惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
H
Heimdal Security Blog
Jina AI
Jina AI
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
AWS News Blog
AWS News Blog
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Hacker News
The Hacker News
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Threatpost
S
Securelist
P
Privacy International News Feed
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 聂微东
博客园 - 叶小钗
J
Java Code Geeks
V
V2EX
博客园 - Franky
Spread Privacy
Spread Privacy
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Simon Willison's Weblog
Simon Willison's Weblog
Project Zero
Project Zero
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
C
Cybersecurity and Infrastructure Security Agency CISA
C
CERT Recently Published Vulnerability Notes
Latest news
Latest news
NISL@THU
NISL@THU
罗磊的独立博客
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园_首页
V
Visual Studio Blog

IDC

IDC On the Ground: Inside GITEX AI Europe 2026's Race to Build Sovereign AI Infrastructure IDC Quanta Launch: The 3-Minute Recap The strategy behind today's launch Dashboards Are Dead: The Future of Business Intelligence Lives in the Workflow Introducing IDC Quanta: The Intelligence Fabric of the AI-Enabled Enterprise How Wearables and AI Will Reshape Healthcare Who operates your meeting rooms now: AV, IT, or an AI agent? DX Software in Transition: AI Investment Trends by Sector Japan's AI Supercycle Is Here — Are You Ready to Lead It? Beyond the Data Dump: Why Cybersecurity Metrics Are Failing, and How AI Fixes It From Wait-and-See to All-In: How SMBs Are Rewriting Their AI Story Your AI Platform Knows the Market. Does It Know Your Business, and Can You Trust It with Your Strategy? Start Here: Six Best Practices for Foundational AI Training Physical AI and Robotics Take Center Stage at Computex Taipei 2026 for Semiconductor Vendors Trump's Quantum EO: What It Means for the U.S. Market The sovereignty conversation vendors need to have - but rarely do Q&A: Your Pipeline Conversion Questions, Answered by IDC Analysts The Intelligence Gap Is Widening. Here's What the Data Says. Anthropic, Trump, and Fable 5: The Dispute That Makes the Case for Frontier AI Studies IDC Quanta: The Next Era of Tech Intelligence The $22.5 Trillion AI Opportunity Why the memory market is still tight: what comes next Indonesia PC Market Grows 9.4% in Q1 2026 Despite Component Pressures But Headwinds Are Building The Dawn of Just-in-Time Software Agent Supplier or Featureware: The Choice Every SaaS Vendor Faces Now SpaceX, Cursor, and the Race to Build the Best Coding LLM in the World NVIDIA Becomes #1 in Datacenter Ethernet Switching as 1Q26 Market Surges 39.8% to $15.4 Billion Wi-Fi 7 Captures 44% of Enterprise WLAN Dependent Access Point Revenue as 1Q26 Market Grows 15.9% to Nearly $2.7 Billion AI Is Ready. Enterprises Are Not. Vendors Need to Fix It. Smart Glasses Surge: The XR Market Is Rewriting Its Own Rules WWDC 2026: Apple’s AI Credibility Test AI Is Making MSPs More Efficient. Here’s How to Share in the Gains. The Dark Funnel: How Answer Engine Optimization is Reshaping B2B Brand Visibility Agentic AI Is Breaking Your ROI Model. Here’s How to Fix It When the Question Can’t Wait: How Kyndryl Delivers Enterprise Intelligence at Speed Why the Grey Market Won’t Disappear in the Middle East and Africa: The Case of Notebooks Print, AI, and the expanded buying committee: highlights from IDC’s Print Executive Dinner in London AI in telecommunications: Why it is becoming an infrastructure priority Do AI Markets Face a Circular Financing Problem? Enterprise Applications Will Determine the Answer. From AI pilots to business value: what EMEA digital leaders are doing differently in 2026 Why India’s PC Market Surged 31.1% in Q1 2026 and What Comes Next PC Market Enters Volatile Territory as Memory Shortage Persists Through 2027 Agentic AI Ecosystems: Navigating the Megatrend That’s Reshaping Enterprise Technology Markets Leaning into disruption: How Perficient delivers real outcomes in an AI-first world Google’s Fitbit Air and Google Health: The Software Platform Play That Matters More Than the Hardware Why Fast and Trustworthy Aren’t Mutually Exclusive in AI Research The Middle East Conflict Just Rewrote