SamSearch
    Wall of LovePricing
    Book a DemoSign In
    LogoSamSearch
    Close contracts faster than humanly possible.
    Ask AI About SamSearch

    Ask your favorite AI assistant about SamSearch and government contracting.

    • Ask ChatGPT
    • Ask Claude
    • Ask Perplexity
    YoutubeLinkedinDiscordTwitterMedium Facebook
    Recognized & verified
    SOC 2 Type II Compliant — SamSearchAWS Partner - Advanced — SamSearch on AWS MarketplaceGartner Peer Insights Customer First — SamSearch
    Contact Us
    Terms of Use
    Privacy Policy
    Compliance
    Trust Center
    Support
    Pricing
    ROI Calculator
    Careers
      Resources
      • Guides
      • Implementation Plan
      • Free GovCon Tools
      • NAICS AI Search
      • Capability Statement Builder
      • GovCon Glossary
      • Contracts
      • Set-Aside Programs
      • Statistics
      • Blog
      • Changelog
      • Comparisons
      • Alternatives
      • Docs
      • Browse NAICS Codes
      Home/News/Topics/Risk Management

      Topics

      Risk Management

      49 signals

      Signals

      CybersecurityInformation TechnologyRisk ManagementProcurementFederal CompliancePolicy
      2 days ago

      Shift to Continuous Threat Exposure Management Improves Cybersecurity Procurement

      The cybersecurity sector is moving towards Continuous Threat Exposure Management (CTEM), shifting from static vulnerability assessments. This dynamic approach is crucial for government agencies managing industrial control systems and IIoT, incentivizing procurement teams to seek solutions that enhance real-time risk evaluation and prioritization.

      CybersecurityInformation TechnologyOpen Source SoftwarePublic SectorRisk ManagementPolicy
      5 days ago

      CISA Unveils Guidance on Open Source Software Security for Federal Agencies

      The Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance aimed at helping federal civilian agencies securely adopt and manage open-source software (OSS). This guidance highlights the importance of the C4 Framework, which will be critical for assessing the trustworthiness of OSS and ensuring compliance with recent executive orders.

      CybersecurityInformation TechnologyEU RegulationsProcurementRisk ManagementPolicy
      6 days ago

      Germany Mandates Cybersecurity Executive Training Under NIS-2 Directive

      As Germany enforces mandatory cybersecurity training for executives, companies face potential penalties for non-compliance. The NIS-2 directive aims to elevate cybersecurity standards, emphasizing personal liability and risk management for leadership in affected industries.

      CybersecurityPublic SafetyCritical InfrastructureWater UtilitiesRisk ManagementGeneral
      8 days ago

      Minnesota Water Utilities Face Cyber Threats Following CISA Warning

      Several Minnesota municipal water utilities recently reported cyber incidents affecting operational technology, underscoring vulnerabilities in critical infrastructure. This highlights an urgent need for enhanced cybersecurity measures and procurement opportunities for contractors in the sector.

      Grants & FundingAgriculture AssistanceDisaster ReliefProcurementRisk ManagementGeneral
      8 days ago

      USDA Notifies Producers of Upcoming August Assistance Deadlines

      The USDA's Farm Service Agency (FSA) alerts agricultural producers about critical deadlines for disaster assistance programs in August 2026, including the ASCF and SDRP. These programs play a vital role in providing financial stability to producers grappling with rising costs and natural disasters, necessitating prompt engagement with FSA offices.

      CybersecurityInformation TechnologyRisk ManagementPolicy
      9 days ago

      Federal Reserve OIG Identifies Gaps in Insider Risk Management Program

      The Federal Reserve Board's Office of Inspector General has pinpointed critical deficiencies in the insider risk management program. This presents opportunities for contractors specializing in risk management solutions and cybersecurity services as the Board commits to implement recommended improvements by late 2027.

