May 28 2021

The evolution of the modern CISO

Category: CISO,vCISODISC @ 2:17 pm

The modern CISO

The role of CISO first emerged as organizations embraced digital revolutions and began relying on new data streams to help inform business decisions. As technology continued to advance and became more complex, so too did threat actors who saw new opportunities to disrupt businesses, by stealing or holding that data hostage for ransom.

As the years have gone by and cyberattacks have become more sophisticated, the role of the CISO has had to advance. The CISO has evolved from being the steward of data to also being a guardian for availability with the emergence of more destructive and disruptive attacks. The CISO also must be highly adaptable and serve as the connective tissue between security, privacy and ultimately, consumer trust.

The changing threat landscape

Previous blogs on CISO & vCISO

Virtual CISO - Virtual Chief Information Security Officer (vCISO)

Related latest CISO and vCISO titles

Tags: CISO, Fractional CISO, vCISO


Mar 30 2021

Five signs a virtual CISO makes sense for your organization

Category: CISO,Information Security,vCISODISC @ 11:59 am

Here are five signs that a virtual CISO may be right for your organization.

1. You have a lot to protect

Companies produce more data than ever, and keeping track of it all is the first step to securing it. A virtual CISO can identify what data needs to be protected and determine the negative impact that compromised data can have, whether that impact is regulatory, financial or reputational.

2. Your organization is complex

Risk increases with employee count, but there are many additional factors that contribute to an organization’s complexity: the number of departments, offices and geographies; how data is used and shared; the distribution of architecture; and the life cycle of applications, data and the technology stack.

A virtual CISO offers an unbiased, objective view, and can sort out the complexity of a company’s IT architecture, applications and services. They can also determine how plans for the future add complexity, identify and account for the corresponding risk, and recommend security measures that will scale to support future demand.

3. Your attack surface is broad

For many organizations, potential vulnerabilities, especially those that share a great deal of data within the organization, may not be obvious at first glance. Virtual CISOs can identify both internal and external threats, determine their probability and quantify the impact they could have on your organization. And at a more granular level, they can determine if those same threats are applicable to competitors, which can help maintain competitiveness within your market.

4. Your industry is highly regulated

Organizations in regulated industries like healthcare, finance, energy/power and insurance will have data that is more valuable, which could make them a bigger target for bad actors. Exposure is even more of a concern due to potential noncompliance. Virtual CISOs bring a wealth of expertise on regulatory standards. They can implement processes to maintain compliance and offer recommendations based on updates to applicable rules and regulations.

5. Your risk tolerance is low

An organization without a great deal of sensitive data may have a much greater tolerance for risk than a healthcare provider or a bank, but an honest assessment is important in determining how much risk each organization should accept. A virtual CISO can coordinate efforts to examine perceived and actual risk, identify critical vulnerabilities and provide a better picture of risk exposure that can inform future decisions.

Cybersecurity is growing more complex, and organizations of all sizes, especially those in regulated industries, require a proven security specialist who can address the aforementioned challenges and ensure that technology and processes are in place to mitigate security risks.

Tags: auditing CISO compliance, CISO, vCISO


Mar 10 2021

Boards: 5 Things about Cyber Risk Your CISO Isn’t Telling You

Category: CISO,Security Risk Assessment,vCISODISC @ 5:33 pm
Let's Fix Startup Board Meetings: 5 Sections To Flow | by Dan Martell |  Medium

As Jack Jones, co-founder of RiskLens, tells the story, he started down the road to creating the FAIR™ model for cyber risk quantification because of “two questions and two lame answers.” As CISO at Nationwide insurance, he presented his pitch for cybersecurity investment and was asked:

“How much risk do we have?”

“How much less risk will we have if we spend the millions of dollars you’re asking for?”

To which Jack could only answer “Lots” and “Less.”

“If he had asked me to talk more about the ‘vulnerabilities’ we had or the threats we faced, I could have talked all day,” he recalled in the FAIR book, Measuring and Managing Information Risk.

In that moment, Jack saw the need for a way that cybersecurity teams could communicate risk to senior executives and boards of directors in the language of business, dollars and cents.

Some CISOs are still in the position of Jack pre-quantification – talking all day and delivering lame answers, from the board’s point of view.  Here’s a short guide to what they’re not saying – and how RiskLens, the analytics platform built on FAIR, can provide the right answers.

1.  I don’t really know what our top risks are 

I can ask a group of subject matter experts in the company to vote on a top risks list based on their opinions, but that’s as close as I can get. 

Top Risks is the first report that many new RiskLens users run, and it only takes minutes, using the Rapid Risk Assessment capability of the RiskLens platform. The platform guides you through properly defining a set of risks (say, from your risk register) for quantitative analysis according to the FAIR standard. To speed the process, the platform draws on data from pre-populated loss tables. The resulting analysis quickly stack-ranks the risks for probable size of loss in dollar terms, across several parameters.

