Roseville, California just provided a case study in what happens when organizations confuse “AI-powered” with “AI-verified.” A Business Insider investigation found that Flock Safety’s AI license plate readers misread plates in 71% of the alerts sent to Roseville police over two years, incorrectly flagging vehicles as stolen or linked to a felony. That number isn’t […]
Last week at Nexthink’s Masters of Experience event in London, one theme came through clearly in every conversation I had with digital workplace leaders, IT practitioners, and experience innovators: The ways that organizations use digital employee experience management (DEXM) solutions are expanding. AI dominated the agenda — as expected. But the real story wasn’t about […]
If you’ve ever tried to meet someone “at Ray’s Pizzeria” in Manhattan, you already understand the contract lifecycle management (CLM) market. “Original Ray’s.” “Famous Ray’s.” “World Famous Original Ray’s.” Same name, similar awning, very different experience. That’s CLM right now: Vendors sound alike, but they’re not built alike. Diverse Functionality, Copy-Paste Claims Every vendor is […]
Check out the latest Forrester Wave™ evaluation of the governance, risk, and compliance platforms market and its findings.
US companies are drowning in AI rules. With a labyrinth of conflicting state laws and no single federal requirement, even the most responsible innovators are struggling to stay afloat. California’s landmark Transparency in Frontier Artificial Intelligence Act proved that states can regulate AI without killing innovation, but it also underscores a hard truth: The current […]
Some security incidents are complex. The Vercel incident is more troubling because it was predictable. The attackers did not exploit a procurement gap. They exploited a definition gap. Here’s what happened. A Vercel employee signed up for Context.ai’s AI Office Suite using a corporate Google account and clicked something effectively equivalent to “Allow All,” granting […]
Over the past five years, security and risk (S&R) professionals have experienced a flood of new cybersecurity regulations, with 170 countries now boasting cybersecurity and data protection laws. Leaders are left to decide which regulations apply, identify gaps, and implement controls — an onerous task as regulatory volume and the pace of change accelerate. Manual […]
For many B2B leaders, volatility no longer feels like an interruption to “normal.” It is now the standard operating environment. Economic uncertainty, geopolitical shocks, AI-driven disruption, and shifting buyer behavior are colliding, exposing weaknesses in traditional go-to-market models and leadership assumptions. The good news? Volatility can benefit those who adapt faster, focus harder, and lead […]
In musical notation, “al niente” means fading until sound is barely perceptible, usually to end a significant piece of music such as the ending of Tchaikovsky’s reflective and somber sixth symphony. And that is how the cybersecurity risk ratings market is likely to proceed over the coming months. Ratings will not fade away to nothing […]
In 1929, astronomer Edwin Hubble discovered something unsettling. The universe isn’t static; it’s expanding everywhere, simultaneously, at every scale. His simple equation (Hubble’s law) shows that galaxies are accelerating away from each other, and the farther they are, the faster they recede. Eventually, galaxies become so distant that they cross our observable horizon entirely — […]
In 2026, continued political instability coupled with technological advancements being used by cybercriminals will force cybersecurity and risk leaders to adapt their defensive technologies and prepare their workforce for big shifts. Find out more in our 2026 predictions for cybersecurity and risk.
Since insider risk is more about people than PCs, security and insider risk management pros must make an unlikely new ally: their colleagues in HR. Find out how HR can help reduce insider risk in this preview of our upcoming Security & Risk Summit.
As cyber regulations continue to multiply, cyber and risk professionals need to make choices about how they comply with cyber regulations that conflict with each other. Find out how generative AI can help in this preview of our upcoming Security & Risk Summit.
Since its launch, human risk management has blossomed into a distinct and expanding market, attracting the interest and budget of many organizations. Learn about the fast evolution of HRM in this preview of our upcoming Security & Risk Summit.
