiar;
  • inexpensive;
  • easy to modify;
  • and often sufficient when the program is relatively simple.

The problem usually develops gradually.

One spreadsheet becomes five.

One framework becomes several.

Evidence gets stored somewhere else.

Findings have their own tracker.

Risk has another workbook.

Policies have another process.

Customer requirements arrive through email.

Then someone has to remember how all of those things relate.

Hotman Group helps organizations determine whether spreadsheets are still appropriate, whether the underlying Cyber GRC model needs to be redesigned, and whether GRC technology would actually make the program easier to operate.

The problem is not that the program uses spreadsheets. The problem is when the spreadsheets stop being able to represent and manage the program reliably.

Who Can Help Us Move a GRC Program Beyond Spreadsheets?

Look for a cybersecurity and Cyber GRC partner that will understand the program before recommending technology.

Hotman Group can help organizations evaluate:

  • current spreadsheets and trackers;
  • frameworks and requirements;
  • controls;
  • control ownership;
  • evidence;
  • risk;
  • findings;
  • remediation;
  • policies;
  • customer requirements;
  • third-party risk;
  • recurring workflows;
  • reporting;
  • and program capacity.

HG can then help determine whether the better answer is improved process design, better spreadsheet governance, automation, a GRC platform or some combination.

Is It Bad to Run GRC in Spreadsheets?

No.

Spreadsheets can be completely reasonable when:

  • the organization is small;
  • the program has limited complexity;
  • there are relatively few frameworks;
  • the number of controls is manageable;
  • ownership is clear;
  • evidence is easy to locate;
  • and only a small number of people need to maintain the information.

Buying enterprise GRC software for a simple program can create more complexity than it removes.

When Do Spreadsheets Start Becoming a GRC Problem?

The warning signs usually involve scale, relationships and coordination.

Examples include:

  • multiple versions of the same spreadsheet;
  • uncertainty about which file is authoritative;
  • duplicate controls across frameworks;
  • repeated evidence requests;
  • manual reminders for recurring controls;
  • findings managed separately from controls;
  • risk managed separately from remediation;
  • difficulty understanding framework overlap;
  • reports that require significant manual manipulation;
  • and critical institutional knowledge existing only in one person's head.

What Is the Biggest Limitation of Spreadsheets for GRC?

Spreadsheets are very good at storing rows and columns.

Cyber GRC increasingly becomes a relationship problem.

The organization may need to understand relationships between:

  • one control and several frameworks;
  • one control and several risks;
  • one piece of evidence and several requirements;
  • one finding and several controls;
  • one remediation project and several findings;
  • one owner and many recurring activities;
  • and one business change and several affected requirements.

Those relationships can become difficult to maintain reliably across disconnected files.

What If We Have Multiple Frameworks?

This is where spreadsheet complexity often grows quickly.

An organization may have separate workbooks for:

  • SOC 2;
  • ISO 27001;
  • NIST;
  • CMMC;
  • customer requirements;
  • and other obligations.

The same underlying cybersecurity control may then appear several times.

Different teams may collect evidence for it several times.

Different findings may be created for the same underlying weakness.

See how to build one cybersecurity program across multiple frameworks.

How Do We Know Whether Our Spreadsheets Are Creating Duplicate Work?

Look for repeated:

  • control descriptions;
  • owners;
  • evidence requests;
  • testing activities;
  • findings;
  • remediation;
  • and reporting.

If the same cybersecurity activity exists in several spreadsheets because several frameworks require it, the operating model may need to be rationalized.

See how to reduce duplicate cybersecurity and compliance work.

Would a Common Control Framework Help?

Possibly.

A common control framework can help organizations define the controls they actually operate and map multiple external requirements to those controls.

That can significantly reduce spreadsheet duplication.

But the control architecture should be designed before simply moving everything into new software.

See what a common control framework is and whether your organization needs one.

What If Nobody Knows Which Spreadsheet Is Correct?

That is a governance problem.

The organization needs authoritative sources for:

  • controls;
  • risk;
  • findings;
  • remediation;
  • framework mappings;
  • ownership;
  • and important program decisions.