2.   I can’t give you an ROI on the money you give me to invest in cybersecurity 

You see, cybersecurity is different from other programs you’re asked to invest in – it’s constantly changing and never-ending. You never really hit a point of success; you just chip away at the problem.  

With Top Risks in hand, RiskLens clients can dig deeper on individual scenarios and run a Detailed Analysis to expose the drivers of risk to see, for instance,  what types of threat actors account for the highest frequency of attacks or what classes of assets account for the highest probable losses. Then they can run the Risk Treatment Analysis capability of the platform to evaluate controls for their ROI in risk reduction.

3.  I can’t really tell you if things are getting better on cyber risk.

 I can show you our progress with compliance checklists and maturity scales, and I hope you’ll assume that’s reducing risk. 

While compliance with NIST CSF, CIS Controls, etc. is good and useful, these frameworks don’t measure performance outcomes in reducing risk – that takes a quantitative approach.  The RiskLens platform can aggregate risk scenarios to generate risk assessment reports showing risk across the enterprise or by business unit, in dollar terms – and to show risk exposure over time. It’s easy to update and re-run risk assessments, thanks to the platform’s Data Helpers that store risk data for re-use. Update a Data Helper, and all the related risk scenarios update at the same time – and so do the aggregated risk assessments.

4.  I can’t help you set a risk appetite. 

I don’t really know how much risk we have and am pretty much operating on the principle that no risk is acceptable.  

Boards should have a strong sense of their appetite for risk in cyber as in all fields, but qualitative (high-medium-low) cyber risk analysis only supports vague appetite statements that are difficult to follow in practice. On the RiskLens platform, a CISO can input a dollar figure for “risk threshold” as a hypothetical, and run the analyses to rank how the various risk scenarios stack up against that limit, making a risk appetite a practical target.

5. I don’t know how to align cyber risk management with the other forms of risk management we do.

Enterprise risk, operational risk, market risk, financial risk—I’ve heard their board presentations in quantitative terms. But cyber is just different.   

Quantification is the answer – reporting on cyber risk in the same financial terms that the rest of enterprise risk management programs employ finally gives the board what it wants to hear on cyber risk management. ISACA, the National Association of Corporate Directors and the COSO ERM framework have all recommended FAIR for board reporting. As an ISACA white paper said,

The more a risk-management measurement resembles the financial statements and income projections that the board typically sees, the easier it is for board members to manage cybersecurity risk…FAIR can enable the economic representation of cybersecurity risk that is sorely missing in the boardroom, but can illuminate cybersecurity exposure.

CISO’s latest titles

Tags: Board Meeting


Feb 24 2021

6 free cybersecurity tools CISOs need to know about

Category: CISO,vCISODISC @ 3:11 pm
Contact DISC

6 free cybersecurity tools for 2021

1: Infection Monkey

Infection Monkey is an open source Breach and Attack Simulation tool that lets you test the resilience of private and public cloud environments to post-breach attacks and lateral movement, using a range of RCE exploiters.

Infection Monkey was created by Israeli cybersecurity firm Guardicore to test its own segmentation offering. Developer Mike Salvatore told told The Stack: “Infection Monkey was inspired by Netflix’s Chaos Monkey.

“Chaos Monkey randomly disables production instances to incentivize engineers to design services with reliability and resilience in mind. We felt that the same principles that guided Netflix to create a tool to improve fault tolerance could be applied to network security. Infection Monkey can be run continuously so that security-related shortcomings in a network’s architecture can be quickly identified and remediated.”

The company recently added a Zero Trust assessment, as well as reports based on the MITRE ATT&CK framework.

Source: 6 free cybersecurity tools CISOs need to know about

Tags: free cybersecurity tools, Infection Monkey


Feb 14 2021

Want to become a CISO

Category: CISO,vCISODISC @ 1:08 pm

CISO role is not only limited to understanding infrastructure, technologies, threat landscape, and business applications but to sway people attitude and influence culture with relevant policies, procedures and compliance enforcement to protect an organization.

#CISO #vCISO
Explore more on CISO role:


May 22 2020

Consider a Virtual CISO to Meet Your Current Cybersecurity Challenges | GRF CPAs & Advisors

Category: CISODISC @ 1:14 am

By: Melissa Musser, CPA, CITP, CISA, Risk & Advisory Services Principal, and Darren Hulem, IT and Risk Analyst The COVID-19 crisis, with a new reliance on working from home and an overburdened healthcare system, has opened a new door for cybercriminals. New tactics include malicious emails claiming the recipient was exposed COVID-19, to attacks on…Read more ›

Source: Consider a Virtual CISO to Meet Your Current Cybersecurity Challenges | GRF CPAs & Advisors

Small- to medium-sized nonprofits and associations are particularly at risk, and many are now employing an outsourced Chief Information Security Officer (CISO), also known as a Virtual CISO (vCISO), as part of their cybersecurity best practices.

vCISO model not only offers flexibility over time as the organization changes, providers are also able to deliver a wide range of specialized expertise depending on the client’s needs.

