logo

The State of Cyber Risk 2025: Business Context Needed

ID: a380dc0e-3c89-59be-a0b5-5356b82f2c06

STIX ID: report--a380dc0e-3c89-59be-a0b5-5356b82f2c06

Feed Name: Qualys Blog

Date Published: 2025-07-14

Date Updated: 2026-04-28

Author: Mayuresh Ektare

...
...

The document summarizes findings from the Qualys–Dark Reading State of Cyber Risk 2025 report, highlighting that while 49% of organizations have formal cyber risk programs, most lack business alignment, with 71% reporting risk rising or flat. Key gaps include incomplete and non-continuous asset inventories, overreliance on severity-only vulnerability scoring, and weak board-level reporting that rarely quantifies financial impact. It advocates for business-contextual, integrated risk prioritization and continuous measurement, proposing a Risk Operations Center (ROC) model and Qualys Enterprise TruRisk Management (ETM) to unify telemetry, apply business-aware scoring, and track risk reduction against outcomes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.