Blog

CISOs and CIOs Forge Vital Partnerships for Business Success

CISOs and CIOs are increasingly collaborating to enhance cybersecurity and support business objectives amid rising threats. Key partnerships focus on strategic planning, transparency, and shared goals, with CISOs often reporting directly to CEOs or alongside CIOs. Successful examples include Webster Bank and United Airlines, where alignment fosters innovation and efficient risk management. Open communication and a business-oriented mindset help CISOs avoid being perceived as bottlenecks, allowing for proactive involvement in strategic discussions to mitigate risks effectively.

https://www.csoonline.com/article/3841624/cisos-and-cios-forge-vital-partnerships-for-business-success.html

How CISOs Are Tackling Cyber Security Challenges

CISOs are addressing cybersecurity challenges by focusing on understanding business needs, enhancing organizational resilience, and improving communication with boards. Notable insights from industry leaders at the Gartner Security and Risk Management Summit highlight the importance of protecting key assets while balancing costs. Effective strategies include fostering relationships with board members, ensuring robust backup practices, and redundancy in cloud architectures. In particular, experts stress the need for disaster recovery planning to swiftly manage incidents and the importance of applying governance across all business areas, similar to operational practices in stores.

https://www.computerweekly.com/news/366620535/How-CISOs-are-tackling-cyber-security-challenges

Navigating NIS 2: Mastering Compliance and Risk in a Fragmented Cybersecurity Landscape

NIS 2 Directive Overview: NIS 2 aims to enhance EU cybersecurity by imposing minimum standards and responsibilities on businesses, including sectors like health, banking, and energy. However, fragmented implementation across Member States poses compliance challenges. This webinar addresses these key issues for organizations navigating NIS 2 compliance.

https://www.whitecase.com/insight-webinar/navigating-nis-2-mastering-compliance-and-risk-fragmented-cybersecurity-landscape

NIS2: a Matter for Lawyers, IT Professionals — or Both?

NIS2 emphasizes data security and resilience across sectors. Sebastiaan ter Wee discusses its impact on lawyers and IT professionals, highlighting the need for collaboration. The European focus on privacy under GDPR contrasts with the US's data protection approach. A disconnect exists between cybersecurity and legal departments, which can lead to operational and liability risks. NIS2 broadens responsibilities, urging directors to ensure compliance and understand cybersecurity. Successful integration of legal and IT roles is essential for maintaining effective information security and risk management.

https://www.deloitte.com/nl/en/services/risk-advisory/perspectives/nis2-voor-juristen-iters-of-allebei.html

IT Frustration Costs Companies More Than $100 Million a Year — With Shadow IT the Only User Solution

IT frustration costs large enterprises over $100 million annually due to inefficiencies and unauthorized app use. Employees lose an average of 36 workdays yearly due to complex IT systems, leading them to download unauthorized apps for productivity. The gap between the number of applications employees switch between and the approved apps creates visibility and security issues. Experts emphasize the need for governance in software use and user training to mitigate these problems without stifling innovation.

https://www.cio.com/article/3841636/it-frustration-costs-companies-more-than-100-million-a-year-with-shadow-it-the-only-user-solution.html

The EU’s AI Act: Implications on Justice and Counter-Terrorism 

EU's AI Act, adopted June 2024, regulates AI use, categorizing systems by risk levels. It presents opportunities and risks in counter-terrorism, where AI aids recruitment and security while also raising ethical and human rights concerns. AI may enhance crime prevention through predictive policing but risks bias and privacy violations, especially affecting marginalized communities. Real-time biometric recognition has exceptions for counter-terrorism, potentially infringing rights. The Act lacks sufficient safeguards against misuse in security contexts, thus requiring rigorous enforcement to balance efficiency in justice with democratic freedoms.

https://gnet-research.org/2025/03/10/the-eus-ai-act-implications-on-justice-and-counter-terrorism/

Out of Balance: What the EU’s Strategy Shift Means for the AI Ecosystem

EU's shift in AI strategy aims for innovation and competitiveness, signaling a move away from strict regulations despite concerns about consumer safety. Leaders like Ursula von der Leyen and Macron suggest cutting red tape and fostering AI investment. This could risk the EU's regulatory influence globally, as the US pursues a deregulatory path, while China's focus on AI governance emphasizes political stability over citizen protection. The outcome of this strategic pivot remains uncertain, raising questions about the EU's motivations and capacity to encourage AI development effectively.

https://www.techpolicy.press/out-of-balance-what-the-eus-strategy-shift-means-for-the-ai-ecosystem/

Financial Services at a Crossroads

EU financial services face significant regulatory transformation through laws like the AI Act, GDPR, Data Act, and Cyber Resilience Act, reshaping compliance and risk management. Institutions must integrate these into their governance strategies, balancing innovation with data privacy and cybersecurity requirements. Effective governance and cyber resilience can transform compliance from a burden into a competitive advantage, driving innovation and customer trust.

https://www.timesofmalta.com/article/financial-services-crossroads.1106212

Grading CISOs: Effective Metrics and Personal Growth Strategies

CISOs need effective metrics for performance assessment and personal growth. Key metrics include third-party risk, benchmarking, training, incident response, personnel, and ROI, with several sources offering diverse insights on CISO evaluation. While various methodologies exist, many are deemed overly complex or inadequately comprehensive. Emphasis on relationships and collaboration is essential for effective performance and professional development, alongside a call for mentoring within the CISO community.

https://www.govtech.com/blogs/lohrmann-on-cybersecurity/grading-cisos-effective-metrics-and-personal-growth-strategies

Want to Win in the Age of AI? You Can Either Build It or Build Your Business With It

AI success allows two paths: build AI or use it for business growth. Demand for AI expertise merges tech and business skills. Technical professionals must master tools, while business leaders need to understand industry-specific AI applications. Key skills include prompting AI, knowledge of tools, and combining technical literacy with business acumen for effective implementation.

https://www.zdnet.com/article/want-to-win-in-the-age-of-ai-you-can-either-build-it-or-build-your-business-with-it/

Scroll to Top