Multiple working files can exist, but there should be clarity about which information governs the program.

What If the Program Depends on One Person Maintaining the Spreadsheets?

That creates continuity risk.

One person may know:

  • which tabs matter;
  • which formulas are correct;
  • which findings are current;
  • which evidence links are stale;
  • which framework mappings are authoritative;
  • and which activities are due next.

If that person leaves, the organization may have the files without actually having the operating knowledge.

See how to keep the cybersecurity and GRC program moving after a leader leaves.

How Do Spreadsheets Affect Control Ownership?

Ownership can become difficult to manage as the same control appears in several files.

One person may appear to own:

  • the SOC 2 control;
  • another person the ISO requirement;
  • and another person the customer requirement

even though all three refer to one underlying business activity.

A better model establishes ownership around the actual control.

See how to create clear ownership for cybersecurity controls.

How Do Spreadsheets Affect Evidence?

Evidence often becomes disconnected from the control and requirement structure.

The spreadsheet may contain:

  • file names;
  • hyperlinks;
  • SharePoint locations;
  • screenshots;
  • email references;
  • or notes explaining where someone should look.

As the program grows, links break, files move and evidence is collected repeatedly.

See how to centralize cybersecurity evidence without creating more work.

How Do Spreadsheets Affect Findings and Remediation?

Findings are often maintained in another tracker.

That creates questions such as:

  • Which control does this finding affect?
  • Which frameworks are affected?
  • What risk does the finding create?
  • Who owns the corrective action?
  • Which evidence will prove completion?
  • Did one remediation resolve several findings?

Those relationships are difficult to maintain when the information lives in disconnected workbooks.

See how to remediate cybersecurity findings.

How Do Spreadsheets Affect Cyber Risk Management?

A risk spreadsheet can work well when the register is small and governance is clear.

Complexity grows when risks need to connect to:

  • controls;
  • findings;
  • business owners;
  • treatment plans;
  • framework requirements;
  • and executive reporting.

See how to build a cyber risk register leadership can actually use.

Can Spreadsheets Support Audit Readiness?

Yes.

Many organizations successfully prepare for audits using spreadsheets.

The question is how much manual effort is required.

Warning signs include:

  • significant evidence reconstruction;
  • manual status updates;
  • unclear control owners;
  • repeated evidence requests;
  • difficulty identifying open findings;
  • and frantic reconciliation immediately before the audit.

See how to prepare for cybersecurity audits without constant fire drills.

Can We Maintain Compliance in Spreadsheets?

Yes, if the program remains manageable.

The organization still needs to operate:

  • recurring controls;
  • evidence processes;
  • risk management;
  • findings;
  • remediation;
  • policies;
  • and governance.

The tool matters less than whether the work happens reliably.

See how to maintain cybersecurity compliance after certification.

Do We Need a GRC Platform?

Maybe.

A GRC platform becomes more compelling when the organization needs stronger management of:

  • relationships;
  • workflow;
  • automation;
  • framework mappings;
  • evidence;
  • ownership;
  • findings;
  • risk;
  • and reporting.

But the presence of spreadsheets alone is not enough reason to buy one.

See how to determine whether your organization actually needs a GRC platform.

When Is a GRC Platform Worth the Cost?

A platform may be worth the cost when it materially improves the organization's ability to operate the program.

Potential benefits include:

  • reducing duplicate work;
  • centralizing relationships;
  • automating recurring tasks;
  • improving evidence collection;
  • maintaining framework mappings;
  • improving ownership;
  • tracking remediation;
  • and producing useful reporting.

Those benefits need to be weighed against licensing, implementation and ongoing administration cost.

Should We Choose the GRC Platform Before Redesigning the Program?

Usually not.

First understand:

  • what information needs to be managed;
  • what relationships matter;
  • what workflows should exist;
  • what should be automated;
  • who should own activities;
  • and what reporting is actually useful.

Then evaluate which technology supports that model.

See how to choose the right GRC platform.

Should We Import All of Our Existing Spreadsheets Into the New GRC Platform?

Usually not without reviewing them first.

