< ciso
brief />
Tag Banner

All news with #grc tag

138 articles

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

How the CISO Role Will Evolve by 2029

🔐 Security leaders predict that by 2029 the CISO will shift from a primarily technical defender to a strategic business leader. Experts foresee CISOs enabling innovation, advising executives on risk, and coordinating enterprise-wide trust and resilience efforts while adapting to AI-driven speed and complexity. The role will vary by organization but will demand stronger business acumen, orchestration skills, and continuous validation of exposure.
read more →

Reframing cyber backlogs: roles, priorities, and outcomes

🔍 Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more →

How CSOs Turn Cybersecurity into Growth Strategy

🔒 Cybersecurity leaders must shift from proving relevance to demonstrating how security enables innovation and growth. CSOs should embed security into business roadmaps, partner early with operational teams, and translate cyber risk into business impact. Emphasizing resilience, user-centered controls, and seamless protections helps security become a catalyst for transformation rather than an obstacle.
read more →

Operationalize third‑party cyber risk, don’t rely on heroics

🔒 Third-party risk often fails in practice because security teams are looped in too late, turning reviews into last-minute blockers. The author recommends establishing formal intake, clear timelines, and joint workflows with procurement, legal, and finance so security can assess vendors before contracts are signed. Emphasis is placed on using contracts to enforce remediation and adapting processes for risks introduced by AI and shadow IT.
read more →

AWS releases CSA Compliance Guide mapping CCM

🛡️ AWS Security Assurance Services published a Cloud Security Alliance (CSA) Compliance Guide for AWS that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 to AWS services and implementation recommendations. The guide helps organizations plan, implement, and evidence controls within their CCM scope, including those pursuing CSA STAR certification, and aligns CSA’s Shared Security Responsibility Model with the AWS model. It notes AWS-owned controls and available attestations via AWS Artifact, and provides implementation guidance, common pitfalls, and example evidence for customer- and shared-owned controls.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

CISOs Rising to Lead Business Resilience

🔒 CISOs are increasingly acting as de facto chief resilience officers, expanding from prevention to incident response and recovery. Experts recommend framing resilience in business terms — uptime, data protection, and financial impact — to secure board-level buy-in and funding. Practical steps include defining minimum viable operations, rehearsing recovery through a "ResOps" approach, and partnering with GRC, finance, and operations to share responsibility.
read more →

Ten survival tips for CSOs reporting directly to CEOs

🔒 As CSOs gain prominence, many now report directly to the CEO, shifting expectations from technical stewardship to strategic partnership. Reporting to the CEO grants greater access and influence but demands business-focused skills, clear metrics, and the ability to translate risk into business impact. Experts recommend aligning expectations, documenting goals, prioritizing trust and candor, and treating governance as a strategic enabler to drive organizational resilience.
read more →

AI Adoption Shifts Expectations for Risk Management

🛡️ As AI becomes embedded across products, workflows, and supply chains, security leaders are being asked to enable faster, safer business decisions. Existing governance programs lag behind AI adoption, widening gaps in visibility and control. Fragmented risk views across security, procurement, privacy, and IT create blind spots that expand the blast radius when AI systems connect to enterprise data and workflows. CISOs must move from periodic risk review to continuous assurance and risk decisioning to prioritize what can move forward, what needs guardrails, and what must stop.
read more →

Police Chiefs Back Cybercrime Risk Orders Reform

🛡️ Senior UK law enforcement leaders have urged stronger legal tools after two men were jailed for the 2024 TfL hack, calling for Cybercrime Risk Orders (CCROs) to manage high-risk suspects. Sentenced under Section 3ZA of the Computer Misuse Act, the case—described as the largest cybercrime prosecution—highlighted investigation complexity, cross-border cooperation, and gaps in existing powers for underage offenders. Debate continues over CCROs’ practicality and enforcement.
read more →