      Regulatory ComplianceInformation TechnologyAI GovernanceRisk ManagementProcurement StrategyPolicy
      9 days ago

      EU and South Korea Enforce New AI Regulations Affecting Contractors

      The European Union and South Korea have initiated the enforcement of their AI regulations, creating significant compliance challenges for telecommunications and technology providers. Companies must prepare for heightened scrutiny and penalties associated with non-compliance in their AI deployments.

      CybersecurityInformation TechnologySAP SecurityProcurementRisk ManagementPolicy
      10 days ago

      Agencies Prioritize Enhanced Security for SAP ERP Systems

      Government agencies focus on strengthening SAP security within their cybersecurity strategies to prevent data breaches. This increased attention emphasizes the need for procurement teams to seek vendors with specialized knowledge in both cybersecurity and SAP governance compliance, signaling opportunities in the market for such solutions.

      CybersecurityDefense & MilitaryProcurementRisk ManagementIntelligenceContract
      11 days ago

      U.S. Army Seeks Program Manager for Vendor Threat Mitigation in Stuttgart

      The U.S. Army Installation Management Command is hiring a Program Manager for Vendor Threat Mitigation to reduce risks from adversarial commercial support in Africa. This role is crucial for securing military operations and offers a competitive salary for qualified candidates with security clearance.

      CybersecurityInformation TechnologyFirmwareVulnerabilitiesSecure BootRisk ManagementGeneral
      11 days ago

      ESET Identifies Vulnerabilities in Microsoft-Signed UEFI Shims, Threatening Secure Boot

      ESET has reported 11 vulnerabilities in UEFI shim bootloaders signed by Microsoft, allowing attackers to sidestep UEFI Secure Boot. This discovery poses significant risks for government and critical infrastructure, necessitating immediate firmware updates and patching to ensure security. Cybersecurity contractors must prioritize these updates to protect their systems.

      CybersecurityInformation TechnologyProcurementRisk ManagementAIPolicy
      13 days ago

      AI Automation in Cybersecurity Reporting: A Balancing Act for Government

      Government cybersecurity leaders are assessing the integration of AI for automating vulnerability reports. Although AI could enhance efficiency, there are significant concerns regarding the reliability of its outputs, which may impact decision-making processes at the executive level.

      CybersecurityInformation TechnologySoftware Supply ChainRisk ManagementPolicy
      13 days ago

      Federal Agencies Embrace SBOM Services to Enhance Cyber Resilience and Security

      The use of Software Bill of Materials (SBOM) services is becoming a priority for federal agencies like **NIST** and **CISA** as they integrate these tools into their cybersecurity strategies. This trend offers procurement professionals insights into growing federal demand for enhanced software transparency and supply chain risk management capabilities.

      CybersecurityInformation TechnologyFedRAMPRisk ManagementComplianceCompany
      15 days ago

      CISO Global Enhances Compliance Capabilities with Expanded TiGRIS Platform

      CISO Global has automated and expanded its FedRAMP-certified TiGRIS platform to address complex compliance needs of federal clients. The integration of generative AI capabilities positions TiGRIS as a critical tool for contractors looking to enhance compliance operations and reduce risks in line with evolving federal standards.

      CybersecurityPublic SafetyOperational TechnologyRisk ManagementPolicy
      16 days ago

      U.S. Infrastructure Faces Cyber Threats, Boosts Procurement Opportunities

      U.S. critical infrastructure sectors are increasingly vulnerable to cyber-physical threats, necessitating procurement of advanced cybersecurity solutions. Contractors specializing in operational technology modernization are uniquely positioned to assist agencies in mitigating these risks.

      CybersecurityInformation TechnologyProcurementRisk ManagementPolicy
      20 days ago

      Evolving Expectations Drive Changes in Security Questionnaire Practices

      Government and industry procurement professionals must adapt to new security questionnaire demands. Shifting focus beyond SOC 2 assessments, organizations are urged to integrate comprehensive security controls, ensuring better vendor risk evaluation and compliance verification.

