Skip to main content

6 bold moves to master cyber risk management in a policy-driven economy

Cyber risk is no longer driven by threats alone. Policy shifts, regulatory scrutiny, and economic pressure are forcing CISOs to evolve cybersecurity operating models to deliver measurable resilience, governance, and enterprise risk performance.

Cyber risk management in a policy-driven digital economy

Cyber risk isn’t just a security issue anymore. It’s a policy, economic, and governance decision.


Cyber risk is being shaped by forces that extend well beyond traditional security boundaries. Regulatory expectations are tightening—with mandates like the EU’s AI Act, GDPR, DORA, and NIS2, alongside a growing list of state-level laws in the U.S.—and policy environments are shifting more frequently as economic conditions place greater scrutiny on how security risks are managed and justified. At the same time, organizations are becoming more digitally dependent, meaning disruption directly affects operations, customer experience, and financial performance, among other business imperatives.

For CISOs, this creates a different kind of operating environment. The challenge is no longer limited to defending systems or responding to incidents. It is about ensuring cybersecurity can stand up to regulatory scrutiny, economic pressure, and real operational stress.

This dynamic is transforming the evaluation of cyber risk and the performance of security programs into enterprise capabilities, rather than merely technical functions.

What is cyber risk management in a policy-driven economy?

Managing cyber risk in a policy-driven economy refers to the ability to monitor and address cybersecurity threats, regulatory requirements, and economic pressures as an integrated system, while ensuring that security performance, governance, and resilience are aligned with enterprise risk and business operations.

Reframe cyber risk as an enterprise governance issue - not just a security function

Cybersecurity is increasingly being used as a proxy for how well an organization can operate under pressure. It is no longer viewed solely through the lens of controls or compliance, but as an indicator of operational continuity, leadership effectiveness, and enterprise resilience.

How are boards and executives redefining cyber risk expectations?

Boards are not asking new questions simply because threats exist—they have always assumed that. What has changed is how cyber performance is interpreted. It is now used to assess whether the organization can withstand disruption, maintain trust, and continue operating in uncertain conditions.

This shift is visible at the executive level. A large majority of CEOs now identify cybersecurity as a top governance concern, and many are increasing investment as AI adoption and digital dependence accelerate. Cyber risk is no longer treated as a technical issue delegated to IT—it is evaluated alongside growth, financial exposure, and strategic risk.1

For CISOs, this means the conversation has moved. It is no longer enough to explain how systems are protected. The expectation is to demonstrate how the organization performs when those systems are tested.

Following are six bold moves designed to help CISOs and their teams navigate the complexities of the modern threat landscape and build a future-ready cybersecurity program.

Move #1: Align cybersecurity with policy, regulation, and enterprise risk management

How can we leverage AI securely?

AI is a double-edged sword: it accelerates the speed and scale of cybersecurity threats while also offering powerful tools for defense. The challenge is that many existing security models are too manual to counter AI-powered attacks effectively. To win this arms race, leaders must strategically apply AI security to automate processes and enhance threat detection.

However, deploying automation without sufficient oversight creates its own AI risk. The new imperative is to treat AI not as a silver bullet but as a force multiplier that requires strong governance. This involves building a hybrid AI-human workforce where AI agents handle routine tasks like network traffic analysis and penetration testing, freeing up human experts to focus on strategic threat management.

In response, 67% of CEOs are increasing their investment in cybersecurity.2 A successful strategy ensures that these investments are governed by intentional systems that build trust and ensure human oversight, turning AI into a reliable pillar of your overall defense program.

What do new regulations require beyond traditional compliance?

Modern regulatory expectations require organizations to show that they can:

  • Withstand operational disruption
  • Recover in a structured and measurable way
  • Manage third-party and ecosystem risk continuously
  • Demonstrate control effectiveness under real conditions

This represents a fundamental shift. Compliance is no longer about proving that controls exist. It is about proving that those controls perform consistently and can be relied upon during periods of stress.

As policy evolves, cybersecurity becomes more tightly integrated with enterprise risk management. CISOs are expected to align their programs not only with technical standards, but with how the business manages uncertainty, regulatory exposure, and long-term resilience.

Move #2: Build toward cyber resilience to withstand operational and economic pressure

What does it mean to be truly resilient?

For years, cybersecurity was focused on prevention—building walls to keep attackers out. In today's landscape, this approach is no longer sufficient. True resilience assumes a breach will happen and focuses on minimizing the business impact. The real challenge is developing a robust capability for faster detection, coordinated response, and disciplined recovery.

This requires a shift in mindset and strategy. Instead of focusing solely on tactical responses, organizations must engage in proactive planning that aligns security objectives with broader business goals.

A comprehensive resilience plan should:

  • Identify critical assets and business processes to prioritize protection and recovery efforts.
  • Develop detailed response playbooks for various scenarios, from ransomware attacks to data breaches.
  • Regularly test and drill these plans to ensure leaders and teams can perform under pressure.

With the global average cost of a data breach reaching $4.88 million in 2024, proving performance during a crisis is a critical measure of a successful risk management program.

Why does resilience often break down in real-world execution?

The issue is not a lack of planning. It is a lack of consistency.

When incidents occur, outcomes often depend on coordination across teams, clarity of ownership, and the ability to make decisions quickly amid uncertainty. As environments become more complex, these variables become harder to control.

This is where the gap “knowing” and “doing” appears. There is broad agreement on the importance of resilience, but less alignment on how to operationalize it. As a result, resilience is often understood conceptually but not executed reliably.

As disruption becomes more visible to leadership, this gap becomes difficult to ignore. Resilience is no longer an internal benchmark—it is an externally scrutinized capability.

Move #3: Secure the extended enterprise to address third-party and ecosystem risk

How can we manage risk from third-party connections?

Your organization is only as secure as its weakest link, and that link often lies outside your direct control. Third-party connections—from vendors and suppliers to software dependencies—are a primary source of cyber risk. Yet, many organizations still rely on periodic, point-in-time assessments that fail to capture the dynamic nature of the threat landscape.

The solution is to move toward a continuous resilience model across the entire ecosystem. This involves embedding security requirements into the foundation of your partnerships and holding vendors accountable. Proactive leaders are demanding greater transparency through measures like a Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM). This aligns with emerging regulations like the Digital Operational Resilience Act (DORA), which mandates a more rigorous approach to third-party risk assessment.

By viewing regulations as an opportunity to strengthen your foundation, you can prevent external risks from causing internal disruption.

How can cybersecurity evolve beyond periodic vendor risk assessments?

Traditional approaches to third-party risk rely heavily on periodic assessments and point-in-time validation. These methods create a sense of control, but they do not reflect how risk actually evolves across interconnected systems.

Modern ecosystems are dynamic. Dependencies change, integrations expand, and new exposures emerge continuously. Static assessment models are not designed to keep up with that pace.

Policy developments are reinforcing the need for change. Organizations are increasingly expected to demonstrate not just awareness of third-party risk, but active oversight and accountability.

This shifts third-party risk from a compliance exercise to a core component of cyber resilience. It requires continuous visibility into the ecosystem and a more integrated approach to managing how external dependencies influence internal risk.

Move #4: Modernize the cybersecurity operating model to scale performance

How can CISOs close the cybersecurity skills gap?

The cybersecurity skills gap is not just a staffing problem; it's an operating model problem. Many security programs are too manual, siloed, and dependent on the heroic efforts of individual experts. This makes performance unsustainable and difficult to scale as business complexity grows and pressure for ROI increases.

Modernizing your security operating model is key to closing this gap. This means redesigning roles and processes to maximize human talent, supported by automation and AI.

  • Automate routine tasks to shift experts from low-value transactions to high-value analysis and strategy.
  • Break down organizational silos between security, IT, and business units to create shared responsibility for cyber protection.
  • Build a hybrid AI-human workforce where AI agents augment human capabilities, enabling teams to become smaller, more agile, and highly productive.

By redesigning work around capabilities instead of static job titles, you can build a scalable and efficient security function that drives business value.

Why can’t traditional security models scale with complexity and demand?

Traditional models were not designed for environments where:

  • Signals arrive continuously and at high volume
  • Systems are constantly evolving
  • Decisions must be made quickly and consistently
  • Governance must be demonstrated in real time

As these conditions become the norm, manual and fragmented approaches become increasingly difficult to sustain.

This is why the conversation is shifting. The challenge is not simply to add more people or more tools. It is to design an operating model where automation, expertise, and governance are integrated in a way that produces reliable outcomes.

Organizations that make this shift are better able to scale performance without increasing fragility.

Move #5: Strengthen identity security as the control plane for enterprise risk

Why is identity management central to modern security?

Many organizations remain trapped in a legacy mindset, viewing identity as a simple access issue. In the modern, perimeter-less enterprise, identity is the new control plane. The challenge is to shift toward a modern, identity-first security model that treats identity as the central pillar of a Zero Trust architecture.

This approach recognizes that every user, device, and application must be authenticated and authorized before accessing resources.

An identity-first model is critical for:

  • Securing remote and hybrid work by verifying identities regardless of location.
  • Protecting against sophisticated attacks like phishing and credential theft.
  • Enabling secure business growth by providing a flexible and scalable foundation for new technologies and applications.

Adopting modern security frameworks centered on identity is no longer optional—it is the foundation of effective cybersecurity in a distributed, cloud-first world.

Where does identity still create unmanaged exposure across the enterprise?

In many organizations, identity is still managed as a collection of systems rather than as a unified control plane. Access is granted across multiple environments, ownership is distributed, and governance often operates on cycles that don’t reflect how quickly roles and privileges change.

This creates gaps between policy and practice.

As regulatory expectations evolve, identity becomes more visible as a governance issue. It is not enough to enforce access; organizations must demonstrate that access is continuously controlled, monitored, and aligned with business activity.

Treating identity as a system rather than a process allows organizations to reduce exposure and strengthen resilience in a way that scales with complexity.

Move #6: Govern cloud and digital environments to create continuous visibility and control

How do we effectively secure complex cloud environments?

The shift to the cloud has delivered unprecedented agility and scale, but it has also introduced new complexities and expanded the attack surface. Cloud environments are in a constant state of flux, making them difficult to secure with traditional tools and processes. Simply meeting baseline compliance standards is not enough to protect against misconfigurations and advanced threats.

Hardening the cloud requires a robust security program that provides continuous visibility, enforces consistent controls, and proactively manages risk. Key actions include:

  • Implementing continuous controls monitoring to gain real-time visibility into your cloud posture and detect misconfigurations before they can be exploited.
  • Adopting a holistic approach that integrates security into the entire cloud lifecycle, from development to deployment.
  • Leveraging automation to enforce policies and remediate vulnerabilities at scale.
  • Mastering cloud security is essential for unlocking its full value while protecting your most critical assets.

Why do cloud environments outpace traditional security controls?

The challenge is not securing individual workloads. It is maintaining visibility across an environment that is constantly shifting.

Traditional security approaches rely on static controls and periodic validation. Cloud environments require continuous visibility, automated control enforcement, and integration across the lifecycle.

This shifts cloud security from a technical discipline to an operating model challenge. Organizations that embed visibility and control into how cloud environments function are better able to manage risk as it evolves, rather than reacting after issues emerge.

Position cybersecurity as a driver of enterprise resilience and performance

Navigating today's ever-evolving security environment requires leaders who see disruption as a springboard for growth. The policy landscape will continue to change, and AI will introduce both new threats and new opportunities. By taking these bold steps, you can build a cyber-resilient organization that not only withstands attacks but also inspires confidence, enables growth, and turns volatility into a strategic advantage.

How can CISOs demonstrate cyber performance to the business and board?

Leadership is no longer focused solely on whether systems are protected. There also is an expectation for organizations to:

  • Maintain continuity during disruption
  • Respond consistently across incidents
  • Demonstrate control effectiveness in measurable terms
  • Align cybersecurity with broader enterprise risk

This is where cybersecurity becomes a signal of organizational capability. It reveals how well systems, processes, and teams work together under real conditions.

For CISOs, this creates an opportunity to reposition cybersecurity. By focusing on performance, governance, and integration with business priorities, security can move beyond reactive defense and become an enterprise-wide capability that supports resilience and growth.

In a policy-driven economy, cyber risk is no longer just a factor to manage. It is a reflection of how well the overarching organization is positioned to perform.

Sources

1,2 2026 KPMG US CEO Outlook Pulse Survey

Proactive cybersecurity to help you guard against tomorrow’s threats today

As cyber threats grow in sophistication, CISOs must navigate an increasingly complex landscape of risks and vulnerabilities. With expanding regulatory requirements and the continuous evolution of attack methods, maintaining a robust cybersecurity posture is more critical than ever. 

At KPMG, we understand these challenges and provide targeted solutions to address them effectively. Today's CISOs need strategies that are both adaptable and multifaceted to stay ahead of ever-evolving threats. KPMG combines cutting-edge technology, actionable insights, and unparalleled expertise to help you prioritize and address your most critical cyber and tech risk challenges.

Our team leverages the latest in AI-driven analytics and industry best practices to deliver proactive, tailored solutions that fortify your security posture. Our cybersecurity and tech risk solutions are designed to enable your organization to anticipate threats, respond swiftly, and emerge stronger. From predictive threat intelligence to rapid incident response, KPMG is your partner in navigating cyber risk with confidence and agility.

 

KPMG Cyber and Tech Risk Services >

 

KPMG Cyber Managed Services >

 

Get in touch >

Advanced Threat Detection

Stay ahead of sophisticated cyber adversaries with AI and machine learning that detect and mitigate threats before they can impact your operations. Our solutions offer real-time threat intelligence and automated response mechanisms to keep your defenses strong and adaptive.

Enhanced Access Management

Effective identity and access management (IAM) is critical for controlling access to your systems and data. Automating IAM processes improves security and operational efficiency, ensuring only authorized users have access based on stringent, dynamic policies.

Regulatory Compliance

Stay compliant with evolving regulations and standards such as GDPR, CCPA, and industry-specific mandates. Our compliance services minimize regulatory risks and potential fines while streamlining audit and reporting processes.

Data Protection and Privacy

Ensure the integrity and privacy of data wherever it resides – on-premises, in the cloud, or in hybrid environments. Our strategies encompass robust encryption, DLP solutions, and strict access controls to protect against breaches and unauthorized access.

Meet our team

Our KPMG Cyber and Tech Risk team offers clients unparalleled expertise and access to cutting-edge technology, ensuring robust protection against evolving cyber threats. By leveraging a unique blend of functional, industry, and technological experience, our professionals help organizations navigate the complex landscape of cybersecurity with confidence. Our specialists are skilled in areas such as AI-driven threat detection, cloud security, identity and access management, and advanced data privacy. We empower your organization to embrace technological advancements safely and confidently, transforming your cybersecurity posture from reactive to proactive.

Image of Michael Gomez
Michael Gomez
Principal, Cyber Security, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline