RegScale

70 stats2 reports

All Statistics

Only 5% of CISOs consider their organisation's compliance program to be optimised for efficiency and continuous improvement.

ComplianceCompliance progran

Roughly 22.6% of CISOs rate their compliance program a 4 (“Adherence: measured with metrics to support audit and risk mitigation”), but only 5.3% believe their program is a 5 (“Optimized: continuous improvement and efficiency”).

ComplianceCompliance program

53.7% of CISOs stated that compliance is not embedded into their CI/CD pipeline.

ComplianceCI/CD

30.3% of CISOs are challenged by control mapping in satisfying regulatory requirements.

ComplianceControl MappingRegulatory Requirements

Just over a quarter (26.4%) of CISOs said that compliance has been embedded into 26-50 percent of their pipeline, while 27.4% have embedded compliance in as much as 75 percent of their pipeline.

ComplianceCI/CD

Less than one-sixth (14.2%) of CISOs have embedded compliance into the majority (76-100 percent) of their pipeline.

ComplianceCI/CD

Almost one in ten (9.6% of CISOs) said their relationship between compliance and security is in a period of complex negotiations while 8.5% said their relationship is out of sync.

ComplianceSecurity

Roughly one-sixth (15.8% of CISOs) endure quite a bit of duplication and 37.4% have some duplication in their compliance efforts.

ComplianceCompliance efforts

Only a fifth (20.5% of CISOs) said they have very little duplication in their compliance efforts.

ComplianceCompliance efforts

Roughly half of CISOs (47.9%) cited evidence gathering as one of their greatest challenges in implementing new or updated compliance frameworks.

ComplianceCompliance frameworksEvidence gatheringImplementation

43.6% of CISOs cited control mapping as a challenge in implementing new or updated compliance frameworks.

ComplianceControl MappingCompliance frameworks

38.3% of CISOs cited cost as a challenge in implementing new or updated compliance frameworks.

ComplianceCostCompliance frameworksBudget

33.5% of CISOs cited audit management as a challenge in implementing new or updated compliance frameworks.

ComplianceAudit ManagementCompliance frameworks

Many CISOs (51.6%) were impacted by their maturing compliance program as a challenge in satisfying regulatory requirements.

ComplianceMaturityRegulatory Requirements

Roughly two-fifths of CISOs are challenged by evidence gathering (41.5%) as a challenge in satisfying regulatory requirements.

ComplianceEvidence GatheringRegulatory Requirements

42% of CISOs are challenged by data and system silos as a challenge in satisfying regulatory requirements.

ComplianceData SilosRegulatory Requirements

40.4% of CISOs are challenged by the lack of a centralized system as a challenge in satisfying regulatory requirements.

ComplianceCentralized SystemRegulatory Requirements

34.6% of CISOs are challenged by regulatory change management in satisfying regulatory requirements.

ComplianceRegulatory ChangeRegulatory Requirements

33.5% of CISOs are challenged by audit readiness in satisfying regulatory requirements.

ComplianceAudit ReadinessRegulatory Requirements

More than one-third of organisations (34.2%) hope to achieve their KPIs for compliance benchmarks by incentivizing success or by penalizing failure, or by implementing both incentives and penalties.

ComplianceKPIsIncentivesPenalties

50% of CISOs said that, on an annual basis, they spend more than $200,000 worth of capital and dedicated staff resources to achieve and maintain compliance across their organisation.

ComplianceCostBudgetResources

20% of CISOs spend between $100,000 and $200,000 annually on compliance.

ComplianceCostBudgetResources

Nearly 22% of CISOs said they haven’t looked at GRC tools yet.

ComplianceGRC ToolsEvaluationResources

Almost all (94.2% of CISOs) believe that continuous controls monitoring will improve both compliance and security.

ComplianceContinuous ControlsSecurityImprovement

Just 17.9% of CISOs are using GenAI tools within their compliance program.

ComplianceGenAIToolsTechnology

More than four-fifths (82.1% of organisations) are not currently using GenAI tools or functions within their compliance program.

ComplianceGenAIToolsTechnology

Nearly one-third (33.2% of organisations) have incorporated automation without GenAI tools.

ComplianceAutomationTechnologyProcess

Approximately four out of five (79.8% of CISOs) believe that a reduction in manual processing is the biggest opportunity to add automation to their compliance and risk management program.

ComplianceAutomationRisk ManagementProcess

Nearly as many (46.3% of CISOs) think the technology will allow them to more rapidly apply governance.

ComplianceAutomationStaffProductivity

Just over a quarter (27.7% of CISOs) think that automation will improve the ROI on existing tools.

ComplianceManual ProcessesCompliance as CodeEase of Use

More than one-third (37.2% of CISOs) said that no platform has demonstrated its reliability for Compliance as Code.

ComplianceMetricsAuditRisk management

41% of CISOs said that OSCAL adoption is hindered by both a lack of usage and a difficulty in understanding its importance.

ComplianceDocumentationProcessStandardization

44.2% of CISOs consider security and compliance a business enabler.

ComplianceCI/CDIntegrationAutomation

Of the organisations that measure the operational cost of managing compliance, more than three quarters (75.4%) track all costs.

ComplianceSecurityNegotiationsManagement

Just 16.3% of CISOs said they experienced cost savings when using technology to enhance their compliance program.

ComplianceEvidenceResourcesImplementation

A staggering 80% of CISOs admit to unnecessary duplication in their compliance efforts.

ComplianceSkillStaffResources

Almost two thirds of organisations (63.7%) do not feel that meeting new regulatory requirements slow their organisational growth.

ComplianceControl MappingProcessManagement

54.2% of respondents to the CISO Society survey feel that they have the talent to meet future regulatory requirements.

ComplianceCostBudgetResources

60% of manufacturers and 52.5% of software and IT services companies see the biggest barrier to adopting Compliance as Code is that no one is using the technology.

ComplianceMaturityRegulatory RequirementsManagement

Over a billion credentials were stolen in malware attacks within a 12-month period.

ComplianceEvidenceRegulatory RequirementsManagement

Research shows over 210 million compromised passwords.

ComplianceDataSystem SilosRegulatory Requirements

Stolen credentials are involved in nearly half (44%) of all data breaches.

ComplianceCentralized SystemRegulatory RequirementsManagement

The most commonly compromised password was "123456", being found in over 1.4 million breached credentials.

ComplianceRegulatoryChange ManagementManagement

Of the 1.8 million breached administrator credentials, 40,000 admin portal accounts had the password ‘admin’.

ComplianceAuditReadinessRegulatory Requirements

38.5% of CISOs said GRC tools are too expensive.

ComplianceGRC ToolsCostResources

Almost one-third (31.1% of CISOs) believe that their company’s resistance to change is primarily driven by financial matters.

ComplianceCI/CDIntegrationAutomation

25.5% of CISOs assume current GRC processes are not broken.

ComplianceProcessStandardizationStructure

Of the organisations that measure the operational cost of managing compliance, 10.1% track IT costs.

ComplianceDuplicationProcessEfficiency

35% of CISOs said that, on a scale of 1 to 5, they would rate their compliance program a 3 (“Defined: early-enterprise, standardized and structured”).

ComplianceCompliance program

75% of retail and consumer goods and 62.5% of entertainment and media corporations are coping with the lack of a centralized system, but retailers are also challenged by silos within their data (75%).

ComplianceRegulatoryChange ManagementProcess