Sharpen CISO Logo

AI Cyber Risk Management: Why Your GRC Program Must Evolve

AI spending is about to explode, and most programs aren’t ready for what that means for AI cyber risk management. Your governance model may not survive the pace.

Gartner forecasts AI spending will grow 44% in 2026 alone. By 2029, total AI spending across infrastructure, products, and services will reach $4.7 trillion. Yet, only 15% of organizations report having comprehensive AI governance in place.

That gap is the real risk. Specifically, it’s a governance problem before it’s a technology problem. This article breaks down why, and what Gartner recommends CISOs and security leaders do about it.

The Fragmentation Trap in AI Risk Governance

Here’s the common mistake. As AI adoption accelerates, many security teams respond by building something new. Specifically, they create separate policies, workflows, and tools just for AI risk.

At first, it feels logical. In practice, though, it backfires.

Because these frameworks run in parallel, they fragment cyber-risk management before it even starts. As a result, they slow down risk-informed decisions. Worse, they make it harder for executives to compare AI risks against everything else on the risk register.

So, Gartner’s guidance is clear. Don’t build a second system for AI. Instead, evolve the one you already have.

This mirrors a governance gap boards are already facing elsewhere. The World Economic Forum’s Global Cybersecurity Outlook 2026 found a similar pattern in supply chain oversight: fragmented visibility, not a lack of tools, is usually the real problem.

Six Ways to Evolve AI Cyber Risk Management

Gartner outlines six specific actions across methodology, people, and technology. Together, they keep AI risk inside your existing governance structure, rather than bolted on beside it.

1. Drive AI cyber-risk accountability. Security teams often become the default owner of every AI-related risk. That’s a problem, since business units that deploy AI tools need to own the risks those tools introduce.

In practice, this means updating your cybersecurity charter. It also means requiring business sponsors to formally acknowledge and accept AI risk before deployment, not after.

2. Keep a unified cyber-risk register. Resist the urge to build a separate register for AI risks. Instead, evaluate AI threats with the same methodology you use for everything else.

Why does this matter? Because a single register forces consistent prioritization across the board. As a result, it stops AI from becoming its own isolated conversation, disconnected from broader risk decisions.

3. Adopt a threat-informed approach. Traditional risk registers often list compliance gaps and isolated vulnerabilities. That approach, however, doesn’t scale well against AI-specific threats like prompt injection or model data leakage.

Instead, ground your risk assessments in real adversary behavior. For example, draft AI-specific scenarios, but score them using the same criteria as every other cyber risk.

4. Normalize AI governance in existing policies. Avoid writing a brand-new “AI policy” for every situation. Instead, most AI risks fit naturally into policies you already maintain, like identity and access management.

Create new, AI-specific standards only when nothing existing applies. For instance, model integrity validation is a good example of a case that may need one.

5. Upskill for AI security. You likely don’t need new job titles. Instead, your current GRC professionals are already well-positioned to manage AI risk, with the right training.

So, invest in upskilling. First, partner with HR to fund AI security certifications. Then, add AI-generated attack scenarios to your existing tabletop exercises.

6. Use technology to strengthen, not fragment, your program. New tools supporting AI governance can add real value. However, adding more disconnected tools won’t automatically fix anything.

Before buying something new, therefore, understand what your existing platforms already do. In short, consolidation, not proliferation, is the goal.

Why AI Cyber Risk Management Matters Now

Some 302 cybersecurity leaders were surveyed for Gartner’s 2025 AI Risk Management research. The result was telling: most said their organizations need significant, if not comprehensive, changes to manage emerging AI cybersecurity risks.

Clearly, that’s not a distant problem for AI cyber risk management. Rather, it’s happening right now, as generative AI tools, custom AI applications, and embedded AI features move into production.

Still, technology alone won’t close this gap. That’s because cyber-risk management depends on expert human judgment. Instead, what AI does is help teams process more signals, faster, so people can focus on the decisions that matter most.

For a look at how this plays out for smaller organizations specifically, see how AI is reshaping cyber risk for growing businesses.

The Bottom Line on AI Cyber Risk Management

AI isn’t a side project anymore. Rather, it’s woven into how organizations already operate.

Because of that, your cyber GRC program can’t treat AI as an exception. Instead, it needs to absorb AI risk into the same structure, register, and accountability model you already trust.