Learn how increased complexity and additional market factors led us to rethink the title of our upcoming Forrester Landscape report on digital sovereignty platforms
For leaders in security, risk, and privacy, this year has been different, with a new level of volatility fueled by geopolitics, new regulatory hurdles, relentless AI disruption, and looming quantum threats. Learn how Forrester’s Security & Risk Summit 2025 can empower you to stay ahead of the chaos, take the right risks, and secure your organization.
This week the UN court said countries must address the “urgent and existential threat” of climate change. It’s easy to see from weather events why this is more urgent than ever before.
July has marked a defining moment for global AI regulation, as policymakers in both the US and the EU removed or abandoned some heavy roadblocks that stood in the way of laws mandating transparency and regulations enshrining risk management.
Disruptive technologies such AI can boost efforts towards some strategic priorities, but can also work against environmental sustainability goals. Learn more about the the dual role played by six of the most important disruptive technologies poised to shape sustainability in 2025.
In ancient Rome, mosaics adorned the floors and walls of villas, temples, and public spaces. These intricate works of art were composed of tiny cubic tesserae. Each piece, though small, contributed to a grander design. But damage to even a single tile could disrupt the harmony of the whole. Today’s global business environment is no […]
Learn how Forrester’s Continuous Risk Management Model can replace outdated risk management methods in this preview of a session at the upcoming Security & Risk Summit.
Three application security technologies are key for retailers to adopt before the holiday season.
Risks posed by and to humans such as deepfakes, data exfiltration by insiders, and misuse of generative AI are expected to accelerate and become more complex. Learn how to discern and manage these human element risks in this preview of an upcoming report.
A recent study by the American Medical Association (AMA) noted that just four firms dominate 70% of the pharmacy benefit manager (PBM) industry, a textbook definition of an oligopoly. Learn more about what's driving this trend and what the impact could be.
Looking for ways to improve your fraud management capabilities? Learn six key ways generative AI can help in this preview of a session at our upcoming Security & Risk Summit in Baltimore December 9-11.
As a former hockey mom, I assure you that there is nothing quite as pungent as a travel-team hockey bag. Adolescent sweat, steamy equipment, and skates with remnants of ice all shoved into a giant bag with no ventilation makes for a breeding ground for fungus and bacteria. But ask any player, coach, or hockey […]
As AI becomes more agentic, making decisions on behalf of businesses and eventually consumers, the risks will grow more complex. Learn more about the use cases and risks of AI agents in this preview of our upcoming Security & Risk Summit.
The fraud attack rate in APAC is above the global average. Find out why in this preview of a new report on the latest trends in fraud management, including evolving fraud patterns and technology adoption trends in APAC.
CrowdStrike's recent global incident underscores businesses' need to have robust crisis communication plans in place before a crisis occurs.
An organization’s single biggest risk is not knowing how much risk it has. That's why cyber risk quantification is on the rise. Learn the basics of how to build a CRQ business case in this post.
Read this blog post to understand the actions that organizations need to take throughout the sustainability materiality assessment process.
Environmental sustainability is a compliance, accounting, and data management challenge for companies. So it's not surprising that the sustainability management software market is expanding rapidly. Learn more about these trends in this preview of our new Wave and Landscape reports on sustainability management software.
As digital threats grow more sophisticated and European and international regulatory landscapes more intricate, the role of cybersecurity consulting services is critical. Hence, I’m excited to announce The Forrester Wave™: Cybersecurity Consulting Services In Europe, Q1 2024 (available for Forrester clients). In this report, my colleagues and I scrutinize the offerings of major players in […]
Learn the key takeaways and market impacts from the Biden administration’s executive order to protect Americans’ sensitive personal data.
A recent cybersecurity incident at Change Healthcare cause the pharmacy claims processors to take its systems offline. Learn the implication of this event and five things firms can do to prepare.
Forrester data shows that 22% of data breaches in 2023 were the result of internal incidents. What does that have to do with fantasy football? Find out in this post.
Given today’s heightened polarization, what role will PR agencies play in guiding corporate brands? We hypothesize three key elements are fundamental to crisis and reputation services.