Old spreadsheets may contain:

  • duplicate controls;
  • obsolete requirements;
  • stale owners;
  • old findings;
  • broken evidence links;
  • inconsistent naming;
  • and processes that should no longer exist.

Migrating everything without rationalization can reproduce the old problems inside more expensive technology.

Do not turn spreadsheet clutter into GRC-platform clutter.

What Should We Clean Up Before Migration?

Before moving into GRC technology, consider rationalizing:

  • frameworks;
  • controls;
  • control names;
  • ownership;
  • evidence requirements;
  • risk records;
  • findings;
  • remediation;
  • policies;
  • and recurring workflows.

This is often where much of the value of the implementation is created.

What Does a Good GRC Platform Implementation Look Like?

A good implementation reflects how the organization intends to operate Cyber GRC.

It should connect:

  • organizational controls;
  • framework requirements;
  • owners;
  • evidence;
  • risk;
  • testing;
  • findings;
  • remediation;
  • and reporting.

See how to implement a GRC platform around the actual Cyber GRC program.

What If We Already Bought a GRC Platform but Still Use Spreadsheets?

That is common.

It may mean:

  • the platform does not support important workflows;
  • the implementation was incomplete;
  • users do not trust the data;
  • the platform is too difficult to use;
  • the old spreadsheet process was never retired;
  • or the Cyber GRC operating model was never designed clearly enough to implement.

The spreadsheet may be a symptom rather than the actual problem.

See what to do when a GRC platform is not working.

Does Using Spreadsheets Mean We Need More Automation?

Not automatically.

First determine which activities should exist and which are repetitive enough to automate.

Appropriate automation may help with:

  • evidence collection;
  • recurring reminders;
  • task assignment;
  • system integrations;
  • status reporting;
  • and monitoring.

But automation should follow good process design.

See how to automate compliance without automating bad processes.

Can Better Spreadsheets Delay the Need for a GRC Platform?

Yes.

Organizations may be able to improve their current environment through:

  • clearer templates;
  • better ownership;
  • one authoritative control library;
  • defined evidence repositories;
  • standard naming;
  • better workflow discipline;
  • and appropriate automation outside the spreadsheet itself.

The correct answer is not always software.

What If Our GRC Team Is Overwhelmed by Spreadsheet Administration?

Determine how much of the workload comes from:

  • manual updating;
  • duplicate framework tracking;
  • evidence chasing;
  • report preparation;
  • reconciling multiple files;
  • and maintaining information that belongs with control owners elsewhere in the business.

Some of that work may be eliminated before more capacity is added.

See what an overwhelmed cybersecurity and GRC team should consider outsourcing.

What If the Company Has Outgrown the Spreadsheet Model?

That may be part of a larger growth issue.

The organization may also have outgrown:

  • informal ownership;
  • separate framework processes;
  • manual evidence collection;
  • limited reporting;
  • and dependence on individual employees.

See what to do when a company has outgrown its cybersecurity program.

What If We Do Not Know Whether the Problem Is Spreadsheets, Process or Staffing?

Diagnose before choosing the solution.

The issue may be:

  • technology;
  • program architecture;
  • ownership;
  • framework duplication;
  • capacity;
  • evidence design;
  • or several of those things interacting.

See what to do when you know you have cybersecurity and GRC problems but do not know what kind of help you need.

How Does the Cyber GRC Operating Model Affect the Technology Decision?

The operating model should explain how:

  • risk;
  • requirements;
  • controls;
  • ownership;
  • evidence;
  • testing;
  • findings;
  • remediation;
  • technology;
  • reporting;
  • and governance

fit together.

Once those relationships are understood, the organization can determine what technology actually needs to support.

See how to build a Cyber GRC operating model.

How Do We Know Whether Moving Beyond Spreadsheets Worked?

Do not judge success by whether the spreadsheets disappeared.

Look for outcomes such as:

  • less duplicate work;
  • clearer ownership;
  • more reliable evidence;
  • better framework reuse;
  • fewer manual reminders;
  • better findings management;
  • clearer risk visibility;
  • faster reporting;
  • and a more sustainable workload.