the Rules of Business Continuity Ecosystem strategy in 2026: turning AI disruption into partner-led growth Worldwide Smartphone Market to Decline 13.9% in 2026 as Memory Crisis and US-Iran War Constrain Growth The AI Supercycle Has Started. Where Does Asia/Pacific Stand? Devices at Google I/O 2026: Android XR Glasses, Googlebooks, and Gemini Intelligence Why Research Alone Isn’t Enough: The Delivery Problem No One Is Talking About Digital Accessibility in the Workplace: From Compliance to Competitive Advantage When Pinocchio Became a Real Boy: Security Platforms Have Grown Up Plotting a Future-Proof Course: How The Resorts Companies Turned a Decade of IDC Partnership into a Competitive Edge European CISO priorities in 2026: AI agents, platformization, and sovereignty Why IDC Directions Is Coming to Hangzhou — and Why You Should Be There Telcos’ Next AI Revenue Play: Monetizing Orchestrated Digital Infrastructure The Workforce Skills Gap That AI Can’t Solve for Itself The Agent Takeover: What Happens When AI Becomes the Primary User of Enterprise Software The AI Answer Gap: Why Fast Answers and Defensible Ones Are No Longer the Same Thing The Market Every Western Executive Should Be Watching. IDC’s CEO Already Is. Ecosystem Strategy in 2026: Why AI Is Rewriting Partner-Led Growth Anthropic, SpaceXAI, and the New Compute Race in AI Navigating a Market Where the Wrong Bet Has Real Consequences Renuka Drummond Named Top 10 Corporate Counsel Worldwide by OnCon Icon Awards From Labor Arbitrage to Platform-Led Outcomes: How Agentic AI Is Rewriting the IT Services Playbook EMEA IT Market 2026 – Q2 Updates: 5 Key Takeaways on AI, IT Spending and Market Trends Japan’s AI Infrastructure Market Is Heading for ¥1 Trillion and Here Is What Comes Next Asia Pacific IT Spending Outlook 2026: How the Middle East War Is Reshaping IT Budgets From Digital Access to Accessibility with AI Enablement From Cost Optimization to Continuity: What IT Buyers Need Now and How Suppliers Must Respond AI as an Organizational Stress Test: What Will Break First in Your Operating Model? Japan’s ¥2.1 Trillion IT Modernization Wave: The Race Has Already Begun Semiconductor Market to Surge Past the Trillion-Dollar Threshold: AI Infrastructure Drives Market Growth Most AI Investments Don’t Deliver Value – Here’s What EMEA Leaders Are Missing Hannover Messe 2026: 7 Insights and 3 Pieces of Advice on Industrial AI, Manufacturing, and the Future of the Factory IDC Directions 2026: The AI Conversation Has Shifted. Here’s How to Catch Up. Coding by Prompt Is Coming to Your Business Units: What CIOs Should Do Next FutureScape 2026: Building Trust, Resilience, and Prosperity in the Agentic Future FutureScape 2026: Charting the Path to Enterprise-Wide Orchestration From Task Execution to Value Creation: What the 2026 Humanoid Robot Half Marathon Reveals About Industry Progress Europe’s AI Story Has a New Problem: It’s Actually Working AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion Digital Sovereignty: Why “Sovereign” Is No Longer Enough FutureScape 2026: Navigating the Crosscurrents of Disruption Huawei and Apple Support China Smartphone Market Resilience as Shipments Decline 3.3% in Q1 2026 The Dirty Secret of AI in ITSM: Why Bad Data Wins Every Time Wholesale telecommunications: How platform models are reshaping the market Beyond LLMs: Why AI Strategy Now Requires Multi-Model, Multimodal, and Multi-Agent Architectures It’s a Data Thing: Retail and Restaurant AI Investments Will Miss the Mark if Not Led by Data Modernization Inference to Overtake Training by 2027 – Why Japanese First Movers Are Betting on Sovereign AI Infrastructure The productivity plateau: Why efficiency gains no longer differentiate Why I’m Excited about IDC Directions 2026 GTC 2026: Workstations enter the sidetop era Dispelling the myth of a silver bullet in sovereign AI MacBook Neo: Apple’s strategic play to disrupt the PC market AI sovereignty risk: A five-step agenda for CIOs Data pricing for AI is being negotiated without a stable model From cyber risk to business risk: How CISOs should engage the board in 2026
Beyond Check-the-Box: Choosing a Security Framework for the AI and Quantum Era
Philip D. Harris, CISSP, CCSK · 2026-07-02 · via IDC

