What to do to establish and enforce strong and effective Cyber Risk Governance:

What to do to establish and enforce strong and effective Cyber Risk Governance:

CSA Swiss Chapter Research Topics
October 30, 2025
  • Integrated Governance: Business, Risk, CIO, CTO, CTO, DPO, 2nd LoD, Audit Top Mgmt.
  • Educate repeatedly, cite examples, show risks & impact
  • Control Framework enforced and audited across Third Party Service Providers and all of their Supply Chain
  • Right to Audit and 24h breach notification across Third Party Service Providers and all of their Supply Chain
  • Cyber Threat & Incident Response Management at each level of Third Party Service Providers and all of their Supply Chain
  • Integrated SOCs between you, Third Party Service Providers and all of their Supply Chain
  • Integrated KPC(i)s and real time and continuous monitoring across Third Party Service Providers and all of their Supply Chain
  • Enforce remediation of deficiencies across Third Party Service Providers and all of their Supply Chain
  • Support yourThird Party Service Providers and all of their Supply Chain in contract clauses and controls design / effectiveness

More like this

Agentic AI in Supply Chain Security

Agentic AI is the next big thing in artificial intelligence. Smart computer programs, that can set goals, make decisions, and learn on their own, without always needing a person to tell them what to do. Old systems just follow rules. But AI agents can change and get better as things around them change. According to Gartner, by 2026, companies using agentic AI for security will find and fix supply chain threats 60% faster than those using older security tools.

Read More

Elevating Board-Level Accountability: Cybersecurity Duties and the New BSI Guideline

In today’s interconnected world, the NIS 2 Directive sets out unambiguous obligations for executive management: it makes clear that ultimate accountability for an organisation’s cybersecurity cannot be outsourced to IT teams alone and must remain firmly with the board. Among other things, NIS 2 requires that board members undertake regular, targeted training so they acquire the necessary knowledge and skills to fulfil these duties.

Read More