No matter how big a game a buyer talks, less than a third of all buyers are risk-tolerant. Trust is the remedy to risk — and trusted companies are more likely to win and retain customers and enjoy a strong buyer preference.
Learn how NASA's Space Security Best Practices Guide benefits not only NASA’s space missions, but any security risk management professional.
Cyberattacks continue to threaten the availability of online shopping for retailers — and the profits that come from it. Retailers can take these three steps to defend against them, this holiday season and into 2024.
Read this report for more insight on the GRC market that has been 20 years in the making and the 15 vendors that matter most.
One of Forrester’s best practices for managing insider risk is to turn your employees into advocates for the program. Get five tips for how to do that in this preview of our upcoming Security & Risk event in November.
Three factors are certain to influence your cyber security program today: regulations, third-party partners, and cyber insurance. Increasingly stringent requirements, exclusions, and policy premium costs may appear as a trifecta of pain launched your way from insurers. But cyber insurance is really an opportunity. Security leaders can wield cyber insurance not only as risk transfer […]
On August 14, 2023, a Montana state court found that Montana violated the plaintiffs’ constitutional right to a “clean and healthful environment” by promoting the use of fossil fuels without factoring for the effects of greenhouse gas emissions (GHE). It sets legal precedent for similar cases already filed in other states. But could it also […]
Last month, Forrester announced its inaugural Security & Risk Enterprise Leadership Award. As former CISOs, my Forrester colleague Brian Wrozek and I are sharing our thoughts about why you should apply. There are tangible benefits to you, your team, your organization, and the greater security community. You should apply — and apply now — for […]
Subscription-based hardware is the emerging model that every hardware vendor is promising to customers, partners, and investors. It’s a significant shift from the classic capex model where firms spend money for outright hardware purchases. There are several scenarios like new technology, short-term projects, test before you buy, and infrastructure bundled with managed services, etc. where […]
Vulnerability management, like flossing, is not fun, exciting, or sexy, but we know that it’s a necessary component of good hygiene. There’s a ton of evidence and research to strongly substantiate its benefits, and yet we frequently struggle to do it despite clearly understanding the consequences — we certainly don’t want a root canal! Yet, […]
Forrester data shows that fewer than 10% of enterprises are advanced in their insights-driven capabilities. Find out why in this blog post.
Forrester is thrilled to announce its inaugural Security & Risk Enterprise Leadership Award, which will recognize security organizations that have transformed the security, privacy, and risk management functions to fuel long-term success. Learn how to apply here.
We’re excited to announce our latest research on Vulnerability Risk Management (VRM) and Security Operations Center (SOC) teams. VRM and SOC teams are pivotal parts of the security organization with different responsibilities but shared challenges. When Allie and I kicked off our research on interlocks between these teams earlier this year, we weren’t sure what […]
What do organizations use VRM for? Learn the five top use cases in this preview of our new report: The Vulnerability Risk Management Landscape, Q2 2023.
Third-party risk management and cyber risk ratings fight better together, making security and risk professionals the beneficiaries of the alliance.
Climate events occur more frequently every year. Treat this Earth Day as a call to action, and add climate risks to your systemic risk purview.
