Why is cyber risk oversight a necessary expense? To cybersecurity professionals, the answer seems obvious – cyber threats are looming, larger than ever. For highly regulated industries, the need for cyber risk oversight is even greater. Financial institutions and insurers are increasingly making cyber risk a board-level priority.
A new report from Datos Insights highlights this critical trend, finding that businesses that adopt integrated cyber governance, risk and compliance (GRC) frameworks are not only better equipped to manage risk but also more resilient and competitive.
According to the research, board and C-suite cyber GRC technology is now the second-largest planned cybersecurity investment for North American FIs in 2025, marking a major industry shift. With increasing regulatory pressures — such as the SEC’s 2023 cybersecurity risk management rules — and rising cyber threats, organisations can no longer afford fragmented governance, risk, and compliance (GRC) approaches.
Key Findings: Cyber Risk Oversight at the Board Level
The Datos Insights study, which surveyed CISOs and cyber-risk leaders from 20 North American regulated firms, reveals that financial institutions are rapidly prioritising board-level cyber risk oversight. Among the key findings:
- 57% of financial institution risk leaders rank improving cyber risk oversight at the board level as their top priority for 2025.
- 60% cite high resource impact on staff as the most severe pain point with current board-level cyber GRC solutions.
- Enterprise risk visibility and cyber risk quantification (CRQ) remain significant gaps, preventing many organisations from effectively assessing and mitigating cyber threats.
The Challenge: Overcoming Siloed and Inefficient Cyber GRC Practices
Historically, cyber risk management has lagged behind other traditional GRC functions in maturity. While organisations have long-established frameworks for managing financial, operational and compliance risks, cyber risk remains a highly dynamic and evolving challenge. The rise of remote work, digitalisation and third-party dependencies has only compounded the complexity.
Without an integrated cyber GRC platform, many financial institutions struggle with:
- Siloed data and inconsistent reporting make it difficult to track and respond to risks in real time.
- Lack of board-level cyber expertise is limiting the effectiveness of oversight and governance.
- Regulatory pressure demanding greater transparency and incident disclosure.
Diligent One Platform: The Solution
As organisations work to modernise their cyber strategies, the Diligent One Platform has been recognised as a leading GRC solution. By providing real-time insights into cyber risks, automating compliance workflows and streamlining board reporting, Diligent One helps boards and C-suite leaders stay ahead of evolving cyber threats.
Key capabilities include:
- Integrated dashboards and AI-driven insights, enhancing board-level risk visibility.
- Automated compliance tracking, streamlining regulatory reporting and disclosures.
- Enterprise-wide risk quantification, enabling leaders to measure and mitigate cyber threats effectively.
What’s Next for Cyber GRC?
As CROs, CISOs and general counsels increasingly work in partnership with boards on cyber risk and compliance oversight, organisations must rethink how they govern, manage and respond to cyber risk. As regulatory scrutiny intensifies and cyber threats grow more sophisticated, the ability to demonstrate cyber resilience will become a defining factor for financial institutions.
For those still relying on disconnected cyber risk management tools, the Datos Insights report serves as a clear warning: unified cyber GRC is no longer optional — it’s a competitive necessity.




