No Result
View All Result
  • Login
Tuesday, June 17, 2025
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Market Analysis

The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond

by theadvisertimes.com
1 month ago
in Market Analysis
Reading Time: 4 mins read
A A
0
The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond
Share on FacebookShare on TwitterShare on LInkedIn


RSAC is the largest cybersecurity conference in the world. Leaders and practitioners across all sectors come together to tackle challenges, all under the maxim of “managing risk.” But what does “risk” actually mean at a security conference? Is it a mythical pursuit? Marketing buzzword? Or generic substitute for “the thing we need to detect/prevent/remediate”?

RSAC Chairman Dr. Hugh Thompson opened this year’s conference by asking: “How do we operate with purpose in a time of great uncertainty?” This simple question is at the core of risk management and marks a radical departure from the security status quo. Where security focuses on “operate,” risk focuses on “uncertainty.” The goal of risk is to make better decisions that maximize opportunity and minimize loss while operating under uncertain conditions. Security and risk intersect by leveraging security data about today’s operational environment to make risk-informed trade-offs.

Where Does Risk Fit In At A Security Conference? Even In Places You Don’t Expect.

Of RSAC’s 535-plus open conference sessions, more than one-third prioritized risk-centric topics. Regulatory compliance still occupies the most space in risk conversations, but there was nearly an even split between strategic/programmatic topics (regulatory, risk management process and governance, and strategic and business risk) and technical risk domains (application security, AI/ML risks, supply chain and third-party risks, threat and vulnerability intelligence, cloud and infrastructure security, and data privacy and security).

 

Key Trends Reshaping The Risk Narrative

As we noted in our RSAC themes blog, efficiency drove vendor messaging. AI agents (hoping to be fully agentic one day), platformization, automation, and intelligence dominated. These RSAC themes, current business trends, and thousands of end-user conversations we’ve held at the intersection of security and risk signal key industrywide shifts, such as:

Technology resilience must be connected to customer services and business value. Regulatory mandates have put operational resilience on the map for financial organizations worldwide, and it’s now influencing global IT practices. To better define and plan for resilient outcomes, risk leaders emphasize connecting technologies with the critical services those technologies enable — even when regulation isn’t forcing their hand. This approach isn’t new, but it’s accelerating, creating stronger partnerships between risk and IT teams and enabling risk teams to better articulate revenue impacts from failures in critical business and technology components. Professional services and business recovery firms highlighted this at RSAC, further underscoring the resilience imperative.
Newer GRC vendors innovate continuous controls monitoring (CCM). The enterprise governance, risk, and compliance (GRC) market has talked about CCM for years. But it required customers to have developer-level expertise to manage API specifications or perform DIY for integrations (spoiler alert: most risk teams don’t have this!). Smaller vendors have leapfrogged established ones by building out-of-the-box integrations that target cloud-native SaaS providers where more “greenfield” customers operate their tech stack. For now, these newer GRC offerings will struggle with enterprise customers who have legacy and on-premises tech footprints with plenty of technical debt to contend with, but they are paving a path to CCM that shows it isn’t just for “high maturity” organizations.
Legal and security teams form an unlikely but critical alliance. This year, RSAC featured many general counsels and heads of legal (30 by our count!) in its GRC and CISO sessions. Legal and security teams are working more closely together, driven by the legal and regulatory landscape. In his session “A Deep Dive Into The New SEC Cybersecurity Disclosure Requirements,” Forrester’s Jeff Pollard explored the legal implications that boards and CISOs must consider. General counsels and CISOs are establishing structured communication channels and regular cross-departmental check-ins to align priorities and share information effectively. This new power couple’s shared goal: Protect their organizations and mitigate risk to the business.
“Supply chain” has become a confusing catch-all in the market. Plastered on conference booths were dozens of references to supply chain risk. Vendors use it to describe a range of capabilities, including AI-driven third-party assessments, fourth- and nth-party discovery, and vulnerability identification in the software supply chain. This broad usage muddles the distinction between managing risks to and from entities versus the security risks posed by components and processes. The result? Buyers are often misled about the solutions.
Cyber risk quantification (CRQ) gains mass appeal among CISOs and vendors. Business-minded CISOs are increasingly seeking ways to articulate operational cyber risk in terms of its material impact on the business. Concurrently, security vendors across various market categories are beginning to integrate CRQ analysis into their products, including vulnerability, attack surface, security posture management, Zero Trust, risk ratings, third-party risk, and GRC technologies. These tools provide essential security telemetry that, when applied through a CRQ model, delivers objective risk insights. Industry efforts to champion open standards, automation, and integrated data models for cyber risk analysis have helped shake off legacy ideas that CRQ is too manual and difficult to accomplish. Now, CRQ is evolving into a core capability of a holistic cyber risk management program.
AI is GRC’s shiny object. GRC is overdue for innovation. AI holds tremendous potential to automate data collection, processing, and reporting, which has been a prolonged pain point for GRC users. While AI promises to drive efficiency and reduce overhead — a core business priority for GRC buyers — scaling AI and agentic AI requires resources to manage workflows and agents, and GRC teams are still struggling with the basics. They’d love to use AI to automatically conduct risk assessments when new assets are identified but are stuck building scalable control testing processes or maintaining accurate asset inventories. To help customers fully embrace AI, GRC vendors need to streamline the fundamentals so that customers have more time and resources to plan for AI-enabled workflows.

