risk management

Resilience Through Cybersecurity Managed Services

The article discusses how organizations can enhance their resilience by leveraging cybersecurity managed services to address evolving cyber threats. It highlights the importance of partnering with specialized providers to ensure continuous monitoring, rapid incident response, and expert support, enabling businesses to maintain secure and stable operations. This approach helps enterprises improve their cybersecurity posture while optimizing resources and focusing on strategic priorities.

https://www.ey.com/en_fi/insights/managed-services/resilience-through-cybersecurity-managed-services

You Outsourced the AI—but You Still Own the Risk

As enterprises increasingly deploy AI systems developed by third parties, they remain legally and operationally responsible for the risks these systems pose, including discrimination, data mishandling, and customer harm. Despite limited visibility into the models’ training or updates, companies face scrutiny from regulators and courts when adverse outcomes occur, underscoring the need for robust AI risk management and governance even when AI is outsourced.

https://hbr.org/2026/07/you-outsourced-the-ai-but-you-still-own-the-risk

The New AI Trust Architecture: 5 Requirements for Agent-to-Agent Communication

Salesforce AI Research identifies a critical need for a new trust architecture to enable effective, reliable communication and negotiation between autonomous AI agents representing competing organizations. The framework requires five key elements: interpretable standards beyond fixed rules, persistent identity and reputation linked to principals, governance through boundaries rather than exhaustive scripting, structured accountability traceable to humans, and calibrated escalation to balance automation with liability. These principles aim to establish governance, legal, and ethical guardrails before AI agents handle consequential enterprise transactions at scale.

https://www.salesforce.com/blog/new-ai-trust-architecture/

The Business Case for Burning Down Security Debt: A Practical Approach for CISOs

Security debt, defined as long-unresolved vulnerabilities, is growing as organizations discover issues faster than they can remediate them, increasing business risk. CISOs should treat security debt like financial debt by measuring and managing it at the executive level, prioritizing fixes based on exploitability and business impact, focusing on critical applications, and expanding remediation capacity through investment and automation. Aligning security efforts with business risk and establishing clear metrics helps secure executive support and improve risk management outcomes.

https://www.csoonline.com/article/4195135/the-business-case-for-burning-down-security-debt-a-practical-approach-for-cisos.html

Modernizing Legacy IT with AI Without Triggering Regulatory Risk

AI can accelerate the modernization of legacy IT systems, especially in regulated sectors with COBOL-based cores, but the main challenge lies in ensuring compliance and traceability to satisfy auditors and regulators. Key risks include undocumented business rules that AI may incorrectly interpret, leading to regulatory violations under frameworks like DORA, NIS2, and AI Regulation. Successful modernization requires thorough asset inventory, human validation of AI outputs, end-to-end traceability, strict data governance, and oversight of AI use to make transformations defensible and sustainable.

https://www.cio.com/article/4193445/modernizing-legacy-it-with-ai-without-increasing-regulatory-risk.html

What CISOs Should Know About AI Runtime Security

CISOs should focus on AI runtime security, which involves protecting AI systems while they are actively operating to prevent data leaks, compliance breaches, and misuse of AI as an attack tool. Key challenges include rapidly evolving AI technologies, expanding enterprise use cases, and a lack of AI-specific security tools, necessitating zero-trust principles that control identity, access, inputs, outputs, and monitor AI behavior continuously. Implementing these measures requires new cybersecurity tooling and prioritizing investments based on organizational AI risk assessments.

https://www.techtarget.com/searchsecurity/tip/What-CISOs-should-know-about-AI-runtime-security

Your CISO Is Becoming a Safety Architect (Whether They Know It or Not)

The traditional role of the CISO is shifting from defending against external human attackers to managing risks posed by autonomous AI agents operating inside organizations. These AI agents act at machine speed with broad permissions, creating new safety challenges as their failures resemble industrial accidents driven by complexity and unpredictability rather than malicious intent. To address this, CISOs must adopt a safety architecture approach focused on observability and pattern-driven monitoring to ensure reliable and accountable AI behavior within enterprise environments.

https://www.scworld.com/perspective/your-ciso-is-becoming-a-safety-architect-whether-they-know-it-or-not

Forget Data Leakage: Shadow AI’s Real Threat Is Access Control

Shadow AI in enterprises has evolved from a data leakage issue to a complex access control challenge, as AI agents increasingly act autonomously with broad permissions on critical systems. These agents, created rapidly across departments via various tools, can read, write, and modify data using inherited credentials, often without clear ownership or oversight, posing significant security risks beyond traditional controls. Effective governance requires continuous discovery, ownership assignment, scoped access, and automated lifecycle management of AI agents to prevent unauthorized actions and exposure within organizational environments.

https://thehackernews.com/2026/06/forget-data-leakage-shadow-ais-real.html

5 AI Risk Management Frameworks for Shoring up Key Gaps

A new generation of AI-specific risk management frameworks has emerged to address gaps in traditional governance, security, and compliance models, helping organizations identify AI risks, implement controls, and demonstrate responsible AI use. Five notable frameworks include the ISO/IEC 42001 AI Management System, the NIST AI Risk Management Framework, ENISA’s AI Cybersecurity Practices, ISO/IEC 23894 guidance on AI risk, and Google’s Secure AI Framework (SAIF), each focusing on different aspects like governance, lifecycle risk management, cybersecurity, or operational security. These frameworks are complementary and vary in complexity and focus, with organizations advised to select ones that align best with their AI risk challenges and maturity level.

https://www.csoonline.com/article/4185917/5-ai-risk-management-frameworks-for-shoring-up-key-gaps.html

5 Things CIOs Must Do as Sovereignty Becomes a Design Constraint

CIOs are adapting to rising geopolitical tensions and data sovereignty requirements by treating geography as a core architectural constraint, shifting from global efficiency to multi-jurisdiction resilience, and classifying workloads based on sovereignty risk. They are designing platforms for workload portability and exit flexibility, while extending sovereignty considerations to data access at the edge and endpoints, reflecting a broader shift from cost-driven to continuous risk management in enterprise technology strategy.

https://www.cio.com/article/4178779/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint.html

Scroll to Top