By Dan Wood, Group CISO Cyberfort
As cyberthreats, regulatory requirements and third-party risks continue to evolve, organisations need a more continuous and connected approach to managing risk. Dan Wood, Group CISO at Cyberfort, explains why traditional risk management practices are no longer enough and how modern platforms can help security teams stay ahead.
Ask most CISOs how they manage risk day to day and the answer you will usually receive is ‘mostly on spreadsheets, bolted onto whatever GRC tool procurement or my predecessor has signed off on, we usually only use the tool once a year when the auditors arrive’. I say that without judgement, I’ve run programmes exactly like this as well. But I no longer think it’s defensible and I suspect most of us already know that is true.
Why traditional risk management doesn’t cut it anymore
The issue isn’t that risk teams don’t care. It’s that risk moves faster than the review cycle built to catch it. A vendor gets breached, a regulation shifts, a new system goes live and none of it waits politely for the next scheduled audit. By the time an exposure surfaces in a quarterly report, it has usually existed for months. Regulators such as the ICO and the FCA aren’t slowing down either and being caught relying on last quarter’s picture of risk is not a comfortable place for any CISO to stand.
Then there’s the sprawl. Most security and risk teams I speak to are juggling some mix of spreadsheets, a legacy GRC platform and manual reporting someone built to plug the gaps between them. Every extra tool adds another version of the truth and every version adds room for error.
Vendor risk is where this shows up hardest. An annual questionnaire tells you what a supplier’s posture looked like on the day they filled it in, not what it looks like now. A vendor can pass a review in January and quietly change its sub-processors, its access controls, or its own security posture by June and nobody finds out until it’s the vendor’s breach notification landing in your inbox. Given how many recent high-profile breaches have started with a third party in the last 12 months, treating vendor oversight as a once-a-year tick-box exercise feels closer to negligence than due diligence.
Data privacy adds another layer that’s easy to underestimate. Between UK GDPR obligations, DPIAs and the practical reality of tracking where personal data actually lives across an increasingly sprawling estate, privacy risk rarely gets the continuous attention it needs. It tends to live in a different spreadsheet, owned by a different team, reviewed on a different schedule, which means it’s often the last thing anyone notices has drifted out of control.
Then there’s the board. Cyber-risk is now a standing agenda item, which is progress, but it means CISOs are expected to translate technical and/or regulatory exposure into something a non-technical director can act on, on a schedule that leaves no room for a week of manual data-wrangling before every meeting. I’d rather spend that time on the risk itself than on the slide deck.
What good risk management software does
This is where the right risk management software earns its place. Not as another dashboard to check, but as the connective tissue between what’s happening across the estate and what gets reported upward. Done well, it should give continuous, real-time visibility rather than a point-in-time snapshot; it should replace static vendor questionnaires with ongoing monitoring that flags changes as they happen; it should hold risk data in one place rather than scattered across systems, so reporting to the board becomes an export rather than a project; and it should make the link between what you’re spending and what risk you’re removing, in language a CFO will accept.
Choosing the right platform
Choosing the right platform is less about the longest feature list and more about fit. I’d start by being honest about which categories of risk keep you up at night – operational, regulatory or vendor – because that should shape what you prioritise, rather than working backwards from a demo.
I’d then test how much of the workflow is genuinely automated versus how much is automation in name only, because plenty of tools promise intelligence and deliver another queue to manage. I’d look hard at integration: a platform that can’t pull from your identity provider, your cloud environment and your HR system will always be working from an incomplete picture, however polished its dashboard looks.
If you operate internationally, stress-test how it copes with multiple regulatory regimes at once – that’s usually where the cracks show first.
Cost matters too, but not in isolation. The sticker price rarely reflects the true cost of ownership once you’ve added training, setup and the internal resource needed to keep it configured properly. I’d rather pay more for a platform with strong support during adoption than save money upfront and spend the next year fighting the implementation. Ask what happens six months in, once the initial enthusiasm has worn off and the platform needs to run itself – that’s the question vendors are least keen to answer in a sales pitch.
Getting implementation right
Implementation is where good intentions often stall. The organisations that get the most from this software tend to do a few things consistently: they map their existing processes and access rights before switching anything on, rather than discovering the gaps live; they train people properly rather than assuming a new interface is self-explanatory; and they track outcomes deliberately, so there’s real evidence to show leadership rather than a vague sense that things feel better.
None of that is glamorous, but it’s the difference between a platform that gets used and one that quietly becomes shelfware within a year.
None of this replaces judgement. Software won’t decide your risk appetite for you, and it won’t have the difficult conversation with a business unit that’s ignoring a control gap. What it does is remove the excuse of not knowing – and in a landscape where regulators, boards and attackers are all moving faster than the traditional audit cycle, not knowing is no longer an option any of us can afford.
Read the article in Intelligent CISO here https://www.intelligentciso.com/2026/07/30/using-the-right-risk-management-software-to-build-resilience/





