Building the Business Case to Reduce Security Debt

🔍 Security leaders have improved visibility into vulnerabilities across applications and pipelines, yet many organizations face growing security debt as findings outpace remediation. Treat security debt like financial debt by measuring total and critical debt, setting reduction targets, and distinguishing acceptable versus unacceptable risk. Focus remediation capacity on exploitable vulnerabilities in crown-jewel systems, establish risk-focused metrics, and increase investment in remediation and automation to align security outcomes with business priorities.
read more →

CISO Playbook for Post‑Quantum Mandates and Migration

🔒 This guide explains regulatory timelines and a strategic playbook for CISOs and senior leaders to manage post-quantum cryptography (PQC) migrations across large organizations. It outlines the practical split between short‑lived protocol upgrades (like TLS) and long‑lived embedded devices, recommends centralized governance via a cryptography center of excellence, and emphasizes board-level framing, vendor engagement, and phased execution to meet compliance deadlines.
read more →

Top IT Security Certifications Driving Higher Pay

🔍 Foote Partners' 2Q 2026 report ranks the most valuable IT security certifications by average pay premium and recent market value increase. The article lists the top 13 credentials employers value now, describing each certification’s focus, prerequisites, exam length, and typical training and exam costs. It highlights portfolio certifications like GIAC’s GSE and GSP, vendor offerings from Microsoft and Check Point, and vendor-neutral options such as CCSK, ISACA’s CRISC and CISA, and ISC2’s CISSP and CSSLP. Practical, hands-on credentials like GX-CS and OffSec’s PEN-200/OSCP+ are also covered.
read more →

UK launches Cyber Resilience Pledge for businesses

🛡️ The UK government announced the Cyber Resilience Pledge, with over 60 businesses signing up after its unveiling at CYBERUK in April alongside a £90m support package. Signatories such as Microsoft UK, Marks & Spencer and Vodafone commit to board-level cyber accountability, NCSC training, Early Warning registration and risk-based Cyber Essentials adoption across supply chains. The scheme targets medium and large firms with the aim of driving baseline security improvements across suppliers.
read more →

The modern CISO is becoming the next CFO

🛡️ The role of the CISO is evolving from a technical operator into a broad, enterprise-level executive responsible for cyber resilience, regulatory compliance, AI governance and business risk. As cyber risk becomes business risk, organizations are expanding security leadership—adding deputy CISOs and specialized teams—while keeping centralized accountability. The author argues the CISO should report independently (e.g., to the CEO, COO or CRO) and that AI increases the need for clear human accountability.
read more →

Seven common cyber risk assessment mistakes to avoid

🔍 A cyber risk assessment should be a decision tool that ties technical findings to business impact, yet many organizations fall into common pitfalls. Experts warn against rote, checklist-driven assessments, sugarcoating results, narrow scoping, and overreliance on risk registers that mask assumptions. Other frequent missteps include failing to link risks to business outcomes, confusing compliance with true security, and neglecting the implications of new technologies like AI. The article outlines seven practical gotchas and recommends context-driven, continuous risk assessment involving business stakeholders to produce actionable, defensible insights.
read more →

FedRAMP 20x and the rise of GRC engineering

🔍 The author argues that much of traditional compliance has become theatrical—focused on curated, point-in-time evidence rather than continuous operational truth. FedRAMP 20x and the broader GRC engineering movement push assurance toward automation, machine-readable evidence and continuous telemetry, shifting audits from static snapshots to ongoing validation. The writer recounts their organization’s FedRAMP 20x pilot, describing early setbacks as iterative learning rather than failure.
read more →

MPs Warn UK Museums Face Cybersecurity Shortfalls

🛡️ Parliament’s Public Accounts Committee has criticised the Department for Culture, Media and Sport for a reactive approach to cybersecurity, leaving national galleries and museums exposed. The PAC highlighted incidents including a ransomware attack on the British Library and thefts from the British Museum as evidence of systemic failings. It calls on DCMS to set out concrete actions, share lessons across the sector, and address skills shortages and legacy technology.
read more →