Michael Rasmussen — GRC Analyst & Pundit at GRC 20/20 Research, LLC
GRC Analyst & Pundit at GRC 20/20 Research, LLC
Michael Rasmussen ranks #566 of 18,799 LinkedIn creators in Market Research, and is a standout voice in United States. They have 37.4K followers and published 49 posts in the last 60 days at a 0.0% average engagement rate.
- 37.4K followers
- 49 posts / 60d
- 0.0% avg engagement
- — follower growth / 30d
The roast
Michael claims he coined the term GRC twenty-three years ago, which explains why his engagement rate is currently trapped in the early 2000s. He’s spent two decades defining the industry just so he can be the only person watching it die at a rate of 0.04 percent.
About Michael
If you ask my family what I do for a living, they might say that I “travel the world talking about risk.” And honestly, that wouldn’t be far from the truth. But the more formal introduction is that I am an analyst, researcher, storyteller, and, as the industry likes to remind me, the Father of GRC. More than 23 years ago, while at Forrester Research, I coined the acronym GRC and articulated it as a way to integrate governance, risk management, and compliance capabilities in strategy, process, and technology. Today, through GRC 20/20 Research, I spend my days studying how organizations around the world navigate complexity and uncertainty. My job is to observe patterns, identify challenges, understand how strategy, process, and technology intersect, and help organizations evolve to be more effective, efficient, resilient, and agile. Along the way, I also founded GRC Report, a global news and insights platform focused entirely on governance, risk management, compliance, and business integrity news and insights around the world. It has become a place where practitioners, executives, policymakers, and technologists can see the GRC landscape through a global lens. I also host two podcasts — Risk Is Our Business Podcast and Hitchhiker’s Guide to the GRC Technology Galaxy Podcast — because I believe conversation is one of the most powerful tools we have for changing how people think about risk and integrity. These podcasts allow me to explore big ideas with remarkable minds from around the world, and they keep me grounded in the reality that risk is not merely a function — it is the fabric of every decision and every ambition.In many ways, I am an explorer of uncertainty. As an industry analyst, I map and monitor the ever-expanding GRC galaxy — now tracking over 1,500 solutions and the professional services orbiting them. The universe of GRC is vast, dynamic, and constantly in motion, and I am endlessly fascinated by how organizations chart their course through it.
Highlights
- Consistent Creator — 49 posts in 30d · top 5%
- Big Audience — 37,424 followers · top 5%
- Top 5% in United States — Ranked #249 of 6073 creators
- Top 10% in Market Research — Ranked #3 of 34 creators
Recent posts
🤖 Agentic AI has officially left the novelty phase . . . The question is no longer whether AI can summarize a policy, draft an assessment, or save someone a few hours . . . The real question is whether we are prepared to redesign GRC around what AI now makes possible . . . On August 12, I am joining Pat McParland of MetricStream for a live discussion: 🚀 Agentic AI in GRC: From Novelty to Strategic Business Advantage We will explore how agentic AI moves GRC: 🧩 From fragmented tools to orchestrated intelligence 📡 From periodic assessments to continuous sensing 🔭 From reactive reporting to
2 reactions · 1 comments · 0 reposts
🎮🎲🐲⚔️ READY PLAYER ONE . . . The crisis has started . . . Critical services are degrading . . . Key technology provider is offline . . . 3rd and 4th-party dependencies surface, and suppliers have quietly switched the AI models underpinning services . . . What do you do next? . . . Choose carefully . . . Your decision changes the scenario . . . I had a strategy session with iluminr, and I remain impressed by how creatively the company approaches risk and resilience. The experience sometimes feels like D&D for organizational preparedness—except the dragon is a cyberattack, geopolitical disr
4 reactions · 1 comments · 1 reposts
You do not manage information security by keeping the entire game plan in one person’s head—and hoping the spreadsheet makes it through extra time . . . I recently conducted a client reference call on ZenGRC with the Head of Information Security at a globally recognized sports organization. This is an organization with enterprise-level exposure, expectations, and scrutiny—but without an army of people available to administer GRC. That distinction matters . . . The security team needed to move beyond spreadsheets, disconnected evidence, policy-chasing emails, and an excessively detailed risk
2 reactions · 0 comments · 0 reposts
Last updated 2026-08-04