No Result
View All Result
  • Login
Monday, September 15, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond

by FeeOnlyNews.com
4 months ago
in Market Analysis
Reading Time: 4 mins read
A A
0
The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond
Share on FacebookShare on TwitterShare on LInkedIn


RSAC is the largest cybersecurity conference in the world. Leaders and practitioners across all sectors come together to tackle challenges, all under the maxim of “managing risk.” But what does “risk” actually mean at a security conference? Is it a mythical pursuit? Marketing buzzword? Or generic substitute for “the thing we need to detect/prevent/remediate”?

RSAC Chairman Dr. Hugh Thompson opened this year’s conference by asking: “How do we operate with purpose in a time of great uncertainty?” This simple question is at the core of risk management and marks a radical departure from the security status quo. Where security focuses on “operate,” risk focuses on “uncertainty.” The goal of risk is to make better decisions that maximize opportunity and minimize loss while operating under uncertain conditions. Security and risk intersect by leveraging security data about today’s operational environment to make risk-informed trade-offs.

Where Does Risk Fit In At A Security Conference? Even In Places You Don’t Expect.

Of RSAC’s 535-plus open conference sessions, more than one-third prioritized risk-centric topics. Regulatory compliance still occupies the most space in risk conversations, but there was nearly an even split between strategic/programmatic topics (regulatory, risk management process and governance, and strategic and business risk) and technical risk domains (application security, AI/ML risks, supply chain and third-party risks, threat and vulnerability intelligence, cloud and infrastructure security, and data privacy and security).

 

Key Trends Reshaping The Risk Narrative

As we noted in our RSAC themes blog, efficiency drove vendor messaging. AI agents (hoping to be fully agentic one day), platformization, automation, and intelligence dominated. These RSAC themes, current business trends, and thousands of end-user conversations we’ve held at the intersection of security and risk signal key industrywide shifts, such as:

Technology resilience must be connected to customer services and business value. Regulatory mandates have put operational resilience on the map for financial organizations worldwide, and it’s now influencing global IT practices. To better define and plan for resilient outcomes, risk leaders emphasize connecting technologies with the critical services those technologies enable — even when regulation isn’t forcing their hand. This approach isn’t new, but it’s accelerating, creating stronger partnerships between risk and IT teams and enabling risk teams to better articulate revenue impacts from failures in critical business and technology components. Professional services and business recovery firms highlighted this at RSAC, further underscoring the resilience imperative.
Newer GRC vendors innovate continuous controls monitoring (CCM). The enterprise governance, risk, and compliance (GRC) market has talked about CCM for years. But it required customers to have developer-level expertise to manage API specifications or perform DIY for integrations (spoiler alert: most risk teams don’t have this!). Smaller vendors have leapfrogged established ones by building out-of-the-box integrations that target cloud-native SaaS providers where more “greenfield” customers operate their tech stack. For now, these newer GRC offerings will struggle with enterprise customers who have legacy and on-premises tech footprints with plenty of technical debt to contend with, but they are paving a path to CCM that shows it isn’t just for “high maturity” organizations.
Legal and security teams form an unlikely but critical alliance. This year, RSAC featured many general counsels and heads of legal (30 by our count!) in its GRC and CISO sessions. Legal and security teams are working more closely together, driven by the legal and regulatory landscape. In his session “A Deep Dive Into The New SEC Cybersecurity Disclosure Requirements,” Forrester’s Jeff Pollard explored the legal implications that boards and CISOs must consider. General counsels and CISOs are establishing structured communication channels and regular cross-departmental check-ins to align priorities and share information effectively. This new power couple’s shared goal: Protect their organizations and mitigate risk to the business.
“Supply chain” has become a confusing catch-all in the market. Plastered on conference booths were dozens of references to supply chain risk. Vendors use it to describe a range of capabilities, including AI-driven third-party assessments, fourth- and nth-party discovery, and vulnerability identification in the software supply chain. This broad usage muddles the distinction between managing risks to and from entities versus the security risks posed by components and processes. The result? Buyers are often misled about the solutions.
Cyber risk quantification (CRQ) gains mass appeal among CISOs and vendors. Business-minded CISOs are increasingly seeking ways to articulate operational cyber risk in terms of its material impact on the business. Concurrently, security vendors across various market categories are beginning to integrate CRQ analysis into their products, including vulnerability, attack surface, security posture management, Zero Trust, risk ratings, third-party risk, and GRC technologies. These tools provide essential security telemetry that, when applied through a CRQ model, delivers objective risk insights. Industry efforts to champion open standards, automation, and integrated data models for cyber risk analysis have helped shake off legacy ideas that CRQ is too manual and difficult to accomplish. Now, CRQ is evolving into a core capability of a holistic cyber risk management program.
AI is GRC’s shiny object. GRC is overdue for innovation. AI holds tremendous potential to automate data collection, processing, and reporting, which has been a prolonged pain point for GRC users. While AI promises to drive efficiency and reduce overhead — a core business priority for GRC buyers — scaling AI and agentic AI requires resources to manage workflows and agents, and GRC teams are still struggling with the basics. They’d love to use AI to automatically conduct risk assessments when new assets are identified but are stuck building scalable control testing processes or maintaining accurate asset inventories. To help customers fully embrace AI, GRC vendors need to streamline the fundamentals so that customers have more time and resources to plan for AI-enabled workflows.