      Regulatory ComplianceAgricultureLitigationProcurementRisk ManagementPolicy
      22 days ago

      Oklahoma Governor Stitt Criticizes Poultry Settlement for Farmers' Future

      Governor Kevin Stitt of Oklahoma expressed strong concerns regarding a proposed multimillion-dollar settlement related to a long-standing lawsuit against poultry producers. The settlement, if approved, may lead to regulatory uncertainties impacting family-run farms and the agricultural sector in the state.

      CybersecurityInformation TechnologyRansomwareInsider ThreatsRisk ManagementCompany
      26 days ago

      Former Cybersecurity Negotiators Sentenced for Roles in BlackCat Ransomware Attacks

      Three ex-negotiators from DigitalMint and Sygnia received four-year prison sentences for their involvement in ransom schemes affecting major U.S. organizations. This event exposes insider threat vulnerabilities in cybersecurity contracts, prompting a reevaluation of vendor selection and oversight strategies across the sector.

      CybersecurityInformation TechnologyFedRAMPRisk ManagementCompliancePublic SectorAward
      27 days ago

      Vanta Secures FedRAMP 20x Class C Certification for Enhanced Cybersecurity Solutions

      Vanta has achieved FedRAMP 20x Class C certification for its Government Cloud platform, improving access for federal agencies. The certification supports IT modernization efforts and enhances compliance for contractors and resellers focused on cybersecurity and risk management.

      CybersecurityInformation TechnologyRisk ManagementFederal RegulationsPolicy
      34 days ago

      NIST Enhances Federal Cybersecurity Risk Management Guidance with New Publication

      The National Institute of Standards and Technology (NIST) released Special Publication 800-18 Revision 2, providing updated guidance on developing crucial system security and cybersecurity supply chain risk management plans. This revision emphasizes automated, machine-readable formats, offering significant procurement implications for federal agencies and contractors in aligning practices with federal standards.

      Regulatory ComplianceInformation TechnologyRisk ManagementProcurement StrategiesResearch FundingContract
      40 days ago

      IARPA Rejects Proposal Over Technical and Scheduling Risk Concerns

      The Intelligence Advanced Research Projects Activity (IARPA) has rejected a proposal from a small business and university due to significant risks associated with technical execution and scheduling. This decision underscores the importance for contractors to emphasize risk management strategies in their submissions to align with IARPA's demanding evaluation framework.

      CybersecurityInformation TechnologyComplianceCloud SolutionsRisk ManagementPolicy
      41 days ago

      FedRAMP 20x Introduces Continuous Cybersecurity Compliance

      FedRAMP 20x is shifting federal cybersecurity compliance from point-in-time audits to continuous, automated monitoring. This transition is crucial for contractors in governance, risk, and compliance engineering, granting new avenues for providing advanced compliance technologies.

      CybersecurityInformation TechnologyFederal ProcurementRisk ManagementPolicy
      42 days ago

      CISA Transitions to Integrated Cybersecurity Defense Strategy

      The Cybersecurity and Infrastructure Security Agency (CISA) is evolving its approach to federal cybersecurity by implementing an integrated defense system. This shift emphasizes the need for contractors with capabilities in cybersecurity integration and compliance, opening new procurement opportunities.

      CybersecurityInformation TechnologyProcurementRisk ManagementIoTPolicy
      44 days ago

      Critical libssh2 Vulnerability Demands Urgent Attention from GovCon Professionals

      Recent findings reveal a significant vulnerability in the libssh2 SSH library, impacting many government systems and IoT devices. Agencies must expedite patch implementation and assess vendor capabilities to mitigate security risks associated with this flaw.

      Supply Chain ResilienceRisk ManagementInternational TradeSecurityFood InsecurityGeneral
      47 days ago

      Supply Chain Leaders Respond to Security Risks in Emerging Markets

      Security threats in supply chains from Africa to Southeast Asia disrupt operations and increase costs. Procurement professionals are urged to enhance visibility and build coalitions to address vulnerabilities and ensure continuity.

