|
시장보고서
상품코드
2092431
Measuring What Matters : 고객에게 필수적인 사이버 보안 지표 플랫폼 구축Measuring What Matters: Building the Cybersecurity Metrics Platform Your Customers Can´t Live Without |
||||||
사이버 보안 지표에 관한 총 2회 시리즈 중 두 번째 편인 이 IDC Market Perspective에서는 공급업체가 구축, 제공 및 수익화할 수 있는 데이터 기반의 3계층 구조(거버넌스, 관리, 운영)로 구성된 지표 프레임워크를 정의하고 있습니다. 전 세계의 조직들은 경영진, 이사회 및 운영 팀에 유용한 형태로 사이버 보안 위험을 측정하지 못하고 있으며, AI의 부상으로 인해 이러한 격차는 더욱 확대되고 있습니다. 기술 제공업체와 서비스 제공업체에게 있어, 이는 GRC 및 사이버 보안 시장에서 가장 중요한 차별화 기회 중 하나가 될 것입니다. AI는 적대적인 공격을 가속화하는 것과 적절한 거버넌스 없이 사내에 AI를 도입하는 것, 이 두 가지 측면에서 위협 상황을 재편하고 있습니다. 이러한 측면들은 모두 기존의 사이버 보안 지표로는 파악되지 않습니다. 섀도우 AI 탐지부터 에이전틱 AI 거버넌스, SaaS에 통합된 AI의 가시화에 이르기까지, AI 고유의 위험 측정 기능을 플랫폼에 통합한 제공업체는 모든 산업 분야와 조직 규모에 걸쳐 중요하면서도 아직 해결되지 않은 고객의 요구를 충족시킬 수 있을 것입니다. 본 자료에서는 섀도우 AI, 규제 준수 체계, 에이전틱 AI의 위험, 모델의 지적 재산권 보호, 그리고 SaaS에 통합된 AI를 포괄하는 전용 AI 위험 지표를 활용하여 3단계 프레임워크를 확장하고 있습니다. 원어민 수준의 AI 거버넌스 기능을 갖춘 GRC 플랫폼을 도입하고, 지표를 비즈니스 리스크와 연계하며, 투명성이 높고 검증된 인사이트를 활용해 대상자별 의사결정을 지원하는 조직이야말로, 오늘날 AI가 주도하는 위협 및 규제 환경에서 자신 있게 주도적인 입지를 구축할 수 있을 것입니다. "AI 시대는 조직이 사이버 보안 위험을 측정하는 방식에 대한 근본적인 재검토를 요구합니다. AI 시스템이 거버넌스, 측정, 설명 책임 없이 운영되고 있음에도 불구하고, 이사회에 방화벽 차단 건수만 보고하는 것은 더 이상 용납될 수 없습니다. 통합된 인텔리전스 플랫폼을 기반으로 구축되고, 모든 대상 수준에서 AI 특유의 위험을 포착하도록 확장된 데이터 기반 지표는 더 이상 모범 사례에 그치지 않습니다. 이는 비즈니스에 있어 필수 요건입니다."라고 IDC의 거버넌스, 리스크, 컴플라이언스 솔루션 담당 리서치 디렉터인 필립 해리스(Philip Harris) 씨는 말했습니다.
This IDC Market Perspective, part 2 of a two-part series on cybersecurity metrics, defines a data-driven, three-tier metrics framework (governance, managerial, and operational) that providers can build, deliver, and monetize. Organizations worldwide are failing to measure cybersecurity risk in ways that serve their executives, boards, and operational teams, and the emergence of AI has widened that gap. For technology providers and service providers, this represents one of the most significant differentiation opportunities in the GRC and cybersecurity market.AI is reshaping the threat landscape on two fronts: accelerating adversarial attacks and deploying AI internally without adequate governance. Neither dimension is captured by traditional cybersecurity metrics. Providers that embed AI-specific risk measurement capabilities, from shadow AI detection to agentic AI governance and SaaS-embedded AI visibility, into their platforms will address a critical, unmet customer need across every industry and organization size.This document extends the three-tier framework with dedicated AI risk metrics covering shadow AI, regulatory compliance posture, agentic AI risk, model IP protection, and SaaS-embedded AI. Organizations that implement GRC platforms with native AI governance capabilities, align metrics to business risk, and empower audience-specific decision-making with transparent, validated insights will be best positioned to lead with confidence in today's AI-driven threat and regulatory environment."The age of AI demands a fundamental rethink of how organizations measure cybersecurity risk. Reporting firewall blocks to boards while AI systems operate without governance, measurement, or accountability is no longer acceptable. Data-driven metrics, built on a consolidated intelligence platform and extended to capture AI-specific risk at every audience level, are no longer a best practice. They are a business imperative," says Philip Harris, research director, Governance, Risk, and Compliance Solutions, IDC.