< ciso
brief />
Tag Banner

All news with #grc tag

148 articles

Five-Year CISO Trends Shift Security to Workflows

🛡️ The 2026 Voice of the CISO report reveals a multi-year shift: resilience, AI governance, human risk, and board scrutiny are converging where work actually happens. While some metrics improved year-over-year, longer-term trends show fluctuating attack expectations, persistent human risk, and AI evolving from experiment to mandate. CISOs face resource gaps as governance demands outpace budgets and expertise.
read more →

Should the CISO role be split in two?

🔒 The CISO role has expanded from technical oversight to strategic business leadership, encompassing risk reporting, governance, privacy, AI oversight, and resilience. Many CISOs now carry executive authority, but two-thirds still report into IT, creating perception and resource gaps. Experts argue against creating two CISOs, favoring one strategic CISO supported by deputies or distinct functional leads for operations and governance.
read more →

Why CISOs Struggle to Answer Boards on Risk

🔒 Boards routinely ask three simple questions—How secure are we, what is our financial exposure, and are we improving? Traditional reports focus on activity counts from discrete tools (vulnerabilities, patches, alerts) and lack cross-tool context. The gaps between identity, cloud, SaaS, endpoint and vulnerability data hide real attack paths. A board-ready approach maps crown jewels, correlates signals into attack paths, prioritizes by blast radius and translates exposure into financial terms to show trend and risk reduction.
read more →

Security Roadmaps Shift to Continuous, Quarterly Review

🛡️ Security leaders are moving away from static three-year roadmaps toward a two-speed approach: long-term principles and architecture planned annually while tactical tools and controls are reassessed quarterly (or more frequently). Organizations must treat governance as ongoing communication, adapt to rapid AI-driven change, and retain long-range commitments only when tied to enduring business outcomes. Success depends on cross-functional coordination, visible metrics for boards, and flexible execution.
read more →

Unit 42 debunks three common cybersecurity myths

🔍 Unit 42 consultants identify three prevalent cybersecurity misconceptions undermining organizational defenses and prescribe corrective strategies. They warn against indiscriminate tool accumulation, which creates alert fatigue, feature underuse, and operational friction, and advocate auditing and consolidating existing platforms. Smaller organizations are reminded they remain attractive targets and should adopt an Assume Breach mindset. Finally, GRC must be treated as active defense rather than mere compliance, with robust RCM, framework alignment, and dedicated ownership.
read more →

UK shifts to service-led cybersecurity governance

🔒 The UK government is moving from top-down mandates to centrally built, user-focused cybersecurity services for its federated civil service. Breandán Knowlton-Hung, Deputy CISO, described how a 2025 NAO report revealed weak implementation of the 2022 strategy and capacity shortfalls, prompting a pivot to polycentric governance. The approach prioritizes useful central services, cheaper adoption, and reserved central authority for systemic risks.
read more →

EU auditors flag fault lines in bloc cyber resilience

🔍 The EU Court of Auditors has identified significant shortcomings in the bloc’s cyber incident detection and response, citing insufficient information exchange and unclear roles between national CSIRTs and EU-CyCLONe. The report also highlights delays in NIS2 transposition, procurement holdups for the European Cybersecurity Alert System hubs, and duplication between the Commission's cyber-situation centre and ENISA. Auditors warned that recipients of EU cybersecurity funds were not consistently vetted, risking exposure to non-EU influence.
read more →

Cyber Essentials Sees Record Uptake but SME Coverage Lags

🔒 The UK’s Cyber Essentials scheme recorded a 20% rise to 61,430 certificates between July 2025 and June 2026, split between 46,245 self-assessed CE and 15,185 CE+ audited certifications. Nearly three-quarters were recertifications rather than new sign-ups, leaving adoption low relative to about 5.7 million UK SMEs. The increase coincides with findings that 49% of SMEs experienced a cyber incident in the past year, highlighting a gap between risk and basic cyber hygiene.
read more →

Twenty-Five Years of Mass Surveillance Is Enough

📝 This essay, coauthored with Cindy Cohn and first published in Lawfare, traces the post-9/11 shift from targeted warrants to widespread mass surveillance by government and private actors. It outlines how data brokers, corporate tracking, and programs like the NSA’s Upstream and Section 702 collections have expanded governmental access to Americans’ communications. The authors argue these practices undermine Fourth and First Amendment protections and call for reassessment.
read more →

Reframe cybersecurity leadership with a CSO role

🔒 The article argues that asking CISOs to become full business leaders misses a structural problem: alignment is an organizational design issue, not just communication. It proposes a distinct CSO role that sits above cybersecurity to coordinate enterprise protection across data, resilience, regulation and operations. The CSO would provide authority to reconcile competing priorities while the CISO remains accountable for technical delivery, creating clearer ownership and better business protection.
read more →

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

How the CISO Role Will Evolve by 2029

🔐 Security leaders predict that by 2029 the CISO will shift from a primarily technical defender to a strategic business leader. Experts foresee CISOs enabling innovation, advising executives on risk, and coordinating enterprise-wide trust and resilience efforts while adapting to AI-driven speed and complexity. The role will vary by organization but will demand stronger business acumen, orchestration skills, and continuous validation of exposure.
read more →

Reframing cyber backlogs: roles, priorities, and outcomes

🔍 Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more →

How CSOs Turn Cybersecurity into Growth Strategy

🔒 Cybersecurity leaders must shift from proving relevance to demonstrating how security enables innovation and growth. CSOs should embed security into business roadmaps, partner early with operational teams, and translate cyber risk into business impact. Emphasizing resilience, user-centered controls, and seamless protections helps security become a catalyst for transformation rather than an obstacle.
read more →

Operationalize third‑party cyber risk, don’t rely on heroics

🔒 Third-party risk often fails in practice because security teams are looped in too late, turning reviews into last-minute blockers. The author recommends establishing formal intake, clear timelines, and joint workflows with procurement, legal, and finance so security can assess vendors before contracts are signed. Emphasis is placed on using contracts to enforce remediation and adapting processes for risks introduced by AI and shadow IT.
read more →

AWS releases CSA Compliance Guide mapping CCM

🛡️ AWS Security Assurance Services published a Cloud Security Alliance (CSA) Compliance Guide for AWS that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 to AWS services and implementation recommendations. The guide helps organizations plan, implement, and evidence controls within their CCM scope, including those pursuing CSA STAR certification, and aligns CSA’s Shared Security Responsibility Model with the AWS model. It notes AWS-owned controls and available attestations via AWS Artifact, and provides implementation guidance, common pitfalls, and example evidence for customer- and shared-owned controls.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

CISOs Rising to Lead Business Resilience

🔒 CISOs are increasingly acting as de facto chief resilience officers, expanding from prevention to incident response and recovery. Experts recommend framing resilience in business terms — uptime, data protection, and financial impact — to secure board-level buy-in and funding. Practical steps include defining minimum viable operations, rehearsing recovery through a "ResOps" approach, and partnering with GRC, finance, and operations to share responsibility.
read more →

Ten survival tips for CSOs reporting directly to CEOs

🔒 As CSOs gain prominence, many now report directly to the CEO, shifting expectations from technical stewardship to strategic partnership. Reporting to the CEO grants greater access and influence but demands business-focused skills, clear metrics, and the ability to translate risk into business impact. Experts recommend aligning expectations, documenting goals, prioritizing trust and candor, and treating governance as a strategic enabler to drive organizational resilience.
read more →