      Regulatory ComplianceInformation TechnologyBlockchainCryptocurrencyRisk ManagementPolicy
      57 days ago

      UK Sanctions HTX Exchange, Impacting Global Blockchain Compliance

      The UK has imposed sanctions on HTX due to its facilitation of Russian sanction evasion. This move necessitates increased scrutiny and adaptation within procurement strategies for blockchain and crypto service vendors.

      CybersecurityInformation TechnologyRisk ManagementISO StandardsSoftware DevelopmentPolicy
      58 days ago

      Government Focuses on Vendor Compliance with ISO 27001 Security Testing Standards

      The government is closely examining vendor adherence to **ISO 27001:2022**, specifically focusing on **Control 8.29**. This mandate requires comprehensive risk-based security testing integrated into the software development lifecycle, influencing procurement strategies and vendor selection in government contracts.

      Regulatory ComplianceInformation TechnologySupply ChainGeopolitical RisksRisk ManagementGeneral
      58 days ago

      iKargos Launches Advanced Trade Risk Management Platform for Supply Chains

      iKargos has launched a cutting-edge trade risk management platform aimed at mitigating supply chain vulnerabilities linked to geopolitical risks and regulatory compliance. This solution will support government contractors and procurement teams in ensuring supply chain resilience while complying with OFAC and BIS regulations, amidst increasing enforcement of sanctions.

      CybersecurityInformation TechnologyFederal ProcurementRisk ManagementAutomationAward
      63 days ago

      NIST Grants Task Order to Tharros for Cybersecurity Framework Development

      The National Institute of Standards and Technology (NIST) has awarded Tharros a task order under its $125 million CAPSS contract. This contract enhances federal capabilities in cybersecurity by developing educational resources and automating tools aligned with Cybersecurity Framework 2.0, indicating strong demand for innovative cybersecurity solutions from contractors.

      Agricultural ServicesRisk ManagementFarm SupportARCPLCPolicy
      70 days ago

      USDA Introduces Base Acre Opportunities for Farmers in 2026

      The USDA's Farm Service Agency is granting landowners the chance to increase base acres from June 1 to August 31, 2026. This initiative is significant for procurement professionals as it may drive demand for agricultural services and enhance risk management support for farmers.

      CybersecurityInformation TechnologyVulnerabilitiesSupply ChainRisk ManagementPolicy
      75 days ago

      CISA Implements New Vulnerability Reporting to Combat Cyber Threats

      CISA has rolled out an enhanced nomination process for reporting Known Exploited Vulnerabilities (KEVs), aimed at improving cybersecurity defenses. This initiative will significantly impact procurement by necessitating greater focus on vendors' vulnerability management practices in alignment with federal compliance standards.

      Regulatory ComplianceForestryTimber SupplyEnvironmental PolicyRisk ManagementContract
      79 days ago

      Tasmanian Government Negotiates Long-Term Wood Supply Contracts Amid Regulatory Uncertainty

      The Tasmanian Government is in discussions with 14 sawmilling companies for wood supply contracts from 2027 to 2040. However, pending reforms to the EPBC Act pose risks of compensation liabilities and fiscal challenges if agreements are made before securing clarification on environmental regulations.

      Supply ChainGeopolitical RisksOperational ResilienceProcurement StrategiesRisk ManagementGeneral
      82 days ago

      Supply Chain Leaders Tackle Geopolitical Disruptions to Enhance Resilience

      Supply chain executives are developing strategies to address disruptions from geopolitical conflicts, such as those in the Strait of Hormuz. Key approaches involve risk assessments, manufacturing flexibility, and partnerships to protect against rising costs and supply shortages.