The vCISO offers a number of advantages to small- and medium-sized organizations and should be part of every nonprofit’s or association’s risk management practices.

Virtual CISO and Security Advisory – Download a #vCISO template!

Three Keys to CISO Success

httpv://www.youtube.com/watch?v=N40pCn77fcE




Tags: vCISO


May 17 2020

CISO Recruitment: What Are the Hot Skills?

Category: CISODISC @ 11:52 am

CISO/vCISO Recruitment

What are enterprises seeking in their next CISO – a technologist, a business leader or both? Joyce Brocaglia of Alta Associates shares insights on the key qualities

What kinds of CISOs are being replaced? Brocaglia says that an inability to scale and a tactical rather than strategic orientation toward their role are two reasons companies are looking to replace the leaders of their security teams—or place them underneath a more senior cybersecurity executive. They are looking for professionals with broad leadership skills rather than a “one-trick pony.”

Today’s organizations want the CISO to be intimately involved as a strategic partner in digital transformation initiatives being undertaken. This means that their technical expertise must be broader than just cybersecurity, and they must have an understanding of how technology impacts the business—for the better and for the worse. And candidates must be able to explain the company’s security posture to the board and C-suite in language they understand—and make recommendations that reflect an understanding of strategic risk management.

CISOs who came up through the cybersecurity ranks are sometimes at a disadvantage as the CISO role becomes more prominent—and critical to the business. Professionals in this position will do well to broaden their leadership skills and credentials, sooner rather than later.

Source: CISO Recruitment: What Are the Hot Skills?



Interview with Joyce Brocaglia, CEO, Alta Associates



The Benefits of a vCISO
httpv://www.youtube.com/watch?v=jQsG-65wxyU



Want know more about vCISO as a Service…






Subscribe to DISC InfoSec blog by Email




Tags: CISO, vCISO


Nov 30 2019

Cybersecurity Through the CISO’s Eyes

Category: CISO,vCISODISC @ 12:52 pm

infographic via Rafeeq Rehman

PERSPECTIVES ON A ROLE

Cybersecurity Through the CISO’s Eyes

Cybersecurity CISO Secrets with Accenture and ISACA

Cybersecurity Talk with Gary Hayslip: Aspiring Chief Information Security Officer? Here are the tips

So you want to be a CISO, an approach for success By Gary Hayslip


Our most recent articles in the CISO category.

Explore latest Chief Information Security Officer titles




Tags: CISO, Gary Hayslip, vCISO


Nov 18 2019

CISO or vCISO? The Benefits of a Contractor C-level Security Role

Category: CISODISC @ 12:40 pm

Read how a virtual chief information security officer (vCISO) can help you uplift a struggling information security program.

Source: CISO or vCISO? The Benefits of a Contractor C-level Security Role

Webinar: vCISO vs CISO – Which is the right path for you?
httpv://www.youtube.com/watch?v=HIvuIIQob7o

CISO as a Service or Virtual CISO
httpv://www.youtube.com/watch?v=X8XSe3ialNk

The Benefits of a vCISO
httpv://www.youtube.com/watch?v=jQsG-65wxyU


Subscribe to DISC InfoSec blog by Email




Tags: vCISO


Oct 08 2019

The Adventures of CISO

Category: CISODISC @ 11:09 am


The Adventures of CISO Ed & Co.

7 Types of Experiences Every Security Pro Should Have

Ten Must-Have CISO Skills

What CISO does for a living

CISOs and the Quest for Cybersecurity Metrics Fit for Business

CISO’s Library


Subscribe to DISC InfoSec blog by Email





Oct 06 2019

A CISO’s Guide to Bolstering Cybersecurity Posture

iso27032

When It Come Down To It, Cybersecurity Is All About Understanding Risk

Risk Management Framework for Information Systems

How to choose the right cybersecurity framework

Improve Cybersecurity posture by using ISO/IEC 27032
httpv://www.youtube.com/watch?v=NX5RMGOcyBM

Cybersecurity Summit 2018: David Petraeus and Lisa Monaco on America’s cybersecurity posture
httpv://www.youtube.com/watch?v=C8WGPZwlfj8

CSET Cyber Security Evaluation Tool – ICS/OT
httpv://www.youtube.com/watch?v=KzuraQXDqMY


Subscribe to DISC InfoSec blog by Email




Tags: cybersecurity posture, security risk management


Apr 23 2019

Ten Must-Have CISO Skills

Category: CISODISC @ 10:23 am

Source: Ten Must-Have CISO Skills – By Darren Death

  • Recommended titles for CISO
  • CISO’s Library
  • CISOs and the Quest for Cybersecurity Metrics Fit for Business
  •  

     

    CISO should have answers to these questions before meeting with the senior management.

