No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Thursday, September 18, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond

by TheAdviserMagazine
4 months ago
in Market Analysis
Reading Time: 4 mins read
A A
The Cyber Risk Tides Are Turning: RSAC ‘25 And Beyond
Share on FacebookShare on TwitterShare on LInkedIn


RSAC is the largest cybersecurity conference in the world. Leaders and practitioners across all sectors come together to tackle challenges, all under the maxim of “managing risk.” But what does “risk” actually mean at a security conference? Is it a mythical pursuit? Marketing buzzword? Or generic substitute for “the thing we need to detect/prevent/remediate”?

RSAC Chairman Dr. Hugh Thompson opened this year’s conference by asking: “How do we operate with purpose in a time of great uncertainty?” This simple question is at the core of risk management and marks a radical departure from the security status quo. Where security focuses on “operate,” risk focuses on “uncertainty.” The goal of risk is to make better decisions that maximize opportunity and minimize loss while operating under uncertain conditions. Security and risk intersect by leveraging security data about today’s operational environment to make risk-informed trade-offs.

Where Does Risk Fit In At A Security Conference? Even In Places You Don’t Expect.

Of RSAC’s 535-plus open conference sessions, more than one-third prioritized risk-centric topics. Regulatory compliance still occupies the most space in risk conversations, but there was nearly an even split between strategic/programmatic topics (regulatory, risk management process and governance, and strategic and business risk) and technical risk domains (application security, AI/ML risks, supply chain and third-party risks, threat and vulnerability intelligence, cloud and infrastructure security, and data privacy and security).

 

Key Trends Reshaping The Risk Narrative

As we noted in our RSAC themes blog, efficiency drove vendor messaging. AI agents (hoping to be fully agentic one day), platformization, automation, and intelligence dominated. These RSAC themes, current business trends, and thousands of end-user conversations we’ve held at the intersection of security and risk signal key industrywide shifts, such as:

Technology resilience must be connected to customer services and business value. Regulatory mandates have put operational resilience on the map for financial organizations worldwide, and it’s now influencing global IT practices. To better define and plan for resilient outcomes, risk leaders emphasize connecting technologies with the critical services those technologies enable — even when regulation isn’t forcing their hand. This approach isn’t new, but it’s accelerating, creating stronger partnerships between risk and IT teams and enabling risk teams to better articulate revenue impacts from failures in critical business and technology components. Professional services and business recovery firms highlighted this at RSAC, further underscoring the resilience imperative.
Newer GRC vendors innovate continuous controls monitoring (CCM). The enterprise governance, risk, and compliance (GRC) market has talked about CCM for years. But it required customers to have developer-level expertise to manage API specifications or perform DIY for integrations (spoiler alert: most risk teams don’t have this!). Smaller vendors have leapfrogged established ones by building out-of-the-box integrations that target cloud-native SaaS providers where more “greenfield” customers operate their tech stack. For now, these newer GRC offerings will struggle with enterprise customers who have legacy and on-premises tech footprints with plenty of technical debt to contend with, but they are paving a path to CCM that shows it isn’t just for “high maturity” organizations.
Legal and security teams form an unlikely but critical alliance. This year, RSAC featured many general counsels and heads of legal (30 by our count!) in its GRC and CISO sessions. Legal and security teams are working more closely together, driven by the legal and regulatory landscape. In his session “A Deep Dive Into The New SEC Cybersecurity Disclosure Requirements,” Forrester’s Jeff Pollard explored the legal implications that boards and CISOs must consider. General counsels and CISOs are establishing structured communication channels and regular cross-departmental check-ins to align priorities and share information effectively. This new power couple’s shared goal: Protect their organizations and mitigate risk to the business.
“Supply chain” has become a confusing catch-all in the market. Plastered on conference booths were dozens of references to supply chain risk. Vendors use it to describe a range of capabilities, including AI-driven third-party assessments, fourth- and nth-party discovery, and vulnerability identification in the software supply chain. This broad usage muddles the distinction between managing risks to and from entities versus the security risks posed by components and processes. The result? Buyers are often misled about the solutions.
Cyber risk quantification (CRQ) gains mass appeal among CISOs and vendors. Business-minded CISOs are increasingly seeking ways to articulate operational cyber risk in terms of its material impact on the business. Concurrently, security vendors across various market categories are beginning to integrate CRQ analysis into their products, including vulnerability, attack surface, security posture management, Zero Trust, risk ratings, third-party risk, and GRC technologies. These tools provide essential security telemetry that, when applied through a CRQ model, delivers objective risk insights. Industry efforts to champion open standards, automation, and integrated data models for cyber risk analysis have helped shake off legacy ideas that CRQ is too manual and difficult to accomplish. Now, CRQ is evolving into a core capability of a holistic cyber risk management program.
AI is GRC’s shiny object. GRC is overdue for innovation. AI holds tremendous potential to automate data collection, processing, and reporting, which has been a prolonged pain point for GRC users. While AI promises to drive efficiency and reduce overhead — a core business priority for GRC buyers — scaling AI and agentic AI requires resources to manage workflows and agents, and GRC teams are still struggling with the basics. They’d love to use AI to automatically conduct risk assessments when new assets are identified but are stuck building scalable control testing processes or maintaining accurate asset inventories. To help customers fully embrace AI, GRC vendors need to streamline the fundamentals so that customers have more time and resources to plan for AI-enabled workflows.