      CybersecuritySoftware Supply ChainCI/CD PipelinesRisk ManagementAI SecurityGeneral
      83 days ago

      TeamPCP Exposes Malware Targeting Software Supply Chain Security

      TeamPCP's release of the SHAI_HULUD malware source code raises alarm bells for procurement professionals. The incident highlights the urgent need for enhanced security measures in CI/CD pipelines and software development environments across government agencies and contractors.

      Grants & FundingAgricultureEducationRisk ManagementFederal ProgramsGeneral
      84 days ago

      FSA and University Partner for Nebraska ARC PLC Webinar on Producer Support

      The USDA's Farm Service Agency and the University of Nebraska-Lincoln will host a webinar on January 30, 2025, to educate commodity crop producers about the Agriculture Risk Coverage (ARC) and Price Loss Coverage (PLC) programs. The event aims to enhance understanding and participation, reflecting ongoing federal investment in agricultural revenue risk management.

      CybersecurityConsultingFederal ContractsMarket GrowthRisk ManagementGeneral
      86 days ago

      Cybersecurity Consulting Market Forecast to Surge to $119.1B by 2034

      The global cybersecurity consulting market is expected to reach **$119.1 billion** by **2034**, largely due to increasing regulatory requirements and evolving cyber threats. Federal agencies like **CISA**, **DHS**, and **NIST** will likely intensify procurement of compliance and risk management consulting services, opening significant avenues for leading contractors in the field.

      CybersecurityGovernment ContractsArtificial IntelligenceRisk ManagementPolicy
      86 days ago

      ASIC Calls for Urgent Cybersecurity Enhancements Amid Rising AI Threats

      The Australian Securities and Investments Commission (ASIC) has urged organizations, including government contractors, to improve their cybersecurity measures due to escalating AI-driven cyber threats. This could indicate increased scrutiny and compliance needs for contractors and market participants, necessitating robust defenses against evolving cyber risks.

      CybersecurityInformation TechnologySupply ChainCritical InfrastructureRisk ManagementPolicy
      86 days ago

      NIST Updates Cybersecurity Guidance for PNT Services Amid Rising Threats

      The National Institute of Standards and Technology (NIST) has released a draft update to its Positioning, Navigation, and Timing (PNT) cybersecurity profile to align with the revised Cybersecurity Framework 2.0. This revision addresses emerging threats in GPS reliability, AI risks, and supply chain vulnerabilities, urging federal agencies and contractors to adapt their cybersecurity measures accordingly.

      CybersecurityInformation TechnologyGovernment ContractsComplianceRisk ManagementGeneral
      88 days ago

      Contractors Face Significant Risks from ATO Compliance Failures

      Failure to secure an Authority to Operate (ATO) threatens government contract continuity and workforce stability. Understanding the risks involved with the Assessment and Authorization (A&A) process is essential for procurement professionals to safeguard their contracts against disruptions.

      CybersecurityInformation TechnologyBehavioral ScienceProcurement StrategyRisk ManagementPolicy
      89 days ago

      Agencies Prioritize Behavioral Science to Enhance Cybersecurity Strategies

      Government agencies are shifting their cybersecurity focus to include behavioral science, recognizing its importance in mitigating human risks. Procurement professionals are urged to seek solutions that foster a trust-based culture, moving beyond traditional compliance. This strategic change may alter requirements and evaluation criteria in upcoming contracts.

      CybersecurityInformation TechnologyRisk ManagementProcurement StrategyPolicy
      89 days ago

      CISA Orders Federal Agencies to Patch Ivanti Zero-Day Vulnerability by May 10, 2026

      The Cybersecurity and Infrastructure Security Agency has mandated federal agencies to address a critical vulnerability in Ivanti's Endpoint Manager Mobile by May 10, 2026. This requirement underscores the importance of cybersecurity measures and may impact procurement strategies for related technologies.