    • What are the top risks
    • Do we have inventory of critical InfoSec assets
    • What leading InfoSec standards and regulations apply to us
    • Are we conducting InfoSec risk assessment
    • Do we have risk treatment register
    • Are we testing controls, including DR/BCP plans
    • How do we measure compliance with security controls
    • Do we have data breach response plan
    • How often we conduct InfoSec awareness
    • Do we need or have enough cyber insurance
    • Is security budget appropriate to current threats
    •  Do we have visibility to critical network/systems
    • Are vendor risks part of our risk register


     Subscribe in a reader





    Apr 18 2019

    What CISO does for a living

    Category: CISODISC @ 9:14 am

    What CISO does for a living by Louis Botha

    It’s based on the CISO mindmap by Rafeeq Rehman, updated for 2018 and adding the less technical competencies

    [pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2019/04/CISO-does-for-living.pdf” title=”CISO does for living”]

    Download of What CISO does for a living (pdf)

    CISO MindMap 2018 – What Do InfoSec Professionals Really Do?

     

     

     

    CISO should have answers to these questions before meeting with the senior management.

    • What are the top risks
    • Do we have inventory of critical InfoSec assets
    • What leading InfoSec standards and regulations apply to us
    • Are we conducting InfoSec risk assessment
    • Do we have risk treatment register
    • Are we testing controls, including DR/BCP plans
    • How do we measure compliance with security controls
    • Do we have data breach response plan
    • How often we conduct InfoSec awareness
    • Do we need or have enough cyber insurance
    • Is security budget appropriate to current threats
    •  Do we have visibility to critical network/systems
    • Are vendor risks part of our risk register


     Subscribe in a reader




    Tags: Chief Information Security Officer, CISO


    Sep 19 2018

    CISOs and the Quest for Cybersecurity Metrics Fit for Business

    Category: CISO,MetricsDISC @ 12:52 pm

    By Kevin Townsend

    Never-ending breaches, ever-increasing regulations, and the potential effect of brand damage on profits has made cybersecurity a mainstream board-level issue. It has never been more important for cybersecurity controls and processes to be in line with business
    priorities.

    Reporting Security Metrics to the Board

    recent survey by security firm Varonis highlights that business and security are not fully aligned; and while security teams feel they are being heard, business leaders admit they aren’t listening.

    The problem is well-known: security and business speak different languages. Since security is the poor relation of the two, the onus is absolutely on security to drive the conversation in business terms. When both sides are speaking the same language, aligning security controls with business priorities will be much easier.

    Well-presented metrics are the common factor understood by both sides and could be used as the primary driver in this alignment. The reality, however, is this isn’t always happening

    Using metrics to align Security and Business: Information security metrics

    SecurityWeek spoke to several past and present CISOs to better understand the use of metrics to communicate with business leaders: why metrics are necessary; how they can be improved; what are the problems; and what is the prize?

    Demolishing the Tower of Babel

    “While some Board members may be aware of what firewalls are,” comments John Masserini: CISO at Millicom Telecommunications, “the vast majority have no understanding what IDS/IPS, SIEMs, Proxies, or any other solution you have actually do. They only care about the level of risk in the company.”

    CISOs, on the other hand, understand risk but do not necessarily understand which parts of the business are at most risk at any time. Similarly, business leaders do not understand how changing cybersecurity threats impact specific business risks.

    The initial onus is on the security lead to better understand the business side of the organization to be able to deliver meaningful risk management metrics that business leaders understand. This can be used to start the process for each side to learn more about the other. Business will begin to see how security reduces risk, and will begin to specify other areas that need more specific protection.

    The key and most common difficulty is in finding and presenting the initial metrics to get the ball rolling. This is where the different ‘languages’ get in the way. “The IT department led by the CIO typically must maintain uptime for critical systems and support transformation initiatives that improve the technology used by the business to complete its mission,” explains Keyaan Williams, CEO at CLASS-LLC. “The Security department led by the CISO typically must maintain confidentiality, integrity, and availability of data and information stored, processed, or transmitted by the organization. These departments and these leaders tend to provide metrics that focus on their tactical duties rather than business drivers that concern the board/C-suite.”

    Drew Koenig, consultant and host of the Security in Five podcast, sees the same basic problem. “In security there tends to be a focus on the technical metrics. Logins, blocked traffic, transaction counts, etc… but most do not map back to business objectives or are explained in a format business leaders can understand or care about. Good metrics need to be tied to dollars, business efficiency shown through time improvements, and able to show trending patterns of security effectiveness as it relates to the business. That’s the real challenge.”

