“What work are you not doing because of the limits of your current system?”
James Marron sells enterprise GRC into some of the most regulated institutions in EMEA, and he starts nearly every conversation assuming he can’t help. A conversation about the ROI most vendors miss, and why board-level accountability has become the real accelerant of change.
James Marron came to Protecht by way of management consulting at Deloitte and a stint selling core banking platforms — deals that ran from several hundred thousand euros a year into the millions, over multi-year transformations. That background shaped how he approaches enterprise GRC in EMEA: he thinks in strategic priorities, board mandates, and buyer journeys rather than sales processes.
We talked with James about the counterintuitive way he opens a discovery call, the ROI case he thinks most vendors get wrong, and how new regulation is pushing risk accountability all the way up to the board.
Selling into highly regulated environments right now, with so much friction around spending — what actually determines what moves forward?
There are two main categories of deal. One is digitizing a manual set of processes — spreadsheets, SharePoints, Outlook emails — where you’re implementing a first system as a transformation program. The other is replacing an existing or legacy vendor, whether because of a functionality gap, cost, or complexity. Each has its own rhythm.
You can run your business on spreadsheets and an email account. It won’t be pretty, and it won’t do everything you want, but you can. So the job is uncovering the strategic priorities and positioning GRC within that framework, rather than as one more cost to the business.
GRC tooling isn’t a Bloomberg terminal. You can run on spreadsheets — it just won’t be pretty. So you position it as strategic, not as another cost.
How do you build that ROI case?
Two ways. The first is the time sinks in the status quo — the hours per week, month, or quarter spent on manual tasks, chasing status updates, assigning actions — which you can put a monetary value against based on FTE cost. The second is more nuanced, and it’s the one I like: what is the work you are not doing because of the limitations of the status quo? We’re not looking to take headcount out of the business. The question is, as a result of these manual operations, what work should risk managers be doing — what would they aspire to do — if you removed the bottleneck?
The question I love in an ROI case: what work are you not doing because of the limits of your current system?
When you’re talking about AI, what skepticism do you hit most?
The most common objection dressed up as a question is about data governance — what happens to my data on the instance, are you going to train your models on it? Which, when you step back, they’re often managing incident triage in a spreadsheet with no audit trail, no change control, and no role-based access, and yet they’re worried about AI model governance. That’s the cart before the horse. It’s not to dismiss the concern — it’s a way to pivot back to where they actually sit on their maturity journey.
I think about maturity on two axes. One is cultural: how well embedded is risk management, do people understand what a risk or a control even is when you ask them to run an RCSA? The other is technology and tooling: where do you sit today, and where would you be in a wave-a-magic-wand future state? And AI moves so fast that by the time an organization finishes putting policies in place, they’re already out of date. Executives mostly want to be reassured that you, as a vendor, have thought about this — that they’re not stepping into the unknown alone.
Boards are increasingly on the hook here.
In this part of the world, new legislation — the UK Corporate Governance Code, DORA in the EU — puts an ever-increasing onus on the board. Boards have always held ultimate responsibility for their organization’s risk profile, but now they’re being asked to sign off on the effectiveness of their material and key controls. So on a discovery call with a Chief Risk Officer, one of the first things I’ll ask is: what’s your confidence level in the information you’re presenting to your board this quarter? If it’s ten out of ten, great, we shake hands and part ways — you don’t need us. But if it isn’t, why not, and what are you going to do about it? That board-level demand for granular insight into control effectiveness is a real accelerant of change.
Is DORA fundamentally different from what came before?
DORA is helpful because it’s extremely prescriptive — the European Banking Authority released an enormous list of exactly the data points they expect reported annually, across five pillars. That had a lot of organizations running around with their hair on fire, because it became clear very quickly that either they don’t capture that information, or it’s spread across so many silos they can’t amalgamate it. Compare that to more principles-based legislation, which is woollier — you can choose your own adventure and tell yourself a comforting story that you’re “probably fine.” Prescriptive rules, and attestation regimes where a named person has to sign their name to a declaration, don’t let you off the hook so easily. There’s less room to bury your head in the sand.
What kind of project energizes you?
The big enterprise ones — and I’ll admit that reflects my own path. My first sales job was selling a core banking platform, where the smallest deal was several hundred thousand euros a year and the biggest I did ran to millions a year over a six-year transformation with a major national bank. You can’t cold-call someone on a Monday and ask them to spend tens of millions turning their bank on its head, so I learned that world of executive and board engagement first. The order form itself — the DocuSign — is just a finance milestone. The enjoyable part is the journey: understanding a team’s goals, working out whether you can actually help, putting a credible road map in place, and watching it come to life.
What do you do differently from most in that journey?
I start from the assumption that we probably can’t help this person today. They already have a working business — the doors are open, the lights are on — so they don’t obviously need to introduce organizational change. If you start there, the best case is they disagree and tell you exactly why they need to change, which gives you the motive. The second-best case is they agree with you and you end the call in four minutes instead of wasting an afternoon. A quick no is a thousand times better than a slow no.
From there it’s: who else cares, how much, why, and where does this rank against everything else they care about? It’s the buyer’s journey, not the sales process — who cares about the seller? And I’ll happily point someone to a lighter-weight tool if that’s genuinely the right fit. If you only have a small budget, that’s not us; go get a year or two out of something simpler and come back when you’ve outgrown it. Risk managers are inherently cautious, infrequent buyers — our average customer tenure is north of eight years — so you can’t arm-twist anyone into a six-figure contract. Even if you did, good luck renewing them.
I start from “we probably can’t help you.” The best case is they tell you why they need to change. That’s the motive.
What gives you the confidence to bring Protecht into the most regulated institutions on the planet?
The fact that we’ve done it before, and the caliber of institutions who vouch for us. A national prudential regulator, a Nordic sovereign wealth fund managing trillions, and the Basel-based institution that quite literally founded the discipline of operational risk management — the central bank of central banks — are all long-time customers. If I’m talking to a prospect about operational risk and they don’t recognize that last logo, I’ll gently suggest they may have bigger problems than their risk register being in a spreadsheet. The intangible value of that association is real, and those customers go to bat for us on reference calls. That’s what lets me sit down and ask a very direct question: why do you do it that way? Is it circumstance or design? And if it has to be that complicated, let’s do a two-week proof of concept and see if we can’t build it better. If we can’t, no harm done.
And outside of work?
I’ve got three kids at home — five, four, and seven months. So energy is not a resource we’re especially familiar with right now.
James Marron works in enterprise sales for Protecht in EMEA. This conversation has been lightly edited for length and clarity. (Note: specific customer names cited in the transcript have been generalized here pending approval to name them.)