RSAC conference sessions, vendor messaging, and customer conversations reflect what we’ve known: Risk is not a compliance checkbox but a dynamic discipline to navigate uncertainty and enable business outcomes. Has it reached critical mass? Not yet. Risk practitioners must continue to drive the conversation by showing up to security conferences, challenging status-quo thinking, and pressuring vendors and presenters alike to think critically about how security exposures and events translate to material business impact. Build proficiency by seeking out technical conference tracks and listening to how security practitioners talk about risk, and showcase your own risk program enhancements at security conferences. As RSAC indicates, security leaders are eager for risk knowledge.



Source link

Tags: CyberRiskRSACTidesturning
ShareTweetShare
Previous Post

Warren Buffett tells WSJ he stepped aside as CEO after feeling old

Next Post

How women in Canada can start investing

Related Posts

You Don’t Need To Be Ethan Hunt To Break Into A Building

You Don’t Need To Be Ethan Hunt To Break Into A Building

by theadvisertimes.com
June 17, 2025
0

From a cybersecurity perspective, when you bring up the need to protect your organization’s endpoints, most people will think of...

Middle East Tensions Dominate, BoJ Rate Hold and DAX Clings to Support

Middle East Tensions Dominate, BoJ Rate Hold and DAX Clings to Support

by theadvisertimes.com
June 17, 2025
0

Market participants remain in limbo as tensions in the Middle East show no signs of slowing down. US President Trump...

Scenario Planning for the Future: 3 Key Examples in Sustainable Supply Chains

Scenario Planning for the Future: 3 Key Examples in Sustainable Supply Chains

by theadvisertimes.com
June 16, 2025
0

In times of heightened uncertainty, scenario planning helps businesses explore the vast complexity of the future. It doesn’t aim to...

The AI Challenge For Brands And Agencies

The AI Challenge For Brands And Agencies

by theadvisertimes.com
June 16, 2025
0

The marketing and advertising industry is gathering for a couple of days at the International Festival of Creativity in Cannes...

Wholesale Distributors

Wholesale Distributors

by theadvisertimes.com
June 16, 2025
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

US Dollar: Can Rising Geopolitical Tensions Spark a Trend Reversal?

US Dollar: Can Rising Geopolitical Tensions Spark a Trend Reversal?

by theadvisertimes.com
June 16, 2025
0

US dollar holds near 98 amid geopolitical risks and a cautious Fed outlook. Markets watch Fed projections, energy prices, and...

Next Post
How women in Canada can start investing

How women in Canada can start investing

Hedge fund manager Einhorn sees upside for gold and inflation

Hedge fund manager Einhorn sees upside for gold and inflation

  • Trending
  • Comments
  • Latest
Sir Jack A Lot returns with a startup for retail traders

Sir Jack A Lot returns with a startup for retail traders

June 22, 2024
Finnish medtech AIATELLA raises €2M: Co-founder Jack Parker on using AI for preventative cardiovascular screening and easing radiologist burnout

Finnish medtech AIATELLA raises €2M: Co-founder Jack Parker on using AI for preventative cardiovascular screening and easing radiologist burnout

June 4, 2025
As Harvard’s and Yale’s private equity holdings go on sale, buyers can use this technique for 1,000% windfalls. ‘It makes your brain melt’

As Harvard’s and Yale’s private equity holdings go on sale, buyers can use this technique for 1,000% windfalls. ‘It makes your brain melt’

June 15, 2025
7 Payouts You Can Still Get From Old Lawsuits and Settlements

7 Payouts You Can Still Get From Old Lawsuits and Settlements

June 1, 2025
15 Highest Yielding Utility Stocks | Dividend Yields Up To 6.6%

15 Highest Yielding Utility Stocks | Dividend Yields Up To 6.6%

June 11, 2025
Costco Membership Promotion: Free  Gift Card with Membership Purchase +  in Fetch Rewards!

Costco Membership Promotion: Free $50 Gift Card with Membership Purchase + $10 in Fetch Rewards!

June 7, 2025
Stocks sink amid instability in the Middle East, Fed decision

Stocks sink amid instability in the Middle East, Fed decision

0
5 Steps to Apply for Social Security (and When to Do It)

5 Steps to Apply for Social Security (and When to Do It)

0
The 10 Highest Yielding Dividend Champions | Yields Up To 7.2%

The 10 Highest Yielding Dividend Champions | Yields Up To 7.2%

0
Episode 213. “We have a M trust

Episode 213. “We have a $1M trust

0
Sonol warns on fuel supply disruptions

Sonol warns on fuel supply disruptions

0
Ending Subsidies to Amtrak Will Benefit Rail Travelers

Ending Subsidies to Amtrak Will Benefit Rail Travelers

0
Stocks sink amid instability in the Middle East, Fed decision

Stocks sink amid instability in the Middle East, Fed decision

June 17, 2025
5 Steps to Apply for Social Security (and When to Do It)

5 Steps to Apply for Social Security (and When to Do It)

June 17, 2025
How switching broker-dealers led to a tech rethink: Show Me Your Stack

How switching broker-dealers led to a tech rethink: Show Me Your Stack

June 17, 2025
Unlock scaling growth at TC All Stage, and get 0 off for 6 more days

Unlock scaling growth at TC All Stage, and get $210 off for 6 more days

June 17, 2025
G7 leaders try to salvage their summit after Trump’s early exit effectively makes it the ‘G6’

G7 leaders try to salvage their summit after Trump’s early exit effectively makes it the ‘G6’

June 17, 2025
Ending Subsidies to Amtrak Will Benefit Rail Travelers

Ending Subsidies to Amtrak Will Benefit Rail Travelers

June 17, 2025
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Stocks sink amid instability in the Middle East, Fed decision
  • 5 Steps to Apply for Social Security (and When to Do It)
  • How switching broker-dealers led to a tech rethink: Show Me Your Stack
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.