      CybersecurityInformation TechnologyRisk ManagementPolicy
      90 days ago

      Cyber Insurance Mandates Improved Identity Verification for Government Contractors

      Cyber insurance providers are raising identity verification standards significantly. Renewals now require detailed metrics, influencing premium costs and underscoring the need for improved cybersecurity practices among government contractors.

      CybersecurityInformation TechnologyPublic SectorProcurement StrategiesRisk ManagementGeneral
      91 days ago

      New Vulnerability Garden Catalog Enhances Cybersecurity Procurement Insights

      The Vulnerability Garden initiative has unveiled a centralized catalog detailing named cybersecurity vulnerabilities, aiding agencies in risk assessments. This resource allows contractors to align their solutions with identified threats, improving acquisition strategies.

      CybersecurityInformation TechnologySupply ChainRisk ManagementProcurementPolicy
      91 days ago

      Cybersecurity Vulnerabilities Exposed by Bleeding Llama Supply-Chain Attack

      The Bleeding Llama attack has compromised a video game platform, exposing vulnerabilities in software supply chains. This incident underscores the urgent need for enhanced cybersecurity measures within government procurement processes and could influence future contract requirements for vendors. Organizations are encouraged to revise their risk assessments and improve their monitoring strategies.

      Detention CentersProcurement StrategyRisk ManagementPublic SafetyComplianceAward
      92 days ago

      Oklahoma County Settles $7M Jail Lawsuit, Impacts on Procurement Expected

      The **Oklahoma County Jail Trust** has finalized a **$7 million** settlement concerning the 2021 death of inmate Brad Leon Lane, with costs being split between insurance and increased property taxes. This decision will significantly influence future procurement strategies within detention center operations, focusing on improved risk management and vendor oversight.

      InfrastructureProcurementTransportationSubcontractingRisk ManagementContract
      95 days ago

      Maryland Terminates Kiewit Contract, Reopens Bidding for Key Bridge Project

      Maryland has terminated its Phase 2 contract with Kiewit for the Francis Scott Key Bridge, citing excessive cost proposals. This creates new opportunities for contractors while reshaping the landscape of the state’s $5 billion infrastructure undertaking, emphasizing the critical need for competitive pricing amid federal-state collaboration.

      CybersecurityOperational TechnologyRisk ManagementStandards CompliancePolicy
      96 days ago

      NIST Initiates New Project To Enhance Operational Technology Cybersecurity

      The NIST's National Cybersecurity Center of Excellence has launched a critical cybersecurity initiative focusing on operational technology (OT). This project aims to address visibility challenges in OT environments, creating significant procurement implications for vendors offering cybersecurity solutions tailored for critical infrastructure.

      CybersecurityInformation TechnologyPenetration TestingProcurementRisk ManagementGeneral
      97 days ago

      Pentesting Sales Strategies Shift as Cybersecurity Needs Emerge Post-Incident

      Cybersecurity firms are adapting their penetration testing sales strategies due to low buyer awareness. Procurement professionals need to shift their timing and approaches, prioritizing educational outreach to increase demand and engagement with potential clients.

      Regulatory ComplianceDefense & MilitaryLitigationRisk ManagementGeneral
      100 days ago

      Supreme Court Reinstates Lawsuit Against Fluor Corp, Impacting Defense Contractors

      The Supreme Court has revived a lawsuit against Fluor Corp. regarding negligent supervision during an Afghanistan incident. This ruling highlights increased legal risks for defense contractors, prompting them to reassess contract terms, risk management strategies, and liability exposure in military operations.

      CybersecurityInformation TechnologyGovernanceRisk ManagementComplianceGeneral
      104 days ago

      ISSO Professionals Essential for Evolving Cybersecurity Roles in Government

      The demand for professionals with Information System Security Officer (ISSO) experience is rising as they transition into critical cybersecurity roles such as governance and compliance management. Agencies and contractors can harness this trend to enhance their security posture and meet compliance requirements through strategic hiring and training initiatives.