So, organizations that evolve their existing governance, rather than duplicate it, will scale far more effectively. In an AI-driven environment, that’s not just good practice. In fact, it’s the only practice that keeps pace.

Source: Gartner, “Cyber GRC Practices Must Evolve to Manage AI Risk,” 27 April 2026 (ID G00846514).

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

Cyber compliance should no longer be a barrier to growth

Proving cyber maturity has become a hurdle to clear before a business can grow. For many organizations, compliance now sits on the critical path of every deployment, every tender, and every audit.

Three everyday situations show exactly how.

  • A project manager needs sign-off from the cyber team before deploying a new application — and that approval can take weeks if the right evidence isn’t already in place.
  • An IT vendor has to prove its security posture during a tender, typically through an ISO 27001 or SOC 2 certification — and one missing document can knock them out of the running.
  • An organization has to prove compliance to regulators, under frameworks like NIS2, DORA, or the CRA — each with its own evidence requirements and its own deadline.

A pace traditional methods can’t follow

Cyberattacks are accelerating. AI is rolling out everywhere. Regulatory requirements keep multiplying, often on the same team, at the same time.

As a result, security teams face more demands with the same limited resources. The frameworks themselves keep stacking, too: NIS2, DORA, and the CRA now overlap for many organizations, each with its own audit cadence and its own evidence trail.

Traditional approaches relied mainly on manual human review, and they simply can’t keep pace anymore. Spreadsheets, one-off audits, and point-in-time certifications suited a slower, more predictable risk environment — not continuous, AI-accelerated change.

Yet when companies innovate at the speed of AI, proving cyber compliance has to move at that same speed. Otherwise, compliance stops protecting the business and starts holding it back.

SharpenCISO: an augmented GRC platform

That’s exactly why we built SharpenCISO.

Our platform automates up to 80% of the manual work needed to demonstrate cyber compliance and manage risk in real time. This isn’t about removing people from the process. It’s about freeing your team from repetitive evidence-gathering, so their expertise goes where it creates the most value: judgment calls, risk decisions, and strategic conversations with the business.

Concretely, SharpenCISO automates the collection of cyber maturity evidence for four audiences at once:

  • Regulators, across frameworks like NIS2, DORA, and the CRA
  • Internal security (SSI) teams, who need continuous visibility instead of a once-a-year snapshot
  • Certification bodies, for standards like ISO 27001 or SOC 2
  • Client tenders and RFPs, where proof of security maturity now shapes business outcomes and risk decisions

One evidence base. Four audiences. No duplicated effort.

Turning cybersecurity into a competitive advantage

That’s our ambition. Proving cyber maturity should never slow an organization down.

Done right, it does the opposite. It builds trust with regulators and customers. It speeds up projects instead of gating them. And it opens doors — deals, partnerships, and markets — that used to stay closed until the paperwork caught up.

Compliance shouldn’t be the brake. It should be the accelerator.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement #SecureAI #AISecurity

Is cyber risk data reliable enough for executive committee decisions?

Cyber risk now sits on nearly every board agenda. But does the data behind those conversations actually reflect what’s happening inside the information system? That’s the question every CISO eventually has to answer in front of their ExCo or board.

Three figures from the latest OpinionWay barometer for CESIN caught our attention:

  • 92% of companies rank cyber risk among their top 5 business risks.
  • 29% review it only once a year, at ExCo or board level.
  • 61% review it several times a year, at the same level.

So cyber risk has clearly become a strategic business risk, not just a technical one. And that status comes with a consequence: CISOs are now expected to support real strategic decisions in the boardroom, not just report on past incidents.

Cyber risk earned its seat at the table — the data hasn’t caught up

Financial data reaching the board goes through audits, standardized formats, and controls built over decades. Cyber risk data, in most organizations, still doesn’t.

This gap isn’t just a reporting habit. It shows up in the decisions that follow, too. For the first time in three years, the share of French companies allocating 5% or more of their IT budget to security actually fell in 2025, down from 48% to 42% (CESIN, 2026). When the data behind that decision is a stale snapshot, the budget that follows gets calibrated on old information — not on the risk as it stands today.

A question that keeps coming up with CISOs

Here’s what we keep hearing in our conversations with CISOs: does data consolidated at a few key moments in the year actually reflect the operational reality of the information system? And is that data reliable enough to inform a CISO’s strategic decisions at ExCo or board level?

