#risk management
13 stories taggedrisk management.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests is not about finding weaknesses. It is about knowing which ones actually matter.

Your AI Is Moving Faster Than Your Security Team Can Follow
Boards want CISOs to greenlight AI projects at speed. The problem is that the tools to track what those AI systems actually touch, and whether they are behaving safely, have not kept up.

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.
Most companies review their suppliers and tick the boxes. Far fewer can actually say how much financial damage a vendor failure would cause them. That gap is the problem.

Your AI risk register is a list, not a plan. Here is what organisations are missing.
Documenting AI risks is the easy part. Knowing who can actually shut the system down when something goes wrong is where most programmes fall apart.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

Why Cybersecurity Teams Are Starting to Speak the Language of Business
Security programmes built around technical checklists often fail to show executives what is actually at risk. A growing push asks teams to tie every control directly to business outcomes.

CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running
Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is stuck in the middle of all three.

CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.
Security chiefs at Appfire, JumpCloud, and BECU describe how they're learning to own risks that finance and operations used to call their own.

Old Risk Frameworks Can't Handle AI. Here Are the New Ones That Try.
From ISO 42001 to NIST's AI RMF and ENISA's layered playbook, a clutch of frameworks is competing to define how organizations govern AI risk — each targeting a different gap.

AI in Cybersecurity: What Security Leaders Actually Need to Know
Dozens of experts weigh in on how artificial intelligence is reshaping both offense and defense — and why the gap between the two may be widening faster than policy can close it.

Webinar Highlights Gaps in Third-Party Risk Management
A critical look at third-party risk programs and their practical failures.