THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, July 01, 2022
All Enterprises that have built an intense current concentration on evaluating and managing corporate risk will continue and accelerate over the next year as a critical focus of corporate management.
FREMONT, CA: In 2021, the pandemic threw unexpected curve balls at corporate managers. The developing situation challenged the accuracy of executive forecasts, the assumptions of corporate risk managers, and the depth of corporate preparation for unforeseen circumstances.
The coming year will herald corporate change, growth, and opportunity. These four trends will probably be of particular interest to corporate risk managers in 2022.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Cybersecurity Receives Intense Attention
When the pandemic occurred, economic losses from cyberattacks skyrocketed. Moreover, heightened awareness of cyber risk increased demand for cyber insurance, so much so that a recent S&P Global Ratings report predicts that insurance rates will rise sharply in 2022, in some cases, even double.
International Data Corporation (IDC) research display that corporations now rank security and compliance as top considerations that management applications to assess whether they will trust potential vendors and other third-party partners, ahead of other concerns such as privacy, sustainability, and diversity.
1. Increased Regulation
Future regulatory changes, compliance dates, and federal priorities – significantly as the government invests vast new sums in infrastructure – will impact risk managers’ compliance priorities and where they need to invest time and resources.
In the coming months, we will likely see new regulations fast-tracked for cybersecurity standards, first in the form of executive orders to government suppliers (which have already started), and secondly, through expansion to other regulated industries via more specialized government agencies.
Court decisions and penalties like government fines will set a precedent, and companies will make moves to evade the newly uttered risks of non-compliance in cybersecurity. This will create a modern cybersecurity floor, a standard by which several companies will have to rise to meet. The level of security to attain mere compliance will be closer to the high-security standard.
2. Third-Party Risk Focus
Forrester forecasts that 60% of security incidents will result from issues with third parties. As a result, supply chain concerns will continue well past the 2021 year-end holidays. But it is not just materials availability and delivery timetables that management is concerned about: Corporations increasingly care about verifying whether their third-party suppliers have the insurance and certifications they claim to have when they initially sign contracts to provide services.
Research has shown that 75% of third parties fail to meet contractual insurance requirements for the average enterprise. So if you’re not managing third-party risk well, you’re risking tremendous liability.
But risk can go above third parties. Fourth-party risks are the hidden risks introduced by your third-party partners. For example, as an organization’s vendors manage relationships with other vendors and partners, they turn fourth parties to the organization.
Corporations can defend themselves considerably from third-party, fourth-party, and “Nth-party” risk by ensuring their third-party risk management systems and checklists are up to par, quizzing third parties about their third-party risk management systems, and keeping in place strong contingency and business continuity plans in case unexpected incidents do occur.
3. Accelerated Adoption of Digital Risk Management
Corporations will embrace and implement next-generation technology at risk. Smart systems will assist and even replace human-led risk management, driven by developments in artificial intelligence and machine learning, as well as easy access to vast amounts of data.
So many organizations are still managing regulatory change manually. Regulatory technology, or Regtech, has swiftly turned mainstream in the financial industry at this point, and it will soon become standard in almost all other businesses. Any business not using technology to manage regulatory compliance and changes is playing the game with a handicap.
Ten years before, it was understandable why so many businesses did not have regulatory technology implemented – the technology was expensive and hard to implement a decade ago. Solutions are available today. However, they can be readily afforded by even small organizations and take just a few days to implement with minimal disruptions. At this stage, the benefits of regulatory technology easily outweigh its costs by a significant margin.
More in News