Post by Todd Edwards, CISSP

Technology Risk Leader | Cybersecurity Assurance | Cloud & Platform Governance | Global Enterprise Environments GRC Expert

Interesting article from the WSJ earlier this month by James Rundle and Angus Loten. Cyber insurers are moving away from evaluating what defenses organizations have in place and focusing more on how fast they can respond when those defenses fail. The driver is AI compressing the time between when a vulnerability is discovered and when it gets exploited, sometimes down to hours. The authors note that when the insurance market starts repricing assumptions, the underlying risk has usually already moved. Shawn Ram, CRO at cyber insurer Coalition, put it plainly: "Point-in-time assessments and annual questionnaires are no longer enough in a threat environment where things can change materially in a matter of hours." What stands out to me is the argument for continuous, engineered governance is now coming from the people underwriting the risk. If you are building or maturing a GRC program, this article has some good building blocks and ideas worth considering. https://lnkd.in/gEtHVZWw #GRC #Cybersecurity #AIGovernance #RiskManagement #OperationalResilience #SecurityLeadership