Five Takeaways for Tech From Draghi’s Speech

Five takeaways from Draghi's speech include: 1) Major telecom reforms (Digital Networks Act) are expected soon; 2) A call for deeper reforms to GDPR, which has increased data costs for EU firms; 3) A request to pause high-risk AI Act rules; 4) Advocacy for “Buy European” public procurement policies to support local tech; 5) Suggestions for easier merger regulations in Europe to promote industry consolidation. Overall, Draghi emphasized the need for impactful governance and simplification to boost European competitiveness. https://www.euronews.com/next/2025/09/17/five-takeaways-for-tech-from-draghis-speech

How CISOs Make the Business Care About Cybersecurity

CISOs share strategies to engage businesses in cybersecurity without fear tactics. Key points include aligning security with business goals, demonstrating value without breaches, careful insurance documentation, leveraging soft skills, creating effective awareness training, and emphasizing health and delegation. The conversation around security is evolving into a focus on business resilience, encouraging CISOs to build trust and foster strategic partnerships. https://cisoseries.com/how-cisos-make-the-business-care-about-cybersecurity/

10 Red Flags Your CISO Is Just Filling a Seat

Weak CISOs often disguise their ineffectiveness through jargon, focusing on tasks rather than outcomes and tools over strategy. Signs of inadequate leadership include low visibility in strategic discussions, high team turnover, fear-driven management, lack of influence across departments, slow incident responses, and no talent development. Strong CISOs should align security with business goals, actively communicate clarity, and integrate security practices throughout the organization, ensuring risk reduction translates into measurable business outcomes. https://www.forbes.com/councils/forbestechcouncil/2025/09/17/10-red-flags-your-ciso-is-just-filling-a-seat/

When It Comes to Breaches, Boards Can’t Hide Behind CISOs Any Longer

91% of security professionals assert that boards, not CISOs, hold ultimate accountability for cybersecurity breaches. A recent survey indicates 56% believe board members should face sanctions for serious incidents, highlighting a shift in responsibility as cybersecurity increasingly enters C-suite discussions. Regulations like NIS2 and DORA suggest senior managers could be held liable, but accountability remains vague. For effective governance, boards require complete risk information from security professionals to make informed decisions. https://www.tripwire.com/state-of-security/breaches-boards-cant-hide-behind-cisos

CIOs Set Talent Strategies for a Future-ready IT Workforce

CIOs focus on skills training for IT workforce readiness amidst AI advancements. They aim to blend technical fluency with curiosity and adaptability. Emerging roles require collaboration across disciplines, driving a shift from specialization to a focus on holistic competencies. Companies like Vanguard and Harvard Business School emphasize continuous learning and adaptability to prepare for evolving tech landscapes.

https://www.cio.com/article/4051056/cios-set-talent-strategies-for-a-future-ready-it-workforce.html

The Pattern of Early Adoption of Security Tools

CISO Series discusses challenges in selling cybersecurity products, noting that large companies typically adopt new tools first, despite being risk-averse. Startups struggle to bridge the gap to smaller clients. Key points include the importance of defining target markets, understanding product integration, and the need for ease of use and managed services. Insights also highlight the influence of major industry players like Gartner on adoption trends, and the concept of a “security poverty line” affecting SMBs. The episode encourages defining customer needs and adapting product offerings accordingly to foster successful market entry.

https://cisoseries.com/the-pattern-of-early-adoption-of-security-tools/

CIO Interview: Sebastiaan Kalshoven, ASN Bank

Sebastiaan Kalshoven, CTO of ASN Bank, balances IT transformation with personal commitments, notably coaching young swimmers. Tasked with major strategic changes, he focuses on unifying the bank's brand and integrating IT systems while enhancing customer experience. Having a background in cloud technology and agile practices, he emphasizes risk management and adaptability. Kalshoven advocates for an engineering culture and collaboration to ensure smooth transitions in technology, aiming for a more flexible, modern IT infrastructure in response to evolving business needs.

https://www.computerweekly.com/feature/CIO-interview-Sebastiaan-Kalshoven-ASN-Bank

Security Posture Management (SPM)

SPM: Approach assessing, improving org's cybersecurity. Evaluates vulnerabilities, threats, compliance. Integrates tools, policies for proactive risk management, ongoing monitoring. Enhances overall security resilience.

Cyber Assessment Framework (CAF)

CAF: Framework for assessing cybersecurity risks, guides organizations in managing and improving cyber posture, includes best practices, risk management, and compliance measures.

CISO’s Guide to Security Vendor Consolidation

CISOs face complexity from numerous cybersecurity vendors, leading to vendor consolidation for operational, strategic, financial, and security benefits. Benefits include reduced management complexity, improved efficiency, lower costs, and enhanced security. Challenges involve vendor lock-in and potential coverage gaps. To consolidate, CISOs should evaluate needs, create a vendor inventory, assess overlaps, and consider costs, reputation, support, features, and contract terms. Each organization’s needs differ, making tailored assessments crucial for effective consolidation.

https://www.techtarget.com/searchsecurity/tip/CISOs-guide-to-security-vendor-consolidation

Scroll to Top