Risk Management Isn’t an Insurance Decision, It’s a Leadership Decision

Powell Brown, CEO of Brown & Brown, emphasizes that risk management is a leadership responsibility that requires continuous engagement rather than treating insurance as a transactional annual renewal. Effective risk management involves understanding exposures, preparing for diverse scenarios, and integrating risk considerations into business operations to protect organizational assets amid evolving threats like cyberattacks, AI governance challenges, and geopolitical uncertainty. Brown advocates for specialized, advisory-driven risk strategies tailored to each industry to help leaders make informed decisions and strengthen their organizations proactively.

https://www.chicagobusiness.com/crains-content-studio/publishing-partner/ccb-risk-management-insurance-leadership-brown/

7 Ways to Restructure IT for Maximum Productivity

CIOs can boost IT productivity by restructuring around business value, consolidating key teams like security and engineering, and creating cross-functional groups with end-to-end ownership of business capabilities. Emphasizing workflow optimization, domain expertise with mentoring, disciplined tool management, and collaborative problem-solving reduces friction, breaks down silos, and aligns IT efforts with strategic outcomes. Integrating AI thoughtfully into platforms and operations further enhances agility and impact across technology functions.

https://www.cio.com/article/4224624/7-ways-to-restructure-it-for-maximum-productivity.html

The EU AI Act Is a CX Problem Now

The EU AI Act, effective August 2026, extends beyond legal compliance to impact customer experience (CX) operations, as AI is deeply integrated into contact center tools, workflows, and analytics. CX leaders must actively govern AI use by understanding its deployment, risk levels, and ensuring appropriate human oversight to maintain customer trust and meet regulatory requirements. Technology vendors also play a critical role by providing transparency and controls to support AI governance, making compliance a fundamental part of CX strategy and technology decisions.

https://www.cxtoday.com/security-privacy-compliance/the-eu-ai-act-is-a-cx-problem-now-ttecdigital-cs-0062/

Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027

Microsoft will retire SMS-based first-factor sign-in for all Microsoft Entra ID workforce tenants worldwide on February 1, 2027, requiring organizations to migrate users to more secure, phishing-resistant authentication methods such as passkeys, Windows Hello for Business, or FIDO2 security keys. This change aims to eliminate vulnerabilities associated with SMS authentication, including interception and SIM swapping, and avoid disruptions in Microsoft 365 and other Entra-protected services by prompting administrators to update authentication policies and user enrollment processes ahead of the deadline.

https://cybersecuritynews.com/entra-id-sms-sign-in-retirement/

Enterprise AI Desperately Needs a Lifecycle for Context

Enterprise AI applications require disciplined management of business context—such as definitions, policies, and rules—that goes beyond data accuracy and security. Adopting a Context Development Lifecycle, akin to software development practices like version control and testing, can help enterprises define, encode, review, test, publish, and update context consistently, ensuring AI systems remain aligned with evolving business knowledge and reducing maintenance complexity.

https://www.cio.com/article/4223499/enterprise-ai-desperately-needs-a-lifecycle-for-context.html

I Don’t Like Passkeys

Ethan Hawksley critiques passkeys, highlighting that while they offer strong protection against phishing and server breaches, they pose significant risks for personal users, particularly around account lockout and recovery challenges. He points out limitations in hardware keys, reliance on operating system account syncing, fragmented third-party manager support, and usability issues on non-personal devices. Hawksley concludes that passkeys are better suited for enterprise environments and that current alternatives like password managers combined with TOTP remain more practical for individual users.

https://hawksley.dev/blog/i-dont-like-passkeys

Digital Transformation Fails Without This Culture Shift

Akio Ueda argues that successful digital transformation hinges not on technology but on fostering a culture of psychological safety where employees feel secure to take risks and learn from failure. He emphasizes that building a learning organization with supportive relationships, ongoing challenge, and innovation enables continuous adaptation and growth in a rapidly changing AI-driven era. Strategic top-down and bottom-up efforts to embed this positive culture can transform DX into a sustainable competitive advantage.

https://www.cio.com/article/4222873/digital-transformation-fails-without-this-culture-shift.html

AI Failures Are Inevitable. So Is the CIO Getting Blamed.

CIOs are increasingly held accountable for AI failures within their organizations, despite often lacking control over AI vendor selection or visibility into AI agent actions. This accountability gap highlights the urgent need for stronger AI governance frameworks, shared organizational responsibility, and automated controls to manage AI risks effectively. Experts emphasize that while CIOs should lead AI governance efforts, responsibility must be clearly distributed to avoid unsustainable blame on IT leaders alone.

https://www.cio.com/article/4222997/ai-failures-are-inevitable-so-is-the-cio-getting-blamed.html

3 Best Practices to Bridge the AI Strategy and Governance Divide

To bridge the divide between AI strategy and governance, organizations should first move risk tiering upstream by integrating risk assessment into early portfolio and funding decisions to avoid costly oversight later. Second, CIOs should focus on owning observability by building transparent AI inventories and telemetry systems that assign clear accountability to business units rather than IT alone. Third, making technical governance artifacts part of the AI platform—rather than standalone policies—ensures governance is embedded in operational systems, promoting scalable oversight aligned with business objectives.

https://www.cio.com/article/4214897/3-best-practices-to-bridge-the-ai-strategy-and-governance-divide.html

AI Is Now Leading Driver of New Cybersecurity Spending

Artificial intelligence has become the primary driver of new cybersecurity spending, with about 70% of chief information security officers prioritizing AI investments for automating security operations and enhancing identity and access management. Despite overall security budgets growing modestly by 5%, AI-related spending is reshaping strategies as organizations adopt AI to detect software flaws and threats, while expecting it to create new cybersecurity roles rather than reduce headcount.

https://www.cybersecuritydive.com/news/ai-leading-driver-cybersecurity-spending/830418/

Scroll to Top