惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
云风的 BLOG
云风的 BLOG
M
MIT News - Artificial intelligence
A
About on SuperTechFans
J
Java Code Geeks
量子位
博客园 - 三生石上(FineUI控件)
博客园 - Franky
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
IT之家
IT之家
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

IDC

IDC On the Ground: Inside GITEX AI Europe 2026's Race to Build Sovereign AI Infrastructure IDC Quanta Launch: The 3-Minute Recap The strategy behind today's launch Dashboards Are Dead: The Future of Business Intelligence Lives in the Workflow Introducing IDC Quanta: The Intelligence Fabric of the AI-Enabled Enterprise How Wearables and AI Will Reshape Healthcare Who operates your meeting rooms now: AV, IT, or an AI agent? Beyond Check-the-Box: Choosing a Security Framework for the AI and Quantum Era DX Software in Transition: AI Investment Trends by Sector Japan's AI Supercycle Is Here — Are You Ready to Lead It? Beyond the Data Dump: Why Cybersecurity Metrics Are Failing, and How AI Fixes It From Wait-and-See to All-In: How SMBs Are Rewriting Their AI Story Your AI Platform Knows the Market. Does It Know Your Business, and Can You Trust It with Your Strategy? Start Here: Six Best Practices for Foundational AI Training Physical AI and Robotics Take Center Stage at Computex Taipei 2026 for Semiconductor Vendors Trump's Quantum EO: What It Means for the U.S. Market The sovereignty conversation vendors need to have - but rarely do Q&A: Your Pipeline Conversion Questions, Answered by IDC Analysts The Intelligence Gap Is Widening. Here's What the Data Says. Anthropic, Trump, and Fable 5: The Dispute That Makes the Case for Frontier AI Studies IDC Quanta: The Next Era of Tech Intelligence The $22.5 Trillion AI Opportunity Why the memory market is still tight: what comes next Indonesia PC Market Grows 9.4% in Q1 2026 Despite Component Pressures But Headwinds Are Building The Dawn of Just-in-Time Software Agent Supplier or Featureware: The Choice Every SaaS Vendor Faces Now SpaceX, Cursor, and the Race to Build the Best Coding LLM in the World NVIDIA Becomes #1 in Datacenter Ethernet Switching as 1Q26 Market Surges 39.8% to $15.4 Billion Wi-Fi 7 Captures 44% of Enterprise WLAN Dependent Access Point Revenue as 1Q26 Market Grows 15.9% to Nearly $2.7 Billion AI Is Ready. Enterprises Are Not. Vendors Need to Fix It.
From cyber risk to business risk: How CISOs should engage...
2026-03-25 · via IDC

Cyber risk is no longer just a technical issue, it is a core business concern discussed at the highest levels of the organization. Across EMEA, boards are demanding clearer visibility into risk exposure, regulatory impact, and resilience. This blog explores the latest IDC insights on how CISOs can translate cyber risk into business language, align with board expectations, and strengthen decision-making in an increasingly complex threat and regulatory landscape.

How cyber risk became a board-level business risk

IDC research confirms that cyber risk has become a top board-level concern across EMEA and globally. Boards increasingly recognize that cyber risk is synonymous with business risk, prompting them to ask CISOs to translate the risk of cyber compromise into tangible business and compliance impacts.

As highlighted in IDC’s perspectives, board members are no longer satisfied with technical metrics alone they want to understand how cyber threats could affect organizational resilience, regulatory standing, and overall business continuity.

Cyber risk appetite vs. security investment: Key EMEA trends

Cybersecurity remains the primary barrier to CIO success in Europe, with 16–18% of organizations identifying it as their top challenge. Despite ongoing economic volatility, security budgets are generally protected, though not immune to cuts. IDC’s EMEA Security Tech and Strategies Survey reveals that 33% of financial services organizations kept their security budgets flat, 29% increased them by less than 10%, and 14% decreased them by more than 10%.

Boards are demanding greater clarity on risk acceptance, transfer, and mitigation strategies. A common pitfall is treating security metrics as mere program performance indicators rather than as expressions of risk and compliance management. Boards are now asking, “What is the risk cyber presents to the organization, and how well are we positioned to address it?”