Ransomware Vulnerability Warnings Are Coming To A Critical Infrastructure Near You The US Cybersecurity and Infrastructure Security Agency (CISA) launched the Ransomware Vulnerability Warning Pilot (RVWP) in January 2023 in response to ongoing concerns about the threat of ransomware. This is the CISA’s ransomware-centric take on external attack surface management for critical infrastructure. The RVWP pilot […]
Last week, The Washington Post did a deep dive on how a publication used “commercially available” mobile data to out a Catholic priest as a Grindr user and visitor of a gay bar, ultimately forcing him to resign. Some of this data was sourced from Grindr; a Grindr spokesperson told the Post that “[the] company […]
For the first time in three decades, athletic retailer Adidas reported an operating loss to the tune of €700 million ($736 million) in 2022 and warned of a €1.2 billion ($1.27 billion) revenue decrease in 2023. The incurred losses and potential revenue hit aren’t from ongoing supply chain issues or a result of inflation. A […]
Perspectives From A Former CISO/CSO For my second blog in this series, I wanted to share my thoughts on one of my favorite subjects: third-party risk management (TPRM). More specifically, I’m going to primarily focus on the receiving side of the equation — i.e., responding to and dealing with external inquiries about your organization as […]
All businesses rely on contracts. Unlike customer-facing functions, however, the software that powers the creation, execution, and management of these commercial obligations hasn’t made the shift toward digital … until now! In my new report, The Contract Lifecycle Management Landscape, Q1 2023, I looked at the 26 notable contract lifecycle management (CLM) vendors that procurement, […]
Unless you’re a floppy disk aficionado, Tom Persky isn’t likely to be a familiar name. Tom is what you’d call a “last man standing,” as he’s the only bulk seller of floppy disks left, and his business of recycling, stripping, and reselling floppy disks is booming. You may be thinking, so what? Do they still […]
Over the last 12 months, “risk dashboards” became all the rage in cybersecurity, with varied titles such as “risk index,” “security baseline,” “security posture,” and “risk posture.” These dashboards appear in a vendor’s user interface and purport to help security programs improve. Some even offer coveted “benchmark data” that leaders can share with boards and […]
In December 2022, a scammer in California worked up fake parking tickets with QR codes on them, directing citizens to a phishing site collecting payment card information — just one of many such recent QR code-related scams. Though QR code use surged in popularity during the COVID-19 pandemic because of customer desire for touchless interactions, QR-code risk management is not maturing at the same rate as adoption.
Each year, Forrester Research and the Disaster Recovery Journal (DRJ) team up to launch a study examining the state of business resiliency. We alternate between two resilience domains each year: IT disaster recovery and business continuity. This is the year of business continuity! The last joint survey we did was right in the middle of […]
Learn why “fixing” supply chain issues is less important than reducing the long-term risks that create the issues in this Security & Risk event preview.
Classic horror movie quirks closely resemble what we’re seeing in firms looking to innovate and differentiate yet are running from rather than toward AI and advanced automation.
New business priorities, strategic initiatives, and a plethora of new risks mean that security, risk, and compliance professionals must master the art of juggling.
Learn how to reduce the three most common types of insider threats in this Security & Risk event preview.
When tech companies select people with ideals and integrity, they get people with ideals and integrity. When they behave in ways that betray those employees, they can expect rebellion.
The trend toward automation is not new. The Industrial Revolution started it in the 19th century, but there has never been such rapid automation progress as today. All forms have accelerated, often without understanding their effect. Humans have become choke points in operations, points of disease and legal liability, and friction to smooth digital pathways, […]
Marketing and risk share a common goal: building customer trust. By partnering, marketers and S&R pros can use the growing momentum around consumer privacy to grow customer trust.
On July 6, 2022, the Travelers Property Casualty Company of America (Travelers Insurance) filed a suit in an Illinois federal court against International Control Services, Inc. (ICS) asking for policy rescission and declaratory judgment against ICS. Travelers alleges that ICS misrepresented its use of multifactor authentication (MFA) on its policy application, which should be sufficient […]
Many organizations are ill-equipped to manage the problem. Yet it's the sort of systemic risk that leaders need to be ready to face.
Fear. Uncertainty. Doubt. Also known as “appeal to fear,” fear-uncertainty-doubt (FUD) is a fallacy in which a person tries to create support for an idea (or technology) by attempting to increase fear towards an alternative. Since passage of Sarbanes-Oxley (SOX), the regulation that launched the era of compliance, technology sales have been predicated on creating […]
The US Cybersecurity and Infrastructure Security Agency and other government agencies will continue to weigh in on vulnerability and patch management. Be prepared to respond.