    Williams sees the problem emanating from a lack of basic business training in the academic curriculum that supports IT and security degrees. “The top management tool in 2017 was strategic planning,” he said. “Strategic planning is often listed as one of the top-five tools of business leaders. How many security leaders understand strategic planning and execution enough to ensure their metrics contribute to the strategic initiatives of the organization?”

    It is not up to the business leaders to learn about security. “The downfall for many CISOs in the past is believing that business needs to understand security,” adds Candy Alexander, a virtual CISO and president-elect of ISSA. “That is a mistake, because security is our job. We need to better understand the business, so that we can articulate the impact of not applying appropriate safeguards. The key to this whole approach is for the CISO to understand the business, and to understand the mission and goals of the business.”

    for more on this article: CISOs and the Quest for Cybersecurity Metrics Fit for Business

     

     





    Tags: CISO, infosec metrics


    Sep 14 2018

    CISO’s Library

    Category: CISODISC @ 4:38 pm

    CISO’s personal library on managing risk for their organization.





    Tags: Chief Information Security Officer, CISO, ISO


    Jan 09 2017

    The new CISO role: The softer side

    Category: Information Security,ISO 27kDISC @ 12:17 pm

     

    English: Risk mitigation action points

    English: Risk mitigation action points (Photo credit: Wikipedia)

    By Tracy Shumaker

    In order for CISOs to stay relevant in their field today, they must add communication and soft skills to their list of capabilities. Traditionally, their role has been to take charge of IT security. Now CISOs oversee cybersecurity and risk management systems. They must manage teams and get leadership approval in order to successfully implement a system that aligns with overall business goals.

    Speak in a common business language

    The CISO will need to appoint both technical and non-technical individuals to support a risk management system, which requires communication in a language that everyone can relate to. Additionally, senior executives’ approval is required and this will involve presenting proposals in non-technical terms.
    Being able to communicate and having the soft skills to manage people is a challenge CISOs face. For CISOs to reach a larger audience, they need to clearly explain technical terms and acronyms that are second nature and translate the cybersecurity risks to the organization into simple business vocabulary.

    Get the tools to gain the skills

    IT Governance Publishing books are written in a business language that is easy to understand even for the non-technical person. Our books and guides can help you develop the softer skills needed to communicate in order to successfully execute any cybersecurity or risk management system.

    Develop your soft skills with these books >>

    Discover the best-practice cyber risk management system, ISO 27001

    This international standard sets out a best-practice approach to cyber risk management that can be adopted by all organizations. Encompassing people, processes, and technology, ISO 27001’s enterprise-wide approach to cybersecurity is tailored to the outcomes of regular risk assessments so that organizations can mitigate the cyber risks they face in the most cost-effective and efficient way.

    Find more information about ISO 27001 here >>

    Top Rated CISO Books





    Jul 22 2026

    AI Governance Readiness Assessment — Service

    Category: AI Governancedisc7 @ 2:03 pm

    A fixed-scope, fixed-fee, two-week engagement that tells a company exactly where it stands against an AI governance standard — and hands them a prioritized, costed remediation plan they can execute against.

    Auditor-grade certainty in two weeks, not a six-month program.

    Included

    • Kickoff + context intake (60 min) — business model, where AI touches the product, the deadline driving this
    • AI system inventory — a complete catalogue of where AI/ML operates across the product and vendors. Most teams cannot produce this, and every framework starts here.
    • Control-by-control gap analysis against one chosen framework (see lenses below)
    • Risk & impact assessment review — is there a defensible, repeatable process, or a one-off spreadsheet?
    • Evidence review — spot-check that priority controls actually operate and produce proof, not just exist on paper
    • Prioritized remediation roadmap — findings ranked by risk × effort, sequenced, with rough effort/cost estimates
    • Readout call (60 min) walking through the report and the recommended sequence

    Explicitly excluded (these are the follow-on engagement)

    • Writing policies, procedures, or the Statement of Applicability
    • Running the risk or impact assessments on their behalf
    • Implementing or remediating any control
    • The certification audit or acting as certification body
    • Penetration testing or technical security testing of the AI system (separate offer)
    • More than one framework lens (multi-framework is a priced add-on)
    • Revisions beyond one round of clarifications on the final report

    Framework lenses (pick one)

    LensBest fit
    ISO 42001Flagship. Teams pursuing certification or building a formal AIMS. Your strongest proof point.
    EU AI ActAnyone with EU users or customers; deadline-driven urgency
    NIST AI RMFUS teams wanting a framework without a certification commitment
    Colorado AI Act / US stateUS SaaS with consumer-facing AI decisions

    Add-on: a second lens or an ISO 42001 ↔ EU AI Act crosswalk, priced at +50% of the base fee. This is a natural upsell for anyone serving both markets.

    DISC InfoSec                                         DEURA INFORMATION SECURITY CONSULTING

    PAID READINESS ENGAGEMENT

    AI Governance

    Readiness Assessment

    Know exactly where you stand — in two weeks, for a fixed fee.

