First Annual Report

The State of Continuous Controls Monitoring

tcs_report_2024_2_draft_002_Page_01-2-768x613

Download the Report

Top challenges for CISOs satisfying regulatory requirements

52
%
maturing the compliance program
42
%
data and system silos
41
%

lack of a centralized system

See expert insights from nearly 200 CISOs

As technological and regulatory challenges continue to grow, the GRC landscape is at a critical inflection point. Limited by costly, manual GRC processes and legacy tools, organizations are struggling to keep up.

Now, for the first time ever, the CISO Society and RegScale are releasing the State of Continuous Controls Monitoring report. Gathering insights from nearly 200 CISOs, the report offers findings on organizational readiness to meet GRC challenges.

The report revealed that CISOs are struggling across every sector with manual processing, data silos, inadequate staffing, limited integrations, and a lack of modern tech adoption. It also revealed a substantial need for Continuous Controls Monitoring (CCM) to automate and accelerate legacy GRC programs and future-proof compliance.

Resource-Image-State-of-CCM-1600x900-1

Only 5% of CISOs consider their compliance program to be optimized for efficiency and continuous improvement. But there is hope — in thinking about how technology will impact their business, nearly 95% of CISOs believe that continuous controls monitoring will improve both compliance and security.

– The State of Continuous Controls Monitoring Report

What do CISOs want to prioritize first in their GRC strategy?

55
%
reducing manual processing
14
%
a single pane of glass
12
%

more rapidly applying goverance

10
%

improving ROI on existing tools

tcs_report_2024_2_draft_002_Page_01-2-768x613

95% of CISOs Believe CCM Will Improve Compliance and Security

Read RegScale’s industry-first 2025 State of Continuous Controls Monitoring report to learn how compliance experts view automation, manual processes, and regulatory challenges. Gathering insights from nearly 200 CISOs, the report offers findings on top GRC challenges — and explains how CCM can help.