Five Governance Gaps Behind Cybersecurity Assessment Findings
Sam Lewis, Manager, Assessments and Advisory, Strategy and Risk Team

“Technical weaknesses may drive individual findings, but ownership and accountability determine whether they are addressed.“
Key Takeaways
- Supply chain risk needs clear ownership across procurement, security, legal, and leadership.
- Policies and system documentation must reflect what is actually implemented.
- Asset inventories and assessment boundaries must reflect the full environment.
- Incident response and recovery plans need regular testing.
- Every assessment finding needs an owner, due date, and path to closure.
Across hundreds of cybersecurity assessments aligned with NIST CSF, FISMA, and FedRAMP, the same issues continue to appear. The most serious findings are often not highly technical. They stem from gaps in ownership, documentation, scope, testing, and follow-through.
They affect organizations of every size, but supply chain risk has become especially difficult to manage.
1. Supply Chain Risk Has Outgrown Vendor Management
Many organizations still manage third-party risk through procurement questionnaires, contract language, and periodic reviews. Those steps matter, but they do not establish who can accept risk, require remediation, or end a vendor relationship.
Verizon’s 2025 Data Breach Investigations Report reported that third-party involvement doubled from 15% to 30% of breaches.¹ In its 2026 executive summary, that figure rose another 60%, reaching 48%.² IBM found that breaches involving third-party vendor and supply chain compromise averaged $4.91 million and took 267 days to identify and contain.³
NIST CSF 2.0 reflects this shift by placing cybersecurity supply chain risk management within the Govern function under GV.SC, which includes ten subcategories.4 Managing supplier risk requires executive oversight, defined risk tolerance, and clear escalation authority. Neither procurement nor security can manage it alone.
Yet no one has clear authority to act when a supplier’s cyber risk exceeds the organization’s tolerance. Often, no one has clear authority to act when a supplier’s cyber risk exceeds the organization’s tolerance. Teams may identify the risk but have no consistent way to accept it, require changes, or reject the supplier.
2. Documentation Does Not Match the Operating Environment
Documentation often describes controls that are not operating as written. A System Security Plan may state that MFA is enforced, or data is encrypted at rest, but interviews and supporting evidence show otherwise. Because PL-2 requires the system plan to describe the operational environment and the controls in place, these discrepancies may result in findings under PL-2 or the controls described in the plan.5
CSF 2.0 places policy, oversight, and accountability within the Govern function. Assessors compare the written program with supporting evidence and observed practices. That mismatch can raise questions about the accuracy of the broader assessment package.
3. Scope and Asset Inventories Are Incomplete
Incomplete asset inventories, missing network diagram segments, and undocumented cloud services remain common findings under the CSF Identify function. Verizon’s 2026 DBIR reported that exploitation of vulnerabilities had become the most common initial access vector, reaching 31% in the reporting dataset.⁶
Undocumented assets can change the system boundary, add control requirements, and reveal gaps in patching or monitoring.
4. Incident Response and Recovery Plans Have Not Been Tested
An incident response plan has limited value if it has never been exercised. Recovery procedures are equally uncertain until a team completes an actual restore.
NIST SP 800-61 Revision 3, published in April 2025, integrates incident response across all six CSF 2.0 functions.7 Verizon’s 2026 DBIR found ransomware in 48% of breaches. That prevalence makes regular response and recovery testing especially important.8
Common examples include plans with no record of a tabletop exercise, unvalidated recovery time objectives, and no coordination process for an incident involving a critical supplier. Tabletop exercises and successful backup restores help teams identify these weaknesses before a disruption.
5. Findings Lack Clear Ownership and Follow Through
Without a named owner, remediation can stall between IT, security, compliance, and other teams. CSF 2.0’s Govern function calls for clear roles, responsibilities, and authority for managing cybersecurity risk.9
Signs of weak ownership include blank milestone dates, generic department names, and overdue POA&M items. In one engagement, a formal POA&M replaced ad hoc email tracking and helped the client close most open findings within one quarter.
Why Governance Matters After an Assessment
Four of these five gaps fall wholly or partly within the CSF 2.0 Govern function.
Technical weaknesses may drive individual findings, but ownership and accountability determine whether they are addressed.
Progress depends on assigned responsibility for supplier risk, documentation, asset scope, recovery, and remediation. NIST SP 1305 offers a useful starting point for organizations building a cybersecurity supply chain risk management program aligned with CSF 2.0.10
CISO Global helps organizations identify cybersecurity weaknesses and develop prioritized remediation plans based on business needs and regulatory requirements.
Endnotes
1 Verizon Business, 2025 Data Breach Investigations Report (2025), https://www.verizon.com/business/resources/Tea/reports/2025-dbir-data-breach-investigations-report.pdf.
2 Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026), https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf.
3 IBM, Cost of a Data Breach Report 2025: The AI Oversight Gap (2025), https://www-api.ibm.com/adobe/assets/urn%3Aaaid%3Aaem%3A607b9590-38e0-4c91-b433-aa8a17f5b5e8/original/as/cost-of-a-data-breach-2025-full-report.pdf.
4 National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST Cybersecurity White Paper 29 (February 26, 2024), https://doi.org/10.6028/NIST.CSWP.29.
5 National Institute of Standards and Technology, Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53, Revision 5 (September 2020, updated December 10, 2020), https://doi.org/10.6028/NIST.SP.800-53r5.
6 Verizon Business, 2026 Data Breach Investigations Report: Executive Summary.
7 National Institute of Standards and Technology, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST Special Publication 800-61, Revision 3 (April 3, 2025), https://doi.org/10.6028/NIST.SP.800-61r3.
8 Verizon Business, 2026 Data Breach Investigations Report: Executive Summary.
9 NIST, The NIST Cybersecurity Framework (CSF) 2.0.
10 National Institute of Standards and Technology, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management (C-SCRM), NIST Special Publication 1305 (October 2024), https://doi.org/10.6028/NIST.SP.1305.