    Your free assessment gave you a directional score. This gives you the auditor’s-eye version: a control-by-control review of your actual AI governance against ISO 42001, the EU AI Act, NIST AI RMF, or US state law — and a prioritized, costed plan to close the gaps.

    WHAT YOU GET

    →  A complete inventory of where AI operates across your product→  A gap register mapped to every relevant control, with maturity ratings
    →  A remediation roadmap, sequenced by risk and effort, with cost estimates→  A 60-minute readout to walk through it, personally

      FIXED FEE   /   TWO WEEKS

      CREDITED IN FULL TOWARD IMPLEMENTATION

      IF YOU PROCEED WITHIN 90 DAYS

    Led by DISC InfoSec — CISSP, CISM, ISO 42001 Lead Implementer — who took a financial data room platform through its ISO 42001 Stage 2 certification audit. Financial data rooms are the hard mode of compliance; if it holds up there, it holds up for you.

      BOOK A 20-MINUTE SCOPING CALL   →

    Is it a fit?  Built for B2B SaaS and fintech teams with AI in production and a deadline in sight. Not there yet? The free assessment is the better starting

    deurainfosec.com | hd@deurainfosec.com              

                       

    AI Attack Surface ScoreCard

    AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

    Your Shadow AI Problem Has a Name-And Now It Has a Score

    Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

    AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

    Schedule a consultation: info@deurainfosec.com

    InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit

    DISC InfoSec blog | DISC InfoSec Site


    Jul 21 2026

    GRC Engineering: From Evidence Theater to Genuine Assurance

    Category: GRC,Information Securitydisc7 @ 11:14 am

    GRC Engineering: From Evidence Theater to Genuine Assurance

    Most GRC programs are quietly optimized for the wrong outcome. They are built to survive an audit, not to reduce risk. The busiest weeks on the calendar are the ones before an assessor arrives, and the measure of success is a clean opinion rather than a safer environment. That is the gap GRC engineering exists to close.

    The shift is simple to state and hard to internalize: stop spending human effort proving controls work, and start spending it understanding whether they actually do.

    The problem with evidence collection

    Traditional GRC burns most of its energy on a single low-value activity — assembling evidence to satisfy an auditor. Someone pulls a screenshot of an access review, exports a config, snips a ticket, drops it in a folder, and labels it. Multiply that across dozens of controls and hundreds of systems, and you have a full-time job that produces no security whatsoever. It produces a record of security, sampled once, at a moment that may bear no resemblance to how the environment looks the other 364 days of the year.

    The screenshot is not the control. It is a photograph of the control on its best behavior.

    From evidence collection to genuine assurance

    This is the heart of GRC engineering. Instead of humans manually gathering artifacts, you automate collection so it pulls directly from the source system — the IdP, the cloud provider, the ticketing tool, the code repository — continuously and programmatically. When you do that, three things change in ways that compound:

    Assurance gets stronger. You are no longer inspecting one sampled snapshot and hoping it generalizes. You are checking the real thing, continuously, against the live state of the system. A control that passes in January and silently drifts in March gets caught in March, not at next year’s audit.

    Policies start to reflect reality. When the people writing policy can see the actual environment — not a sanitized description of it — the gap between “what we say we do” and “what we do” narrows. Policy stops being aspirational fiction and starts describing an enforceable, observable state.

    The GRC professional stops being a translator. So much of the traditional role is shuttling screenshots between engineering and auditors, acting as a human API between teams that do not speak the same language. Automate that, and the practitioner is freed to do the work that requires judgment: interpreting risk, advising on trade-offs, and pushing for changes that actually move the needle. The job upgrades from clerk to advisor.

    GRC as an insights function

    Here is the reframing that makes all of this strategic rather than merely efficient.

    When your data is continuous and machine-readable, GRC stops being an audit-prep function and becomes an insights function. You can suddenly surface signals that leadership has never had access to before: trends across hundreds of systems, concentrations of risk that only appear when you aggregate, and — the most valuable of all — controls that look perfectly fine on paper but keep failing quietly in practice.

    That last category is where real risk hides. A control marked “implemented” in the register but failing 8% of the time is invisible to a checklist and obvious to a data pipeline. Only continuous, queryable evidence exposes it.

    And in this model, audit readiness stops being the goal. It becomes a byproduct. If you are continuously verifying the real state of your controls and can produce that history on demand, the audit is no longer an event you brace for — it is a report you export. You were ready the whole time, because you were never doing this for the audit in the first place.

    Why this is the real shift

    It is tempting to sell GRC engineering as an efficiency play — fewer manual hours, faster evidence collection, lower cost of compliance. All true, and all beside the point. The efficiency is the least interesting thing about it.

