let's deep in.

“Pensare la complessità. Governare il cambiamento”

Riflessioni e prospettive su cybersecurity, governance, risk, compliance e trasformazione digitale.
Un punto di osservazione indipendente sui temi che stanno ridefinendo il modo in cui le organizzazioni comprendono, governano e proteggono il proprio valore.

AI Governance before AI Adoption

This article examines the need to develop artificial intelligence governance models prior to its operational adoption, highlighting how the pace of technological integration within organizations risks outpacing the maturity of control systems. Through an analysis of the AI Act, the NIST AI Risk Management Framework, and the ISO/IEC 42001 standard, the text demonstrates that governance must be conceived as a preventive, cross-functional, and iterative function capable of guiding innovation without compromising security, compliance, and human oversight. The article argues that AI is not merely an emerging technology but a new organizational dimension that requires integrated risk management competencies, responsibilities, and processes throughout the entire system lifecycle. From this perspective, governance does not slow down innovation; rather, it is the enabling condition for it.

Leggi tutto

When Compliance Becomes Strategy

This article analyzes the evolution of the role of compliance in modern governance systems, highlighting the shift from a reactive approach—focused on regulatory compliance—to a proactive model of “compliance by design.” By examining European regulatory frameworks—in particular the GDPR and the NIS2 Directive—and the principles of ISO 31000, the text demonstrates how contemporary regulation requires the integration of risk management and compliance safeguards right from the design phase of processes. Compliance thus emerges as a strategic function, capable of anticipating risks, guiding organizational decisions, and contributing to the resilience and sustainability of operational structures. The article argues that compliance should not be interpreted as a mere constraint, but as a driver of innovation and competitive advantage, capable of generating long-term value.

Leggi tutto

Sign up for the PF ADVISORY newsletter!

Receive our periodic analysis of trends, regulations, and threats in information security, as well as articles on compliance and cybersecurity.

Evolving Governance, Risk, and Compliance
from a control function
to a value driver.