Most organizations still pick a security framework the way they did in 2022: find the biggest name, check the box, move on. That approach hasn’t survived contact with the last three years, three new regulations, a finalized quantum-cryptography standard, and an entirely new AI threat surface later.

The current situation: A framework landscape transformed since 2022

Choosing the right security framework has never been more consequential or more complex. When IDC last published comprehensive guidance on this topic in 2022, the landscape was manageable: a stable set of well-known frameworks and a relatively predictable regulatory backdrop. The intervening years have fundamentally changed both dimensions.

Four structural shifts now define what buyers must navigate:

  • NIST CSF 2.0 (February 2024) introduced a formal Govern function, its first major revision in a decade, elevating cybersecurity from an operational discipline to a board governance obligation and broadening scope to all organizations regardless of size or sector.
  • DORA (EU 2022/2554) became fully applicable in January 2025, imposing mandatory ICT risk management and third-party oversight obligations on approximately 22,000 EU financial entities.
  • PQC standards were finalized: NIST released three post-quantum cryptography standards in August 2024 (FIPS 203, 204, 205), transforming quantum readiness from a theoretical concern to an operational imperative.
  • AI has created a new risk surface: NIST published a draft Cyber AI Profile (IR 8596) in December 2025, extending CSF 2.0 specifically to AI-related cybersecurity risks. Organizations that have deployed AI, particularly agentic AI or LLM-integrated workflows, must now factor AI governance into framework selection.

The wrong framework choice, one that exceeds organizational maturity, understates regulatory obligation, or ignores supply chain exposure, produces worse security outcomes than a well-adopted, properly scoped, simpler framework. The good news: there are strong options. The challenge: the decision is more complex than it was three years ago.

Decision-making criteria and methodology

Security framework selection is a risk management decision, not a technical checklist, requiring input from legal, compliance, finance, operations, and the board. IDC’s 2026 methodology starts with crown-jewel data classification, then splits into regulated and non-regulated tracks, now including universal AI governance and quantum-readiness branches. Key criteria include data classification, regulatory obligations, threat landscape, and AI adoption footprint. Organizations deploying agentic AI face risks that general-purpose frameworks don’t address, while harvest-now-decrypt-later (HNDL) exposure demands cryptographic roadmap planning alongside traditional control mapping.

Additional criteria round out the methodology: third-party risk (CSF 2.0’s Govern function and DORA Article 28 set the compliance floor), PQC readiness (FIPS 203-205 are finalized, with 2030 as a planning horizon), and organizational maturity (smaller organizations should start with CIS Controls IG1 rather than overreaching). Budget discipline favors phased, risk-prioritized roadmaps supported by cyber risk quantification. Finally, multi-framework interoperability and GRC technology support are now prerequisites: manual evidence collection across concurrent regimes such as CSF 2.0, ISO 27001, HIPAA, and DORA is no longer sustainable at scale.

Regulated versus non-regulated organizations: Two different journeys

Regulated organizations

For regulated organizations, the regulator largely determines the framework; strategic focus shifts to execution. Key questions: How can multiple simultaneous requirements (DORA + ISO 27001; HIPAA + NIST 800-53) be satisfied without duplicating evidence work? Which GRC platform best automates cross-framework mapping? How should gap closure be sequenced within the budget? Have ICT third-party providers been assessed against CSF 2.0 Govern, DORA Article 28, and NIST 800-161? Mature organizations typically adopt a “framework stack”: CSF 2.0 or ISO 27001 as backbone, NIST 800-161 for high-risk vendors, plus industry-specific overlays.

