Redflags. reposted this
London was looking… well Londoney last week, walking back from SASIG Events’ GRC event. An event where it was really apparent that big shifts are taking place in governance risk and compliance. Best practice has always been to focus on measurable outcomes and not just tick box activity. But NIST 2.0 and the cyber resilience bill push this agenda faster. Outcomes > activities → evidence of risk reduction matters, not training completion Behavioural cyber risk → human actions are treated as both risk drivers and risk controls Continuous improvement → maturity assessed over time, not point-in-time Integration of governance, policy and operations → policies must be understood and applied by people in real situations In practical terms: Organisations should no longer be assessed on “delivering” training But must now prove: - People recognise real threats - People behave securely in context - Incidents are reported correctly and quickly - Human behaviour measurably reduces risk This shift is pretty fundamental and is going to need the tooling to measure and intervene right place, right time, right way. Luckily we are ahead of the game :-) Redflags.