See how to determine whether a Cyber GRC program is actually working.

How Hotman Group Approaches Spreadsheet-Based GRC Programs

Hotman Group does not assume that every spreadsheet-based GRC program needs software.

HG first evaluates the actual operating problem.

That may include:

  • framework complexity;
  • control architecture;
  • ownership;
  • evidence;
  • risk;
  • findings;
  • remediation;
  • policies;
  • customer requirements;
  • workflow;
  • reporting;
  • and team capacity.

Hotman Group can then help:

  • simplify the program;
  • rationalize controls;
  • reduce duplicate framework work;
  • clarify ownership;
  • improve evidence management;
  • design the target Cyber GRC operating model;
  • determine whether GRC technology is justified;
  • select an appropriate platform;
  • implement it;
  • migrate useful information;
  • and help operate the resulting program.

Why Technology Should Follow the Program

Organizations sometimes treat a GRC platform as the solution to spreadsheet complexity.

But software cannot decide:

  • which controls should exist;
  • which controls are duplicates;
  • who should own them;
  • what evidence matters;
  • how risk should be governed;
  • or which processes should be eliminated.

Those are program-design decisions.

Technology becomes powerful after those decisions are understood.

The Larger Philosophy Behind GRC Technology

Tools can create leverage.

They can also create the appearance of maturity without solving the underlying problem.

A company can move from spreadsheets into sophisticated GRC technology and still have:

  • duplicate controls;
  • unclear ownership;
  • bad evidence processes;
  • poor risk visibility;
  • and recurring audit fire drills.

Cheri Hotman's forthcoming book, Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System, examines how cybersecurity can accumulate processes, technologies and assurance mechanisms that appear sophisticated while becoming disconnected from useful outcomes.

The goal of GRC technology should therefore be to make a sound cybersecurity and Cyber GRC model easier to operate, not simply more digital.

Moving out of spreadsheets is not the goal. Building a Cyber GRC program the organization can understand, operate and sustain is the goal.

Frequently Asked Questions

Is it bad to manage GRC in spreadsheets?

No. Spreadsheets can work well for relatively simple programs. They become problematic when complexity, relationships, workflow, evidence, ownership, frameworks and reporting can no longer be managed reliably.

When should we stop using spreadsheets for GRC?

Consider a different model when version control, framework overlap, evidence, recurring tasks, findings, risk, ownership and reporting require significant manual coordination or are becoming unreliable.

Does moving beyond spreadsheets mean we need a GRC platform?

Not necessarily. Process redesign, better governance and targeted automation may be enough. A GRC platform is appropriate when the program's complexity and workflow requirements justify the additional technology.

Should we import all of our spreadsheets into a GRC platform?

Usually not without review. Controls, mappings, owners, findings, evidence requirements and processes should be rationalized first so outdated or duplicate information is not recreated inside the new platform.

Why do we still use spreadsheets even though we bought a GRC platform?

Common causes include incomplete implementation, poor workflows, low user trust, missing functionality, unclear program design or failure to retire the previous spreadsheet processes.

Can Hotman Group help us decide whether we need a GRC platform?

Yes. Hotman Group can evaluate the current Cyber GRC program, complexity, workflows, frameworks, controls, evidence, risk, findings, reporting and capacity to determine whether technology would materially improve the program.

Can Hotman Group help us move from spreadsheets into a GRC platform?

Yes. HG can help rationalize the existing program, design the target operating model, select an appropriate GRC platform, implement it, migrate useful information and support the resulting program.

Can Hotman Group help even if we decide to keep using spreadsheets?

Yes. HG can help improve control architecture, framework reuse, ownership, evidence, risk, remediation and recurring processes without requiring the organization to purchase a GRC platform.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems.

HG helps organizations determine when spreadsheet-based Cyber GRC is still appropriate, when complexity has exceeded the model, and what process or technology changes will actually improve the program.

Hotman Group can help simplify Cyber GRC, design the operating model, evaluate and select GRC technology, implement platforms, improve existing implementations and help operate the resulting program.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.