By the end of this year, we will likely all be sick of the phrase “systemic risk.” Referring to the complex and interconnected nature of risks that brought down the financial services sector, the phrase has been a focal point in the discussions on how to prevent such failures in the future. (And in my experience, this increased attention means that service and software vendors will be using the term in their marketing literature with increasing frequency in 2010.)
Policy makers are recommending systemic risk solutions such as new oversight bodies to assess for systemic risks or penalties for companies that are perceived to threaten the system. European Central Bank president Jean-Claude Trichet even suggested that financial institutions help avoid systemic risks by "putting aside their own profit" and being "moderate in remuneration behavior," in order to reinforce their balance sheets.
Details such as product integration and go-to-market strategy will trickle out slowly of course, but so far, this is a significant deal for a couple of reasons:
Archer fills a substantial void in EMC’s product offering, which included many elements of GRC, but no central platform to pull it all together.
EMC will introduce the Archer products to a much larger set of potential customers...most notably as a platform to manage security and compliance, but also to customers with requirements for related areas like vendor management or business continuity.
It brings another IT heavy-weight fully into the GRC space, with substantial engineering resources to work on product development (but only if Archer continues to be seen as a top priority within RSA).
As we watch this acquisition come together, as well as other upcoming announcements that will make the GRC space even more competitive, here are a few questions to consider: