
Loading summary
A
This is the story of the 1. As the purchasing manager at a manufacturing plant, she knows the only thing more important than having the right safety gear is having it there when you need it. That's why she partners with Grainger for auto reordering, so her team members can count on her to have cut resistant gloves on hand and each shift can run safely and efficiently. Call 1-800-GRAINGER click granger.com or just stop by Grainger for the ones who get it done.
B
This is Scott Becker with the Becker Business in the Becker Private Equity podcast. We're thrilled today to be joined by a brilliant leader in the cybersecurity space. We're joined today by the CEO of Acuity Risk Management, David Rajakovich. And David's going to talk to us about trends he's watching in cybersecurity, AI, continuous risk intelligence and monitoring, and a lot more. David, can you take a moment to introduce yourself and tell us a little bit about Acuity Risk Management?
C
Sure. Like you said, Scott, my name is David Radnickowicz. I'm CEO at Acuity Risk Management. Acuity Risk Management is a cyber GRC software company. So that stands for governance, risk and compliance. And what we do is help organizations manage their cyber risk. That's it in a nutshell. I'm sure I'll go into a lot more of what we do as we go along, but thanks, Scott.
B
No, thank you so much. And in terms of that area of cyber risk, this is one of the hugest areas out there and there's constant reports about how to getting worse and worse and more and more challenging. With artificial intelligence and more you operate sort of this intersection of cybersecurity governance, enterprise risk. What are the biggest shifts that you're seeing in how boards CEOs think about risk as we move into 2026?
C
Yeah, absolutely. So there's a direct correlation between data breaches and share prices, which CEOs and boards are clearly taking notice of. Stock prices can continue to decline even up to 90 days after an incident is what we've seen. Marks and Spencer here in the UK was badly hit, their share price badly damaged by an incident, a data breach that came through one of their suppliers, a third party, risk and boards. Another shift that we're seeing are the boards are looking for an understanding of our current posture that is much more evidence based. So it's no longer enough to have a policy about something, but it's actually seeing data coming in and being able to interpret that data and understanding where we are. They're Also looking for are we more or less of a target versus our competition? We, we don't want to find ourselves on the below average end of a, of a benchmark. The, another shift that we've seen is that risk has become a strategic enabler. It's not just a cost center. So boards do want their companies to take technology risk, but they want to make sure that we're taking the right risks versus just taking risk for risk sake. So 84% of business leaders say, and they actually have said that their focus on cybersecurity has increased over the past three years. Give you another statistic, which is that 58% of boards now want their organizations, like I said, to take more technology risk. Even, even while 81% view cybersecurity as a key business risk. The final thing that I'll, I'll just mention is that the CISO role has, has evolved dramatically and CISOs have the ear of their CEOs much more often. In fact, 80% of them have, have interact directly with the CEO and that's that those are some of the trends that we're seeing.
B
And David, talk about a couple of these things before we move on this concept that companies want to take more technology risk because they know they've got to move faster into the artificial intelligence world, into the ability to do things in technology. At the same time, as you take more technology risk, you're opening yourself up to more uses, more potential incursions and so forth. Just talk about that dichotomy for one second and then also talk about this concept of, and this is not a new concept, but I love how you talked about it. People want to know how they compare to their peers. Do they become bigger targets than their peers? Is there a reason why they would be targeted versus others? How do they look at that? How do they make sure. So they're, they're at least in their class, as secure as possible, in the right spot. If you don't mind, take a moment of those two trends that you mentioned.
C
Yeah, sure. So, so clearly that if you're not using AI, you're going to be left behind. And, and the, I mean, whether it's, whether it's in terms of coding or whether it's decision making, everyone is using AI. The question is do you have some sort of AI governance framework in place that allows you to make decisions on what you allow users to use? So do you just allow them to use whatever they like? That's probably a bad idea because that, we've seen anything that you put into say, a ChatGPT or Claude or Gemini, especially not the paid plans that just goes into the public. So you can't have that. So you need to put some guardrails around it. It's good to have an AI governance framework to help you make those decisions.
B
David, talk about a little bit about this concept of you want to make sure that you're better protected than your peers and that you're in the right spot compared to your peers and what might make a peer or yourself a bigger target versus somebody else.
C
Yeah. If you are using, for instance, software with known vulnerabilities and you don't have the capability to respond and patch those vulnerabilities immediately, that could be one example. If you aren't using any sort of, or if you're, you're conducting assessments say every six months or every year versus more of a continuous monitoring of your posture, that would, that would make you much more vulnerable than your, than your peers because vulnerabilities are always changing, threats are always changing. And in an ideal circumstance you would have a model that is alerting you when your critical data is at risk. So one trend though is the CISOs are drowning in alerts and they have many different systems. Ideally they have one system that brings that all together, shows where threats, changing threats and changing vulnerabilities impact critical business systems. And that is throwing up an alert to say, okay, you really need to focus on this particular alert versus another one.
B
Thank you very much. Take a second on where do organizations have consistently sort of underestimate the risk posture and maybe a couple blind spots that organizations sometimes have?
C
Yeah, absolutely. I think one of the biggest ones is in third party cyber risk management. That's where we've seen a number of breaches occur. So Marks and Spencer's Jaguar, Land Rover, the Co Op here in the UK, those are some of the biggest examples. And third party involvement in breaches has doubled, rising from 15% to nearly 30%. So there's a growing recognition that we not only need to manage our internal vulnerabilities and risks, but also those of our suppliers with that have access to our critical data. We also need, there's a need for continuous monitoring. I mentioned there, it used to be okay to just conduct an assessment every six months or a year, but these days, especially as you alluded to with AI, the frequency of attacks and the sophistication of those attacks has increased. So the likelihood is your vulnerabilities are going to get exposed faster and therefore you need continuous monitoring and you need to update your priorities rather than just kind of working through a long list of alerts. These, these are still underestimated in our experience as well as another thing that we've alluded to already is this concept of shadow AI and ungoverned technology adoption. And these, this is one where leaders are struggling to identify how they need to close those gaps.
B
Thank you. And talk about, you mentioned this about continuous risk intelligence rather than one off assessments. I mean the old days somebody brought in an audit firm, they did every once in a while they sort of had a clean slate for the period of time. Now it's moved much more towards constant real time monitoring of risk risk and cyber risk. How is it changing the game in terms of how larger and even midsize and smaller enterprise operate? How is that changing the game? Sort of the constant real time risk monitoring.
C
Yeah, so the, the speed of decision making is increasing. So if you see that, so if there's a particular control that you've applied, let's say multi factor authentication or mfa, and you see that it's not applied consistently, especially in a very critical business system, let's say in a billing system or a customer portal, then those vulnerabilities are constantly changing. So the speed of your decision making is increasing. And if your speed isn't increasing, then you're falling behind your peers. And I would say the other, another element to how the game is being changed is prioritization based on actual risk. So you, you mentioned there's, there's one point in time assessments and that just really creates noise because by the time you've, you've done another assessment in six months, the priorities, if your priorities haven't changed, then you are very likely addressing the wrong risk. But continuous monitoring, so continuously monitoring these vulnerabilities and also your threats and also the level of deployment of your controls or level of effectiveness of your controls that allows you to focus resources on what matters right now. And if all CISO teams will tell you they are under resourced for everything they're being asked to do, therefore they need that prioritization.
B
Thank you. And take a second on how AI is changing the game. You touched on it a little bit, but a big article this morning, I think in the Wall Street Journal about how AI is increasing risk for companies about cyber security and governance. Talk a bit about where AI fits into this and how that much more important continuous risk monitoring is in defense.
C
Is yeah, absolutely, massively important. And what I would say to organizations looking to get started is start with the a risk Management framework. So it could be using a standard like the NIST AI Risk Management Framework. Choose that rather than going for a particular tool right off the bat. And in fact, so I did caution against tools. I will mention a new product that we're working on which is, which is AI native that will allow you to align to a governance AI risk governance framework and also tweak that to make it custom to your particular organization. So you'll be able to define your maturity levels by business service. So again the business service would be an E commerce site, it could be your website, it could be a billing system for pharmaceutical companies, it could be IP repository. So you define your critical systems. And AI is very good at categorizing and scoring unstructured data so it can ingest all this, all the different, lots of different types of evidence, for instance from your vulnerability scanning tool and give you a score on where you are. The other piece of advice I would give is to maintain a AI bill of material so understand where in your software AI is being used as, as a first step in being able to understand where your vulnerabilities might lie. Finally, I would say make sure you establish accountability for, for who is, who is responsible for making sure that we're using AI responsibly and in a way that's in line with our policies.