    The interesting thing is that GRC engineering changes what the function is for. It moves the center of gravity from “can we pass” to “are we actually secure, and how do we know” — and it gives you the data to answer that second question with something better than a shrug and a folder of screenshots.


    My perspective

    Having built and audited management systems on both sides of this — the manual, screenshot-driven world and the automated one — I think the framing above is broadly on the right track, but there are two areas where it would benefit from closer scrutiny.

    First: automation raises the stakes on your control design, it does not lower them. When evidence collection was manual, a badly designed control was merely tedious to prove. When it is automated and continuous, a badly designed control fails loudly, constantly, and in front of leadership. That is a feature, but teams underestimate the cultural readiness it demands. The first time a dashboard shows a control failing 12% of the time, someone will ask to “fix the dashboard.” The maturity of a GRC engineering program is measured by how the organization answers that request. Continuous assurance is only valuable if you are prepared to act on inconvenient truths, not explain them away.

    Second: the hardest part is not the pipeline — it is deciding what “passing” actually means. Automating collection is a solved problem; the tooling is mature. The genuinely difficult, irreducibly human work is translating a control objective into a machine-checkable assertion that is neither so loose it is meaningless nor so strict it drowns you in false positives. “All production access is reviewed quarterly” is a policy. Turning it into a query that knows what production is, what access counts, what a valid review looks like, and what to do about the service account that legitimately never gets reviewed — that is engineering judgment, and it does not automate away. It is exactly the work that gets freed up when you stop shuttling screenshots. So the promise of the advisor role is real, but only if the practitioner has the technical fluency to define the assertions in the first place. The role does not just get more strategic; it gets more technical. Both things are true at once, and the people who thrive in this discipline will be the ones comfortable living in that overlap.

    The organizations I have seen get real value from this are, unsurprisingly, the ones operating in high-stakes data environments — where a control drifting silently for a quarter is not an audit finding, it is an incident waiting to be disclosed. When the downside is that severe, continuous assurance stops being a nice-to-have and starts being the only honest way to run the program.

    GRC engineering, done well, is not compliance done faster. It is the point at which the compliance function finally starts telling the truth in real time.

    AI Attack Surface ScoreCard

    AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

    Your Shadow AI Problem Has a Name-And Now It Has a Score

    Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

    AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

    Schedule a consultation: info@deurainfosec.com

    InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit

    DISC InfoSec blog | DISC InfoSec Site

    Tags: GRC Engineering


    Jul 20 2026

    AI Risk Management: AIRM isn’t a Security Problem — It’s Bigger

    Category: AI,AI Risk,Risk Assessmentdisc7 @ 9:23 am

    AI Risk Management: The Discipline Your AI Strategy is Missing

    Most organizations discovered last year just how much AI they were already running. A customer support chatbot here. Copilot in the IDE. Einstein scoring leads in the CRM. A fraud model someone built in 2021 that nobody owns anymore. When I run AI inventories for clients, the number of AI systems they think they have and the number they actually have are never the same — and the gap is where the risk lives.

    That gap is exactly what AI risk management exists to close.

    What Is AI Risk Management?

    AI risk management is the discipline of identifying, evaluating, and treating the risks that AI systems introduce across their entire lifecycle — not just the security risks, but the fairness, robustness, transparency, privacy, and accountability risks that traditional security programs were never designed to catch.

    Here’s the distinction that matters: prompt injection and jailbreaks are the security slice of AI risk. They get the headlines. But the risks that actually put organizations in front of regulators look different. A hiring model that screens out candidates from a protected class. A credit model that’s 95% accurate overall but 60% accurate on the demographic it impacts most. A production LLM that hallucinates a policy your company never had — to a customer, in writing. A model that drifted quietly for eighteen months because nobody was watching, and no one could explain its decisions when a regulator asked.

    None of those are breaches. All of them are business-ending risks in the wrong context.

    The most widely adopted framework for managing this is the NIST AI Risk Management Framework (AI RMF 1.0). It’s voluntary, but it has become the lingua franca of AI risk — cited in contracts, RFPs, executive orders, and increasingly in customer security questionnaires. If you speak NIST CSF, the shape will feel familiar. The AI RMF organizes the work into four functions:

    GOVERN is the persistent layer: written AI principles, a named AI risk owner, approval gates for high-impact deployments, and — critically — someone with the authority to stop a deployment. If nobody in your organization can say “no” to an AI system, you don’t have governance. You have hope.

    MAP establishes context per system: what does this AI actually do, who does it affect, what does “broken” look like, and — the question I find most clarifying in practice — is the decision reversible? A spam filter making a wrong call is an annoyance. A mortgage denial is not.

    MEASURE is where the engineering happens: accuracy evaluated on data slices rather than aggregates, fairness metrics (demographic parity, equalized odds, calibration — which conflict, and choosing among them is a governance decision, not a technical one), robustness against adversarial inputs and distribution shift, and explainability. A model you cannot explain is a model you cannot defend in a regulatory inquiry.