RSAC conference sessions, vendor messaging, and customer conversations reflect what we’ve known: Risk is not a compliance checkbox but a dynamic discipline to navigate uncertainty and enable business outcomes. Has it reached critical mass? Not yet. Risk practitioners must continue to drive the conversation by showing up to security conferences, challenging status-quo thinking, and pressuring vendors and presenters alike to think critically about how security exposures and events translate to material business impact. Build proficiency by seeking out technical conference tracks and listening to how security practitioners talk about risk, and showcase your own risk program enhancements at security conferences. As RSAC indicates, security leaders are eager for risk knowledge.



Source link

Tags: cyberRiskRSACTidesturning
ShareTweetShare
Previous Post

Warren Buffett tells WSJ he stepped aside as CEO after feeling old

Next Post

How women in Canada can start investing

Related Posts

edit post
Get Your Zero Trust Initiative Back On Track With Forrester’s Zero Trust RASCI Chart

Get Your Zero Trust Initiative Back On Track With Forrester’s Zero Trust RASCI Chart

by TheAdviserMagazine
September 17, 2025
0

Zero Trust starts like many other strategic initiatives do: An executive (likely the CISO) sets a bold vision to implement...

edit post
Inbound Channel

Inbound Channel

by TheAdviserMagazine
September 17, 2025
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

edit post
Natural Gas: Consolidation Could Set Stage for Breakout Above .20 Barrier

Natural Gas: Consolidation Could Set Stage for Breakout Above $3.20 Barrier

by TheAdviserMagazine
September 17, 2025
0

Henry Hub prices stabilized near $3 after testing annual lows above $2.60 per MMBtu. Weather-driven cooling demand supports gas consumption,...

edit post
Innovation Driving the Nxt Era of Patient Care

Innovation Driving the Nxt Era of Patient Care

by TheAdviserMagazine
September 17, 2025
0

The global urology devices market is expanding rapidly as healthcare systems worldwide respond to rising incidences of kidney disorders, prostate...

edit post
3 Altcoins on Track to Test Critical Resistance Levels This Week

3 Altcoins on Track to Test Critical Resistance Levels This Week

by TheAdviserMagazine
September 16, 2025
0

The altcoin market gained 6% last week but started this week on a cautious note as investors await the ....

edit post
AI And Automation Take Center Stage

AI And Automation Take Center Stage

by TheAdviserMagazine
September 16, 2025
0

BoxWorks 2025 brought together Box customers and partners in San Francisco this past September 11–12 with key announcements that underscore...

Next Post
edit post
How women in Canada can start investing

How women in Canada can start investing

edit post
Hedge fund manager Einhorn sees upside for gold and inflation

Hedge fund manager Einhorn sees upside for gold and inflation

  • Trending
  • Comments
  • Latest
edit post
What Happens If a Spouse Dies Without a Will in North Carolina?

What Happens If a Spouse Dies Without a Will in North Carolina?

September 14, 2025
edit post
California May Reimplement Mask Mandates

California May Reimplement Mask Mandates

September 5, 2025
edit post
Who Needs a Trust Instead of a Will in North Carolina?

Who Needs a Trust Instead of a Will in North Carolina?

September 1, 2025
edit post
Does a Will Need to Be Notarized in North Carolina?

Does a Will Need to Be Notarized in North Carolina?

September 8, 2025
edit post
DACA recipients no longer eligible for Marketplace health insurance and subsidies

DACA recipients no longer eligible for Marketplace health insurance and subsidies

September 11, 2025
edit post
Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a  cheesesteak every 58 seconds

Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a $12 cheesesteak every 58 seconds

August 30, 2025
edit post
Block, Inc. (XYZ): A Bull Case Theory

Block, Inc. (XYZ): A Bull Case Theory

0
edit post
Why Data Beats Depreciation Every Time

Why Data Beats Depreciation Every Time

0
edit post
Jobs report revisions September 2025:

Jobs report revisions September 2025:

0
edit post
XRP Bulls Poised – .12 Break Might Start Strong Upswing

XRP Bulls Poised – $3.12 Break Might Start Strong Upswing

0
edit post
Could Energy Upgrades Pay Back Faster Than Your Bond Fund?

Could Energy Upgrades Pay Back Faster Than Your Bond Fund?

0
edit post
How connected is your firm’s tech

How connected is your firm’s tech

0
edit post
XRP Bulls Poised – .12 Break Might Start Strong Upswing

XRP Bulls Poised – $3.12 Break Might Start Strong Upswing

September 18, 2025
edit post
India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth

India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth

September 17, 2025
edit post
Amazon to invest over  billion in fulfillment and transportation workers to boost pay

Amazon to invest over $1 billion in fulfillment and transportation workers to boost pay

September 17, 2025
edit post
Citi Predicts ETH at ,300 by End of 2025, Citing Investor Optimism Over Activity

Citi Predicts ETH at $4,300 by End of 2025, Citing Investor Optimism Over Activity

September 17, 2025
edit post
Small Leaks, Big Impact: How Tiny Daily Spending Habits Can Quietly Drain (or Transform!) Your Budget

Small Leaks, Big Impact: How Tiny Daily Spending Habits Can Quietly Drain (or Transform!) Your Budget

September 17, 2025
edit post
Nvidia AI chip challenger Groq raises even more than expected, hits .9B valuation

Nvidia AI chip challenger Groq raises even more than expected, hits $6.9B valuation

September 17, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • XRP Bulls Poised – $3.12 Break Might Start Strong Upswing
  • India’s Goldilocks mix of high growth and low inflation is sustainable in the short term: LGT Wealth
  • Amazon to invest over $1 billion in fulfillment and transportation workers to boost pay
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.