RSAC conference sessions, vendor messaging, and customer conversations reflect what we’ve known: Risk is not a compliance checkbox but a dynamic discipline to navigate uncertainty and enable business outcomes. Has it reached critical mass? Not yet. Risk practitioners must continue to drive the conversation by showing up to security conferences, challenging status-quo thinking, and pressuring vendors and presenters alike to think critically about how security exposures and events translate to material business impact. Build proficiency by seeking out technical conference tracks and listening to how security practitioners talk about risk, and showcase your own risk program enhancements at security conferences. As RSAC indicates, security leaders are eager for risk knowledge.



Source link

Tags: CyberRiskRSACTidesTurning
ShareTweetShare
Previous Post

Warren Buffett tells WSJ he stepped aside as CEO after feeling old

Next Post

How women in Canada can start investing

Related Posts

Global Oil Field Chemicals Market Size, Trends, and Forecast

Global Oil Field Chemicals Market Size, Trends, and Forecast

by FeeOnlyNews.com
September 15, 2025
0

The oil field chemicals market plays a crucial role in the exploration, drilling, production, and refining processes in the oil...

Reintroducing A Classic: The S&R Executive Spotlight

Reintroducing A Classic: The S&R Executive Spotlight

by FeeOnlyNews.com
September 14, 2025
0

As the world moves forward, some things really should stay behind — like eighties shoulder pads, popcorn ceilings, and fondue...

School Is In Session And Attackers Are Grading Your Software Supply Chain Security

School Is In Session And Attackers Are Grading Your Software Supply Chain Security

by FeeOnlyNews.com
September 12, 2025
0

Software supply chain attacks continue to be a top external attack vector for attackers to breach enterprises, government agencies, and...

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

by FeeOnlyNews.com
September 12, 2025
0

News has been trickling out since August 20 about a security issue in Salesloft’s Drift product, a marketing and sales...

Rewind And Fast-Forward TV Advertising

Rewind And Fast-Forward TV Advertising

by FeeOnlyNews.com
September 12, 2025
0

TV’s stakeholders — consumers, advertisers, and publishers — are out of sync. Consumers love streaming TV but say they don’t...

Answer Engines Outpace Antitrust Law

Answer Engines Outpace Antitrust Law

by FeeOnlyNews.com
September 12, 2025
0

To remedy Google’s monopoly in search, Judge Amit Mehta ruled that Google merely has to share limited search data with...

Next Post
How women in Canada can start investing

How women in Canada can start investing

Hedge fund manager Einhorn sees upside for gold and inflation

Hedge fund manager Einhorn sees upside for gold and inflation

  • Trending
  • Comments
  • Latest
1 Stock to Buy, 1 Stock to Sell This Week: Walmart, Target

1 Stock to Buy, 1 Stock to Sell This Week: Walmart, Target

August 17, 2025
Of Property Rights, Civil Society, and Shampoo

Of Property Rights, Civil Society, and Shampoo

September 1, 2025
Engine Capital takes a stake in Avantor. Activist sees several ways to create value

Engine Capital takes a stake in Avantor. Activist sees several ways to create value

August 16, 2025
James Galbraith: Crash in Top Economist Hiring Contradicts Elite-Favoring “Skill Biased Technical Change” Theory

James Galbraith: Crash in Top Economist Hiring Contradicts Elite-Favoring “Skill Biased Technical Change” Theory

September 2, 2025
Vanguard reaches .5M SEC settlement

Vanguard reaches $19.5M SEC settlement

August 29, 2025
RBC wealth revenue rises despite recruiting costs

RBC wealth revenue rises despite recruiting costs

August 27, 2025
Book Review: What I Learned about Investing from Darwin

Book Review: What I Learned about Investing from Darwin

0
Bluey Scavenger Hunt Board Game only .99!

Bluey Scavenger Hunt Board Game only $7.99!

0
OpenAI board chair Bret Taylor says we’re in an AI bubble (but that’s okay)

OpenAI board chair Bret Taylor says we’re in an AI bubble (but that’s okay)

0
Global Oil Field Chemicals Market Size, Trends, and Forecast

Global Oil Field Chemicals Market Size, Trends, and Forecast

0
How a Written Roadmap Can Empower Your Retirement Plans

How a Written Roadmap Can Empower Your Retirement Plans

0
From Gaza to Europe: How one Palestinian outsmarted war, smugglers, and the Mediterranean using ChatGPT and a jet ski

From Gaza to Europe: How one Palestinian outsmarted war, smugglers, and the Mediterranean using ChatGPT and a jet ski

0
Bitcoin ETFs lock .3b in inflows as BTC steadies above 5K

Bitcoin ETFs lock $2.3b in inflows as BTC steadies above $115K

September 15, 2025
How a Written Roadmap Can Empower Your Retirement Plans

How a Written Roadmap Can Empower Your Retirement Plans

September 15, 2025
From Gaza to Europe: How one Palestinian outsmarted war, smugglers, and the Mediterranean using ChatGPT and a jet ski

From Gaza to Europe: How one Palestinian outsmarted war, smugglers, and the Mediterranean using ChatGPT and a jet ski

September 15, 2025
5 fintechs that could IPO after Klarna

5 fintechs that could IPO after Klarna

September 15, 2025
Global Oil Field Chemicals Market Size, Trends, and Forecast

Global Oil Field Chemicals Market Size, Trends, and Forecast

September 15, 2025
Australia’s financial regulator slaps a 0 million fine on ANZ, its largest ever on a single entity

Australia’s financial regulator slaps a $160 million fine on ANZ, its largest ever on a single entity

September 15, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Bitcoin ETFs lock $2.3b in inflows as BTC steadies above $115K
  • How a Written Roadmap Can Empower Your Retirement Plans
  • From Gaza to Europe: How one Palestinian outsmarted war, smugglers, and the Mediterranean using ChatGPT and a jet ski
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.