Skip to main content
Four Findings That Prove Your Risk Silos Are Costing YouRisk Assessment & Treatment
4 min readFor IT Governance Teams

Four Findings That Prove Your Risk Silos Are Costing You

Your risk management setup might look complete on paper. You've got a CISO handling security, a DPO managing privacy, a compliance team tracking regulations, and procurement vetting suppliers. Each function runs its own assessments, maintains its own registers, and reports through its own channels.

The problem? None of them are talking to each other. That fragmentation is creating the exact blind spots attackers exploit.

What the Data Shows

Info-Tech Research Group analysis reveals a troubling pattern: organizations have built cyber-risk functions that operate in isolation even as the risks themselves have become interconnected. The research identifies three core barriers blocking integration: immature processes and shared language, rapidly evolving threats that outpace siloed teams, and risk management treated as compliance theater rather than strategic capability.

The consequences show up in the numbers. Two-thirds (65%) of organizations suffered AI agent-related security incidents in the past year. The average enterprise now deploys 61 security tools. Cambridge University research shows CISOs under this pressure default to reactive management and tick-box compliance. IANS data puts a finer point on it: 52% of CISOs report their scope is no longer fully manageable.

Key Findings

Finding 1: Your attack surface expanded faster than your governance model

The castle-and-moat perimeter dissolved years ago. Cloud infrastructure, remote endpoints, SaaS applications, OT systems, IoT devices, edge servers, and now AI infrastructure have all joined your risk portfolio. Each expansion brought new stakeholders: cloud architects, data scientists, product teams, legal counsel. But governance didn't evolve to connect them. You're managing 2024 risks with a 2014 org chart.

Finding 2: Shadow AI is creating unmanaged risk you can't see

AI infrastructure isn't just LLMs your data science team deploys. It's agents, vector databases, ML pipelines, APIs, plugins, and cloud inference servers spread across business units. Info-Tech's research found 82% of organizations suspect they have unmanaged AI agents running in their environments. If you can't inventory it, you can't assess it. If you can't assess it, you can't control it.

Finding 3: Third-party risk management is still point-in-time theater

You assess suppliers at onboarding. You send questionnaires at renewal. What happens between those snapshots? Most organizations have no visibility into whether the controls they validated six months ago still exist today. Supply chain compromises don't wait for your annual review cycle. Continuous monitoring isn't optional anymore; it's the only way to maintain an accurate risk picture when you're running on 61 security tools and an ecosystem of digital suppliers.

Finding 4: Distributed accountability without shared taxonomy creates reporting chaos

NIS2 and similar regulations now hold senior management personally liable for cyber resilience. That accountability shift is correct, but it exposes a structural problem. When your CISO reports on security controls using one framework, your DPO reports on privacy using another, and your AI governance lead uses a third model, the board can't see the aggregate picture. Distributed ownership is necessary. Disconnected reporting is not.

What This Means for Your Team

You can't unify oversight by centralizing all risk functions under one leader. The scope is too broad, the expertise too specialized. What you need is integration without consolidation: separate functions operating against a common control framework.

Black Duck CISO Dom Glavach frames the cost of fragmentation clearly: "When silos disrupt oversight, organizations end up with blind spots, duplicate work, slower response, and difficulty proving that the controls were working across the organization."

The fix requires structural change, not just better coordination. Info-Tech's four-point plan provides the skeleton: establish goals and governance, develop mechanisms to identify and assess risks, develop risk response options, and create a tooling and monitoring plan. But two elements deserve immediate focus.

First, implement a common control framework. ISO/IEC 27001, NIST, or a well-constructed internal model all work if they establish consistent taxonomy and clear traceability between risks, controls, and ownership. The framework creates what Black Duck's Ronald Lewis calls "connective tissue between privacy, security, third-party risk, AI governance, and operational resilience."

Second, shift third-party risk management from periodic assessment to continuous monitoring. Muhammad Yahya Patel, vCISO EMEA at Huntress, emphasizes this gap: "What they don't have is continuous visibility of whether the controls they relied on at assessment time are still in place."

Action Items by Priority

Priority 1: Map all risk functions to a single control taxonomy (Q2 2025)

Inventory every team managing cyber-related risk: security, privacy, compliance, legal, procurement, AI governance, business continuity. Document what framework or model each uses. Select one master framework (ISO/IEC 27001 Annex A or NIST CSF work well) and map every team's controls to it. This doesn't change what controls they implement; it creates a shared language for reporting.

Priority 2: Implement continuous supplier monitoring for critical vendors (Q3 2025)

Identify your top 20 suppliers by data access, system integration, or business criticality. Deploy continuous security posture monitoring (security ratings services, attack surface monitoring, or integrated GRC platforms). Set thresholds for material changes: certificate expiration, breach disclosure, control failures. Integrate alerts into your internal risk register.

Priority 3: Create a unified risk dashboard for executive reporting (Q4 2025)

Build a single view that aggregates risk data from all functions. Use the common taxonomy from Priority 1. Include metrics for control effectiveness, not just compliance status. Show trend lines and concentrations: which risk categories are growing, which suppliers represent clustered exposure, where controls overlap or leave gaps.

Priority 4: Establish AI asset inventory and governance process (Q1 2026)

Require registration of all AI systems, including agents, models, APIs, and data pipelines. Classify by risk level using the EU AI Act categories as a baseline (unacceptable, high, limited, minimal). Assign ownership and control requirements based on classification. Audit quarterly for shadow AI.

You Might Also Like