< ciso
brief />
Tag Banner

All news with #grc tag

138 articles · page 2 of 7

Cybersecurity’s Shift From Protection to Survival

🔒 The piece argues that cybersecurity must move beyond a prevention-first mindset to a survival-focused discipline. It stresses that while traditional controls (MFA, patching, hardening) remain necessary, organizations need breach readiness: continuity, recoverability, tested incident response, and clear governance. Regulatory and market pressures (EU resilience laws, US disclosure and accountability) plus AI-driven acceleration make resilience an operational imperative.
read more →

Six CISO Strategies to Master Business Risk

🔐 Senior security leaders outline how CISOs must expand beyond technical risk to address business risk, aligning security with profitability, operations, and strategic objectives. They recommend partnering with business owners, mapping security to corporate OKRs, building relationships across functions, and running business-focused tabletop exercises. Formal education in governance and integrating cyber into enterprise risk management are stressed as critical steps to ensure cyber risks are evaluated alongside financial and operational risks.
read more →

FCC Proposal Would End Anonymous 'Burner' Phones

🛡️ The FCC has proposed a rule that would eliminate so-called burner phones by requiring telecom providers to collect and retain detailed personal information from virtually all phone customers. The rule would mandate submission of government-issued ID numbers, physical addresses, and additional data for business and foreign accounts, raising alarm among privacy and civil rights advocates. Supporters argue the changes target scammers and illicit activity, while critics warn of significant privacy, surveillance, and cybersecurity consequences if carriers must store this expanded dataset.
read more →

UK filtering plan raises encryption and security concerns

🔒 UK Prime Minister Keir Starmer urged tech firms to implement device controls to block children from viewing or creating sexually explicit imagery, prompting CISOs to warn the plan could undermine enterprise encryption. Starmer gave companies three months to propose voluntary measures before pushing legislation; analysts caution on-device scanning is unlikely at scale and cloud processing would introduce new risks. Experts highlight logistical, performance, age-verification, and abuse risks that could create exploitable inspection vectors.
read more →

Quantifying Cyber Risk to Engage Boards Effectively

🔍 A panel at Infosecurity Europe 2026 advised that focusing on financial impact is an effective way to communicate cyber risk to boards. Using Cyber Risk Quantification (CRQ) and clear data helps translate technical threats into dollar values that executives understand. BP and NatWest speakers emphasized making outputs simple, trustworthy and aligned to board needs to secure support and decision-making.
read more →

Executives and CISOs Must Treat Cyber as Statecraft

🔒 Bharat Thakrar of ISACA’s London Chapter told Infosecurity Europe 2026 that cyber, AI and geopolitics are now inseparable and warned against treating security as merely an IT problem. He cited breaches like Sony Pictures (2014), Viasat (2022) and Stryker (2026) to show private firms can be legitimate geopolitical targets. Thakrar proposed the Cyber Geopolitical Preparedness and Response (CGPR) framework—assess exposure, evaluate readiness, plan response and continuous monitoring—and urged geopolitical stress‑tests, revamped HR vetting, tighter access controls and predefined executive authorities.
read more →

AWS Spring 2026 SOC Reports Cover 188 Services

🔒 Amazon Web Services (AWS) released Spring 2026 SOC 1, 2, and 3 reports covering 188 services for the period April 1, 2025–March 31, 2026, providing customers a full year of assurance. Customers can download SOC 1 and 2 reports via AWS Artifact, while the SOC 3 report is available on the AWS SOC Compliance Page and AWS Artifact. AWS also published the SOC report package in NIST OSCAL (JSON) format to support machine-readable, standards-based compliance automation. AWS encourages customers to review services in scope and contact their account teams with questions or feedback.
read more →

Six critical security gaps every CISO must address

🔒 CISOs admit many organizations remain underprotected, with surveys showing gaps in data protection, incident preparedness, and resourcing. As adversaries adopt automation and AI, security programs must close six core gaps: perception, speed versus attackers, business‑security alignment, skills, AI security, and legacy systems. Experts urge CISOs to shift toward resilience, accelerate operations with automation and CTEM, and invest in workforce and governance.
read more →

SEC 10-K Cybersecurity Trends and Governance 2025

📝 This article analyzes the new SEC 10-K cybersecurity disclosure section (1.C) across the top 200 S&P companies, summarizing governance, reporting lines, standards, and trends between 2024 and 2025. It highlights that the CISO remains the principal cybersecurity role, with the CIO commonly as the reporting executive and audit committees most frequently overseeing cyber risk. The piece also reviews common practices such as TPRM, proactive testing, human-centric training, AI risks, and the author’s AI-assisted data collection and analysis methods.
read more →

Why Organizations Need a Vulnerability Operations Center

🔎 A Vulnerability Operations Center (VOC) centralizes how organizations qualify, prioritize, and drive remediation to turn vulnerability findings into measurable risk reduction. Unlike legacy vulnerability management, which relies on periodic scans and severity scores, a VOC applies exposure management, governance, and cross‑team coordination to focus remediation on reachability, exploitability, and business impact. VOC teams track execution KPIs, enforce SLAs, and work alongside SOCs to shift organizations from reactive patching to continuous prevention.
read more →