    MANAGE treats what MEASURE surfaces: retrieval-augmented generation for hallucination, monitoring and scheduled retraining for drift, human-in-the-loop for high-stakes decisions, vendor risk reviews for third-party models — and a decommissioning plan for every model, because an unowned production model is the AI equivalent of an unmaintained dependency.

    Layer the regulatory landscape on top — the EU AI Act with its risk tiers and phased enforcement, the Colorado AI Act, NYC’s bias audit law for automated hiring tools, FTC and EEOC enforcement authority — and the picture is clear: AI risk management is no longer optional for any organization deploying AI in consequential decisions.

    My Perspective: What a Proper AI Risk Management Program Actually Buys You

    I led the ISO 42001 AI Management System implementation at ShareVault, a virtual data room platform serving M&A and financial services clients — an environment where the data is deal-sensitive and the tolerance for AI failure is effectively zero. Taking that program through a successful Stage 2 audit taught me what separates AI risk management as a paper exercise from AI risk management as a working system. Here’s what a proper program delivers:

    It converts unknown risk into managed risk. The inventory step alone is worth the engagement. You cannot govern what you haven’t cataloged, and shadow AI — the tools employees adopted without review — is present in every organization I’ve assessed. Visibility precedes control, always.

    It prevents the expensive failures, not just the embarrassing ones. Biased outcomes in hiring or credit carry regulatory penalties, litigation exposure, and remediation costs that dwarf the price of evaluating the model before deployment. Fairness testing during MEASURE costs days. A disparate-impact claim costs years.

    It turns compliance from a scramble into a byproduct. Organizations with a working AI RMF-aligned program aren’t rebuilding from scratch when the EU AI Act’s high-risk requirements apply to them, or when a state law lands, or when an enterprise customer’s due-diligence questionnaire asks how they govern AI. The documentation, the impact assessments, the human oversight mechanisms — they already exist. Frameworks like NIST AI RMF and ISO 42001 map cleanly onto each other and onto the regulations. Build once, answer everywhere.

    It becomes a sales asset. This is the part most organizations underestimate. In B2B — especially financial services — your customers’ risk teams are now asking about your AI. Being able to hand over an AI system inventory, model documentation, and evidence of independent audit doesn’t just pass procurement. It shortens sales cycles. At ShareVault, ISO 42001 certification became a differentiator precisely because the market is full of AI claims and short on AI evidence.

    It lets you move faster, not slower. The counterintuitive one. Teams without governance hesitate on every AI deployment because nobody knows what’s acceptable. Teams with clear approval gates — rigorous review for high-impact systems, lightweight paths for low-impact ones — ship with confidence. Good governance is a throttle, not a brake. Overengineering the process kills it; right-sizing it accelerates everything.

    The organizations getting AI risk management right in 2026 aren’t the ones with the thickest policy binders. They’re the ones who treated it as an operating discipline: inventory what you have, understand what it affects, measure what matters, treat what you find, and build the governance layer that keeps it working after the consultants leave.

    Leadership must treat regulatory security, privacy & AI compliance as a strategic risk management priority. Noncompliance can lead to financial penalties, litigation exposure, reputational damage, and loss of customer trust. Top management should ensure that security, privacy & AI compliance risks are incorporated into enterprise risk assessments, evaluated using risk-based decision-making frameworks, reported regularly to executive leadership and governing bodies, and addressed through mitigation strategies aligned with organizational risk tolerance.

    The ones getting it wrong will find out the way organizations always find out — in production, in public, or in front of a regulator.


    HD is Principal Consultant at DISC InfoSec, a boutique cybersecurity and AI governance consultancy. He holds CISSP, CISM, AICP, ISO 27001 Lead Implementer, and ISO 42001 credentials, and led the ISO 42001 AIMS implementation and internal audit at ShareVault through a successful Stage 2 certification audit.

    If your organization is deploying AI and can’t yet answer “how do you govern it?” — let’s talk. Book a consultation: info@deurainfosec.com

    AI Attack Surface ScoreCard

    AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

    Your Shadow AI Problem Has a Name-And Now It Has a Score

    Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

    AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

    Schedule a consultation: info@deurainfosec.com

    InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

    DISC InfoSec blog | DISC InfoSec Site


    Jul 12 2026

    The adversary that treats your balance sheet as the objective

    Download html file

    AI Attack Surface ScoreCard

    AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do

    Your Shadow AI Problem Has a Name-And Now It Has a Score

    Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

    AIMS and Data Governance – Managing data responsibly isn’t just good practice—it’s a legal and ethical imperative

    Schedule a consultation: info@deurainfosec.com

    InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Security

    DISC InfoSec blog | DISC InfoSec Site

    Tags: Lazarus Group, TTPS


    « Previous PageNext Page »