CISO Mandate 2025: WEF’s Blueprint for Budgets, Boards, and Real Cyber Resilience

The World Economic Forum has a message for every CISO: the job has outgrown its technical shell. Boards must empower security leaders, and CISOs must speak the language of business. The report calls cybersecurity a core business imperative, not a side function. It urges boards to treat the CISO as a strategic enabler of growth, … Read more

CISOs Warn of Imminent Attacks and Mounting Pressure in 2025

Security Leaders Expect Cyberattacks Soon – Proofpoint’s 2025 Voice of the CISO report delivers a stark message: most chief information security officers (CISOs) feel under siege. “76% feel their company is at risk of a material cyberattack within the next 12 months,” the report states. That’s up from 70% last year. More than a third … Read more

SEC Cyber Disclosure Rule Criticized in Recent Reports

We’ve reported extensively on the SEC cyber disclosure rule that requires public companies to submit 8-K filings when they’re hit with cyber attacks. For some reason, the rule has attracted criticism from several media outlets in recent days. Earlier this week Bloomberg Law provided a critical review (under paywall) of how companies have responded to … Read more

CISOs Beware: Derive Declares the “Dying Breed” Era of Cybersecurity Leadership

Chief Information Security Officers (CISOs) might want to polish off their resumes. Cybersecurity firm Derive suggests the CISO role could become a “dying breed.” The Virginia-based company has launched a next-generation platform it claims can replace CISOs with data-driven insights. Derive’s Cyber Risk Quantification (CRQ) platform promises to redefine cybersecurity leadership. The system quantifies cyber … Read more

CISO Liability Concerns Grow with Enhanced Disclosure Rules

Chief Information Security Officers (CISOs) face growing personal liability risks amid increasing cybersecurity threats and stricter regulations. Recent Securities and Exchange Commission (SEC) actions have targeted CISOs individually. For the first time, the SEC charged a CISO with fraud and internal control failures related to cybersecurity. New SEC disclosure rules now require timely reporting of … Read more

×