How CISOs Can Prepare to Secure Board and Advisory Roles

🔒 Many CISOs are pursuing board and advisory roles to bridge gaps between security teams and directors, improve communication, and shape product roadmaps. Leaders such as ISACA vice chair Jamie Norton, Accenture’s Mitra Minai, and Nathan Morelli describe governance learning, vendor advisory seats, and targeted certifications as common pathways. The article emphasizes governance capability, strategic language, and the significant time commitment these roles demand.
read more →

Patching SLAs Should Be the Minimum, Not the Strategy

🔒 The author warns that relying on patching SLAs creates a misleading dashboard: SLAs show ticketing discipline, not true exposure. Easy, agent-patchable items keep scores green while legacy systems and architectural flaws remain in exception queues. Drawing on experience as a CISO and industry reports, the piece promotes cyber risk quantification to express exposures in dollars. It recommends treating SLAs as a floor, tightening exception hygiene, and funding remediation.
read more →

Aligning Cyber Risk Communication with Boardroom Psychology

🔍 Security leaders must translate technical risk into clear business decisions to gain board support. Boards want concise, data-driven briefings that link exposures to financial impact, operational disruption and regulatory consequences rather than technical status updates. The most effective conversations prioritize a few high-impact issues, explain trade-offs and show exactly where resources will measurably reduce loss.
read more →

Top Sales Challenges Costing MSPs Cybersecurity Revenue

🔍 The article identifies five go-to-market barriers that prevent managed service providers (MSPs) from converting growing cybersecurity demand into predictable revenue. It argues many MSPs emphasize technical findings and frameworks rather than translating risks into business outcomes, leaving security positioned as a cost rather than a strategic investment. Cynomi's GTM Academy Complete Sales Kit is presented as a practical, operator-led playbook to align sales and technical teams, quantify ROI, and expand existing accounts through targeted discovery, scoring, and playbooks.
read more →

Managing OT Risk at Scale: Leadership Over Technical Fixes

🛡️Organizations frequently assume IT security models apply to operational technology, but the article argues that OT demands a different approach because systems have long lifecycles, limited patching, and pervasive third‑party dependencies. The core issue at scale is governance: consistent decision rights, escalation logic and shared accountability across distributed sites. Boards should focus on concrete OT scenarios, clarify whether governance is centralized or federated, and insist on independent assurance rather than tool debates. The piece frames OT resilience as a leadership and governance challenge, not merely a technical one.
read more →

CISOs Evolve into Enterprise Risk and Business Strategists

🔒 Nitin Raina’s move from IT operations to Thoughtworks’ global CISO and global head of enterprise risk illustrates a fast-growing trend: CISOs increasingly lead enterprise risk programs. Since 2020 Raina has built an ERM function that links strategic, operational, and cybersecurity risks through assessments, gap analyses, and controls. Industry reports show most CISOs now share accountability for operational business risk and are responsible for AI governance, making GRC and risk quantification central to executive and board trust.
read more →

Why the CISO Reporting Line Debate Still Matters in 2026

🔒 The article argues that the ongoing debate over the CISO reporting line persists because many organizations still view cybersecurity as a technical issue rather than a strategic leadership concern. It emphasizes that reporting relationships matter for access, authority and influence, but they are not a panacea. Effective security depends on governance, trust between the CISO and their boss, and the ability to operate across IT, legal, HR, procurement and business units. The piece rejects a universal model and urges focus on cross‑functional authority and leadership.
read more →

Board-Level Definition Needed for Cyber Resilience

📌 A literature review of 38 academic and industry sources finds cyber resilience is inconsistently defined, creating governance and measurement challenges for boards and executive teams. The author argues cyber resilience should be framed in business terms—operational continuity, stakeholder confidence, and financial stability—rather than technical controls alone. Regulatory divergence and sector priorities complicate standardization, so boards need clear, outcome-focused metrics and assigned accountability.
read more →

Federal Cyber Funding Shifts in Trump’s 2027 Budget

🔍 The Trump administration's proposed 2027 budget trims total civilian federal cybersecurity funding by about $227 million, falling from $12.455 billion in 2026 to $12.228 billion in 2027. The request directs the largest increases to the Department of Justice (+$312M) and State (+$174M) while cutting Department of Homeland Security cyber funding and imposing deep reductions at CISA and the NSF. Enterprises should reassess dependencies on federal cyber support, accelerate private-sector threat intelligence ties, and review compliance assumptions given reduced federal capacity.
read more →

Why Third-Party Risk Is the Biggest Gap in Client Security

🔒 The next major breaches are likely to originate from trusted vendors, SaaS tools, or subcontractors, expanding the enterprise perimeter beyond owned infrastructure. Cynomi's new guide argues that Third-Party Risk Management (TPRM) must evolve from an annual checkbox into a continuous, governance-grade security function driven by regulatory pressure and financial risk. With regulators like CMMC, NIS2, and DORA raising expectations, and research showing third parties factor in roughly 30% of breaches and average remediation costs near $4.91M, MSPs and MSSPs can monetize structured, tech-enabled TPRM as a repeatable, high-margin service.
read more →