CISO best practices for communicating cyber risk to the board

IDC recommends that CISOs translate cyber risk into financial terms, expressing exposure as realistic cost-of-breach scenarios rather than relying solely on severity labels. Structured exercises should identify which risks threaten financial stability and which are critical for certification or compliance. At the board level, metrics should focus on governance, risk, and compliance trends, answering questions such as: “What are our minimal viable operations? Are we cyber crisis ready? How resilient are we? How long will our business, systems, and production be offline in the event of a severe cyber compromise?”

A robust risk management framework can address 70% of board questions by identifying mission-essential assets, evaluating threats, monitoring controls, and clarifying risk ownership. While boards seek benchmarks and industry comparisons, they are cautioned against adopting a “do $1 more than our competitor” mentality.

IDC advocates for quarterly red teaming and realistic tabletop exercises to educate boards and executives, clarify escalation policies, and better identity and assess third party risk. Boards are also increasingly interested in the impact of AI and emerging technologies such as quantum key encryption and Model Context Protocol (MCP) deployment on organizational risk posture. CISOs should review use cases, implement human-in-the-loop controls, assess data security, and continuously audit AI assets.

Cyber risk and regulation in EMEA: Key insights for CISOs

Regulatory pressure is intensifying in Europe, with frameworks like NIS2, DORA, and the EU AI Act resulting in governance, risk, and compliance (GRC) as the top security technology priority for large organizations. Over 40% of these organizations now place GRC at the forefront, with liability for infringements increasingly assigned to senior management.
In European financial services, cyber security for clients (59%) and internal cyber security (57%) are the primary drivers of risk management investment. But only 43% of CISOs in large UK enterprises report having monthly board engagement, while 48% engage on an ad-hoc basis. IDC recommends establishing regular, structured communication to align risk appetite and investment decisions.

Practical steps to improve cyber risk management and board engagement

To enhance board engagement and risk management, IDC advises quantifying risk in business terms using financial impact, loss scenarios, and regulatory exposure. Cyber risk management should be continuous, using process automation where possible.
Boards must align security investment with risk appetite, and balance resilience, compliance, and operational priorities. Regular, meaningful engagement beyond ad-hoc updates is essential, as is benchmarking against peers while avoiding herd mentality. Integrating GRC platforms to automate reporting, audit, and compliance can support board-level visibility and informed decision-making.

Key takeaways for CISOs and boards in 2026

IDC’s EMEA and worldwide research underscores that effective cyber risk assessment and CISO-board communication require translating technical risk into business impact, quantifying risk appetite, and aligning security investment with strategic objectives.
Boards seek clarity, context, and actionable insights not operational minutiae. CISOs must become influential partners, guiding risk acceptance, transfer, and mitigation in a language the board understands. As regulatory and threat landscapes evolve, disciplined, data-driven communication is essential for resilient, compliant, and secure organizations.

Join the conversation: Deep dive in our upcoming webinar

Want to go beyond the headlines and understand what these shifts mean for your organization? Join our upcoming IDC webinar on May 12 to hear directly from our analysts as they break down the latest EMEA cybersecurity trends, evolving board expectations, and what it takes to translate cyber risk into business impact. Gain practical insights, benchmark your approach, and learn how leading organizations are aligning security strategy with business priorities.

Joel Stradling - Senior Research Director, European Security - IDC

As senior research director for IDC's European Security practice, Joel Stradling leads the content and analyst team for tracking the European security segment. His main focus areas include Zero Trust Network Architecture, Managed Security Services, and Cyber Risk and Resiliency. Stradling has 22 years of experience as an analyst of cyber security, and international managed enterprise network and IT services. He is a regular speaker at major industry conferences talking about security and privacy, Digital Trust and Managed Security Services in B2B enterprise services. Joel is a well-known and highly regarded expert in the industry, offering insight and advice to C-level executives on security technology competitive landscapes and evolving security market segments including: managed security services ZTNA, cloud security, risk and compliance, end point, identity and access management, IT/OT security, secure IoT and 5G, and secure operations.

David Clemente - Research Director, European Security - IDC

Dave Clemente is a Research Director in IDC's European Security practice, with a focus on security services (including managed services and professional services). He is a research professional with more than fifteen years of experience in cyber security, including in think tanks (Chatham House and the International Institute for Strategic Studies), professional services (PwC and Deloitte), and market analysis. Dave is a regular conference speaker and media contributor, and has authored numerous publications on topics including C-suite technology and security priorities, security policy and governance, risk management, and data protection.