In many organizations, teams still pull that data together manually, from scattered tools, just before the meeting. By the time it reaches the board, it’s already a snapshot of where things stood weeks earlier — not where they stand today.

At SharpenCISO, we’re convinced the real issue isn’t measuring more often. It’s building on more reliable data in the first place. Reporting frequency without data quality just means reporting the wrong picture, more often.

What “reliable” actually means here

Reliable doesn’t just mean accurate at the moment of collection. It means current when it reaches the decision-maker.

Take third-party risk as an example. Only 23% of French companies monitor their attack surface continuously — most still rely on a contract clause, reviewed once and rarely revisited. That’s a governance choice as much as a technical one, and it’s exactly the kind of gap that a single point-in-time report can hide.

The same shift is already happening elsewhere in security. The share of organizations that assess their AI tools before deployment nearly doubled in a year, from 37% to 64% (WEF, 2026). Continuous verification is becoming the norm for AI risk. Cyber GRC reporting for the board needs to make the same move — from a periodic snapshot to a live picture.

So, what’s your confidence level?

We’re curious: how much confidence does your organization place in its cyber GRC data when it’s time to make a decision at ExCo or board level?

CISOs, does the data you present match what’s really happening on the ground? And board members, do you feel you’re deciding on today’s risk, or on last quarter’s? Tell us in the comments — we’d like to hear how this looks from where you sit.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

Cybersecurity is becoming a governance issue. It’s now a matter of resilience and risk control, not just technical defense. The latest OpinionWay barometer for CESIN confirms this shift: three regulatory frameworks now dominate corporate priorities in France.

Overall, 59% of French companies say they’re in scope for NIS2, 32% for DORA, and 30% for the CRA (CESIN, 2026). But those averages hide a sharp divide by company size. That divide is where the real story is.

1. NIS2: the new center of gravity

70% of large enterprises rank NIS2 as a top priority. Among small and mid-sized businesses (TPE/PME), that figure drops to just 44%.

The gap makes sense. Large groups already went through NIS1, so they know the drill: risk management, incident notification, board-level accountability. Smaller structures, on the other hand, are still discovering the real scope of the requirements — including obligations that reach into their supply chain, not just their own systems.

2. DORA: operational resilience at the heart of finance

DORA remains a strong priority for large enterprises, at 38%. That number reflects its scope: financial institutions and their critical ICT providers.

Resilience testing, third-party risk management, governance: DORA demands a rigorous discipline. And because it reaches ICT providers as well as financial firms directly, its impact spreads well beyond the finance sector itself.

3. The CRA: securing products by design

With the CRA, the logic shifts. Security has to be built in from the start, not bolted on later. That’s the core of Secure by Design and Secure by Default.

Large enterprises are ahead here too: 37% are already anticipating the CRA, compared to just 23% of mid-sized companies (ETI). That 14-point gap matters, because the CRA’s core requirements — software bills of materials (SBOM) and patch management — take real time to operationalize. Waiting until the deadline isn’t really an option.

What sets the top-performing organizations apart

We’re convinced the organizations that progress fastest will share three habits:

  • They pool controls and reference frameworks across regulations, instead of running separate compliance programs for NIS2, DORA, and the CRA side by side.
  • They prioritize action by actual risk level, not by how easy it is to produce evidence. The easiest compliance box to tick isn’t always the risk that matters most.
  • They give cyber GRC teams the tools to industrialize assessments, produce reliable evidence, and manage several regulations at once — without multiplying the effort every time.

This isn’t a small opportunity. As we discussed in an earlier post, 76% of CISOs already say that managing multiple frameworks in parallel hurts their ability to stay compliant. Convergence isn’t a nice-to-have; it’s how compliance stays sustainable.

Turning compliance into a lever, not an obligation

That’s precisely the approach we’re building with SharpenCISO, our AI-native GRC platform, automated in real time.

Our goal is simple: turn compliance into a genuine lever for managing cyber risk — one that durably strengthens security posture — instead of a string of regulatory obligations to tick off, one framework at a time.

So, what have you put in place?

We’re curious: what have you put in place to improve the performance and impact of your cyber GRC teams?

Are you still running NIS2, DORA, and the CRA as separate tracks, or have you already started pooling the effort? Let us know in the comments.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA