{"id":123215,"date":"2025-07-21T07:22:02","date_gmt":"2025-07-21T06:22:02","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=123215"},"modified":"2025-07-21T07:22:04","modified_gmt":"2025-07-21T06:22:04","slug":"new-qualys-report-warns-cyber-risk-management-still-lacks-business-context","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2025\/07\/21\/new-qualys-report-warns-cyber-risk-management-still-lacks-business-context\/","title":{"rendered":"New Qualys report warns: cyber risk management still lacks business context"},"content":{"rendered":"\n<p>Despite increasing investment in cybersecurity, a new 2025 Qualys report reveals that most organisations still struggle to link cyber risk to real business impact\u2014leaving boardrooms with a blind spot in decision-making.<\/p>\n\n\n\n<p>According to the <em>State of Cyber Risk Assessment 2025<\/em> report by Qualys in partnership with Dark Reading, while nearly half of organisations now have a formal risk management programme, a staggering number still lack the ability to translate technical vulnerabilities into meaningful business decisions.<\/p>\n\n\n\n<p>\u201cSpending has increased, frameworks have matured, and boards are asking tougher questions,\u201d said Mayuresh Ektare, Vice President of Product Management at Qualys. \u201cYet 71% of organisations report that their cyber risk levels are either rising or remaining the same. That should be a wake-up call.\u201d<\/p>\n\n\n\n<p>Only 6% of those surveyed said their risk levels have decreased.<\/p>\n\n\n\n<p><strong>The business context black hole<\/strong><\/p>\n\n\n\n<p>The report reveals a persistent disconnect between cybersecurity operations and business outcomes. While 49% of respondents reported having formal risk programmes, only 30% link them directly to business objectives. Even fewer (18%) use integrated risk scenarios that consider both business processes and financial exposure.<\/p>\n\n\n\n<p>\u201cEvery business is unique; hence, each risk management programme must be tailored to reflect that reality,\u201d Ektare noted. \u201cThe old one-size-fits-all, CVSS-driven approach doesn\u2019t work anymore.\u201d<\/p>\n\n\n\n<p>Adding to the concern is how cyber risks are being communicated at the executive level. While 90% of organisations report cyber findings to the board, just 14% quantify those risks financially, and only 22% involve finance teams in discussions. The gap between technical risk and strategic consequence remains stark.<\/p>\n\n\n\n<p><strong>Asset visibility: the old problem that won\u2019t go away<\/strong><\/p>\n\n\n\n<p>Two decades on, organisations are still struggling with asset visibility, a foundational challenge that continues to undermine security efforts. Although 83% of organisations perform regular asset inventories, only 13% can do so on a continuous basis. Nearly half still rely on manual processes, and 41% admit that incomplete asset data is one of their most significant barriers to effective risk management.<\/p>\n\n\n\n<p>The report suggests that true cyber resilience begins with knowing what\u2019s at risk. But without visibility, organisations are essentially securing blindfolded.<\/p>\n\n\n\n<p><strong>Risk prioritisation needs a new vocabulary<\/strong><\/p>\n\n\n\n<p>The industry also appears to be slowly moving beyond CVSS (Common Vulnerability Scoring System) as the primary metric for prioritisation. Around 68% of organisations now blend severity scores with threat intelligence and loss forecasting to drive risk decisions. Still, nearly one in five (19%) rely solely on traditional scoring methods, missing out on the bigger picture.<\/p>\n\n\n\n<p>\u201cPatching everything is neither possible nor necessary,\u201d said Ektare. \u201cWhat matters is which risks affect your crown jewel assets. If everything is critical, then nothing is.\u201d<\/p>\n\n\n\n<p><strong>The rise of the risk operations centre (ROC)<\/strong><\/p>\n\n\n\n<p>To address this challenge, Qualys is advocating a shift toward a \u201cRisk Operations Center\u201d (ROC) model &#8211; a framework that merges vulnerability data, threat intelligence, and business asset context under one roof. Unlike reactive SOC models that respond to incidents, the ROC aims to predict and prevent them by aligning cybersecurity strategy with business impact.<\/p>\n\n\n\n<p>\u201cROC is the next evolution,\u201d Ektare said. \u201cIt provides a continuous, business-aligned view of cyber risk. And that\u2019s what stakeholders are demanding.\u201d<\/p>\n\n\n\n<p>The report\u2019s key message is clear: current cybersecurity efforts, though well-intentioned, often fall short where it matters most, business value. Risk data needs to be translated into stories that resonate with CFOs, CEOs, and boards. Otherwise, cyber will remain a technical silo, detached from enterprise priorities.<\/p>\n\n\n\n<p>For organisations looking to improve, the recommendations are simple but urgent:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Define crown jewel assets and tailor risk programmes to protect them.<\/li>\n\n\n\n<li>Replace fragmented telemetry with enterprise-wide risk signals.<\/li>\n\n\n\n<li>Prioritise risk in business\u2014not just technical\u2014terms.<\/li>\n\n\n\n<li>Quantify risk in financial language for the board.<\/li>\n\n\n\n<li>Shift from reactive SOCs to proactive ROCs.<\/li>\n<\/ul>\n\n\n\n<p>\u201cThe illusion is that cyber risk is being managed just because tools and dashboards exist,\u201d Ektare concluded. \u201cBut real risk reduction only happens when the business is part of the conversation.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Despite increasing investment in cybersecurity, a new 2025 Qualys report reveals that most organisations still struggle to link cyber risk to real business impact\u2014leaving boardrooms with a blind spot in decision-making. According to the State of Cyber Risk Assessment 2025 report by Qualys in partnership with Dark Reading, while nearly half of organisations now have [&hellip;]<\/p>\n","protected":false},"author":4338,"featured_media":122381,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[18907,14804,19391,3032,13],"tags":[22,1530,908,562,10,184],"class_list":["post-123215","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-study-latest-analysis","category-cybersecurity","category-hot-topic","category-industry-verticals","category-top-stories","tag-cloud","tag-cybersecurity","tag-digital-transformation","tag-middle-east","tag-security-2","tag-uae"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/4338"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=123215"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123215\/revisions"}],"predecessor-version":[{"id":123216,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123215\/revisions\/123216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/122381"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=123215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=123215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=123215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}