Risk and Compliance Management – much more than Loss Avoidance and “Check-the-Box“

Mercury Risk and Compliance, Inc. (“Mercury”) was founded in 2023. As former CISOs and GRC Leaders of Fortune-50 companies, its founders and executive leadership team are internationally-recognized pioneers in Cybersecurity, GRC, Cyber Risk Quantification (not just loss-avoidance), Automated Compliance Efficacy Testing and aligning Cyber Security, Cyber Risk and Technology Risk with overall Business Strategy and Operations across multiple industries, including Technology, Telecommunications, Social Media, Energy, Gas & Oil, Transportation, Manufacturing, Financial Services, Government, and Military in some 60+ countries.

Significantly, Mercury’s methodologies, frameworks, and technology provide you with a profound, industry-leading, proven and scalable approach to actionable, defensible decision-making to deliver a return-on-risk and compliance management.

Mercury’s solutions, methods and advisory services deliver a business-centric, defensible, value and outcome-based decision support platform, that aligns with your strategic objectives and that is rooted in Data-centric and information-centric private data models – supporting your commitments to stakeholders, customers, and regulators.

Incorporated in Delaware, USA, the company’s Corporate Head Office is in Austin Texas, USA and along with its partners, has operations across the USA (including New York, New Jersey, Boston, California), the UK, Europe, Southeast Asia and Australasia.

Gavin Anthony Grounds

CEO and Co-founder

Gavin Grounds jointly founded Mercury as a former CISO, Strategist, and multiple patent-holder across a variety of industries and sectors, including Technology, Telecommunications, Social Media, Cyber Security, Oil & Gas, Financial Services, IT/OT/BP Outsourcing, Engineering and operations, Government and Military in countries on all continents.

He is a globally-recognized thought leader in Risk Management, Risk Quantification and Cyber Security Strategy & Operations.

His patents including Cyber Risk Quantification, Cross-jurisdictional Taxation and Remittance, and Micro-payments processing.

He has served in executive leadership positions at companies such as Meta, Verizon, DXC, Hewlett Packard Enterprise and HP.

Gavin has successfully launched, grown and operated several technology companies in the UK and in the USA, including a software house developing plant operations for Europe’s largest toxic waste incineration and waste disposal sites, automating some of Europe’s and Scandinavia’s largest industrial weighing, quarrying, and distillery operations, as well as two cyber security consulting firms and a payments processing platform in the USA.

He holds an MBA (GPA 4.0), a Bachelor’s with Honors in Computer Science, is a Chartered Engineer, a Chartered IT Professional, an accredited Board Director, and is also a Fellow of the BCS (Chartered Institute for IT.)

Grace E. Beason

COO, Cofounder and Board Member

Grace E. Beason is Co-Founder and Chief Operating Officer of Mercury Risk & Compliance and a global Governance, Risk and Compliance executive and transformation leader with more than two decades of experience spanning cybersecurity, enterprise GRC, risk, privacy, regulatory compliance and technology-enabled transformation.

Grace’s leadership experience spans complex global enterprises, including Guidewire Software, DXC, HPE, HP, EDS, and the Massachusetts Department of Mental Health, where she served as Chief Privacy Officer. Her expertise spans enterprise GRC strategy and operations, cybersecurity and technology risk, regulatory compliance, privacy, audit and assurance, governance, control design and effectiveness, risk assessment and quantification, multi-regulation and multi-framework strategy, global regulatory environments, GRC technology and automation, and large-scale program transformation. She led a 200-person global GRC organization and pioneered Automated Control Efficacy Testing (ACET).

Her background in clinical social work and counseling psychology adds a distinctive human-centered perspective, particularly in understanding how behavior, organizational dynamics and change influence the effectiveness and adoption of risk, compliance, technology and AI initiatives. At Mercury, Grace brings that perspective together with global GRC operating experience to advance measurable, technology-enabled and human-centered approaches to cyber risk and GRC, including an AI-first strategy that extends Mercury’s shift-left approach to risk and compliance.

Grace is an international conference speaker and holds CISA, CISM, CRISC, CDPSE and CHPS credentials. Her industry recognition includes MetricStream’s GRC Visionary Award and Best-in-Class Excellence in IT GRC Management from 20/20 GRC.