Non-regulated organizations

Non-regulated organizations must perform more active analysis, with the right starting point depending on maturity. Early-stage or SMB organizations should adopt CIS Controls v8 Implementation Group 1, 56 safeguards achievable with limited staff, mapped to NIST CSF 2.0 for growth. Mature programs or those facing elevated threat exposure should adopt NIST CSF 2.0 or ISO 27001:2022, both of which include a Govern function that supports board-level accountability and SEC disclosure readiness. All non-regulated organizations, regardless of status, should evaluate the AI Governance and Quantum Readiness branches given their present-day risk implications.

AI and quantum: Two criteria that didn’t exist in 2022

Artificial intelligence: risk surface and governance obligation

AI has added two urgent dimensions to the framework selection process. Offensively, adversaries use LLMs for convincing phishing, automated vulnerability discovery, and direct attacks via model poisoning and prompt injection. Assess whether your framework addresses AI-enabled detection and response. Defensively, organizations deploying AI in production, especially autonomous agentic AI, face authorization, auditability, model integrity, and supply chain risks that general-purpose frameworks don’t address. The NIST Cyber AI Profile (IR 8596, December 2025 draft) extends CSF 2.0 across three risk areas and should serve as a supplementary governance layer. Shadow AI and SaaS-embedded AI remain largely unmeasured exposures requiring dedicated governance tooling.

Post-quantum cryptography: from theory to operational imperative

PQC standards are finalized: NIST published FIPS 203, 204, and 205 in August 2024, with a fourth HQC-based standard selected in March 2025. The harvest-now-decrypt-later threat is present today: adversaries are collecting encrypted data now to decrypt once quantum computing matures, creating real exposure for organizations holding financial, healthcare, or critical infrastructure data. NSA’s CNSA 2.0 mandates 2030 migration for National Security Systems; commercial organizations should treat this as a planning horizon, not a start date. Immediate actions include completing a cryptographic inventory, prioritizing long-lived data systems, evaluating vendor PQC roadmaps, and considering hybrid cryptographic approaches.

Essential guidance for the technology buyer

A well-adopted, properly scoped framework always outperforms a theoretically superior one that exceeds organizational capacity. Buyers should structure stakeholder conversations, including legal, compliance, finance, and the board, around the 10 decision criteria, treating AI governance and PQC readiness as first-order, not future-state, considerations. Conduct a cryptographic inventory now and evaluate AI footprint against the NIST Cyber AI Profile. Address third-party risk per CSF 2.0, NIST 800-161, and DORA Article 28. Favor frameworks with strong cross-mapping, invest in automated GRC technology, and adopt cyber risk quantification for CFO-ready budget conversations. Build a phased, five-year roadmap, closing highest-risk gaps first, and recalibrate annually.

“The right security framework is a critical factor in adequately managing security risks, not only those present today, but also those that could emerge in the future. The 2026 landscape demands that organizations evaluate AI governance and post-quantum cryptography readiness as first-order criteria, not future-state considerations.”Philip D. Harris, Research Director, Cybersecurity GRC Solutions, IDC

Guidance for the technology supplier and services provider

The security framework market is in structural transition, and suppliers calibrated to 2022 are selling into a market that no longer exists. Multi-framework compliance automation is now the dominant selection criterion, making unified control libraries across CSF 2.0, ISO 27001, HIPAA, and DORA essential. Suppliers should build DORA as a named capability, establish AI governance credibility now while the Cyber AI Profile remains in draft, and develop a PQC advisory practice anchored to cryptographic inventory services. Value propositions should be reframed financially for CFO-influenced procurement, while midmarket buyers increasingly favor managed compliance wrappers. Roadmap priorities span CSF 2.0/DORA now, Cyber AI Profile alignment in 2027, and full PQC/EU CRA support by 2030.

Philip D. Harris, CISSP, CCSK

Philip D. Harris, CISSP, CCSK - Research Director, Governance, Risk, and Compliance (GRC) Solutions

Phil Harris is Research Director for GRC Solutions at IDC, where he develops and promotes IDC's point of view on risk, advisory, privacy, and compliance services and software. He conducts research on business strategies and the impact of relevant offerings…