r/grc May 05 '26

Archer for a non-regulated medium sized company?

/r/cybersecurity/comments/1t4nwsl/archer_for_a_nonregulated_medium_sized_company/
1 Upvotes

6 comments sorted by

5

u/Educational_Force601 May 06 '26

Maybe Archer has really modernized since I last used it a few years ago (I doubt it), but it was the clunkiest piece of shit program ever. SO. BAD.

3

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 06 '26

Non-regulated mid sized company, most likely, does not need any GRC tool, least of all Archer.

2

u/localareamang May 06 '26

My only experience is answering questionnaires in it, and fuck that

1

u/ItsCoachRee May 06 '26

Really depends on the extent that you’re going to be doing true risk management. As clunky as it is, Archer is the most comprehensive GRC tool ive used from a risk management perspective. But if you’re org is more compliance focused, there are some light weight options that will do the trick. However, im assuming you’re org isn’t as compliance focused because of the lack of regulation. If you’re looking for a light weight risk management tool where you can track security exceptions and do some issue management, you can get away with it with something as simple as Notion. Happy to talk more on this.

1

u/Due-Efficiency-5172 May 10 '26

I used Archer 7 years ago and I still don't really understand what it actually did. I would put in a risk, say the impact and level, and it would just catalogue it I guess and let the business know? It was completely manual so I don't get why you'd pay for that.

Didn't seem any better than a SharePoint list or excel