B
Thank you. And take a second David. This sort of. When you look at businesses today, mid size, large size, small, whatever it is, what are the most important steps they should be taking right away to improve the risk profit posture from a cyber perspective, what's the most important things they could do? Currently?
C
Yeah, I think the number one item I would start with is to identify and categorize your 3 to 5 most critical business systems I mentioned for a pharmaceutical company that might be whatever database or IT system holds your intellectual property for your drugs. Take those, identify those and identify the, so the software bill of materials, all the different pieces of software that make up that repository. Get an understanding of which suppliers might have access to that critical data. Where might those entry points be through third parties? After you've, you've identified those critical business systems and your software bill of materials and your third parties that may have access to those systems. Then it's about getting a handle on where your weaknesses lie. Where, where are you most exposed, where do you have the most vulnerability and where are those threats coming from? Once you do that, then you have a better idea understanding of what actions you need to take to, to secure those most critical systems. So you say you're Doing vulnerability patching, you won't just go down a big list of vulnerabilities, but rather you'll focus on those vulnerabilities that impact your most critical business services or those most critical systems. You'll also focus your third party risk management. You won't just send out the same questionnaire to thousands or tens of thousands of suppliers but but rather you'll focus on the ones that have the most access to your critical data and you'll work with them to patch up those vulnerabilities and also to build resilience into the system. So can you isolate part of your IP repository if there is an attack so that the damage is limited versus damage that we've seen on the scale of say a Marks and Spencer where their share price was absolutely massacred.
B
Talk for a second David, about sort of how you ended up in this risk business and about a little bit about your history and that of Acuity Risk Management, if you don't mind.
C
Sure. Acuity Risk Management has been around for over 20 years and it was founded by two gentlemen that are highly experienced and world class experts in the area of Cyber grc. So this has always been our focus. It started more of a consultancy and has now grown into a software business. So we've got our classic Stream software which is incredibly adaptable and handles cybersecurity risk management for some of the top echelons of the public sector and the private sector. So if you're looking for the credentials of someone who deals with the most sensitive data that you can imagine, then that is someone that we are someone you should be talking to. That's a bit of the history of Acuity Risk Management. I have been here since the second half of December in 2024. My background is in technology of many different types, most relevantly in education technology. So I was a co founder and then became the CEO at Skill Dynamics which is a education technology company that delivered training for supply chain and procurement professionals. And I've gone through two different private equity. We grew up the company as a bootstrap company and went through two private equity, very successful private equity exits. So I've worked a great deal in the private equity space. And now Acuity Risk Management, which is adding to my experience, is a publicly traded company on the AIM stock exchange. So there is, there is quite a bit of difference there which I could, I'd be happy to expound upon at some point. That's a bit about Acuity Risk Management and my, my background.
B
David, just remarkable and fantastic to visit with you today about acuity risk management, about cyber risks which are escalating, it seems like daily, and about acuity risk management and how you provide continuous intelligence in risk management versus sort of this one off assessment. Love it. David Radjacovich, thank you so much for joining us today on the Becker Business and the Becker Private Equity podcast. Just fantastic. Thank you very, very much.
C
Great. Thank you. Scott.
D
You know that wellness goal you set at the start of the year? It's not too late to stick with it and make your future self proud. Especially with The all in One Nutrition Shake from Cachava with 25 grams of protein, 6 grams of fiber, greens, adaptogens and more. No fillers, no nonsense, just the highest quality ingredients. Stick with your wellness goals. Go to kachava.com and use code NEWS for 15% off. That's K-A-H-A-V-A.com code NEWS.
Date: February 16, 2026
Host: Scott Becker
Guest: David Rajakovich, CEO of Acuity Risk Management
This episode spotlights David Rajakovich, CEO of Acuity Risk Management, in a deep-dive discussion on the latest trends in cybersecurity, particularly at the intersection of enterprise risk, governance, and artificial intelligence (AI). The conversation explores how company boards and executives are adapting to an evolving risk landscape characterized by continuous threats, regulatory scrutiny, and the rapidly rising importance of real-time risk intelligence.
On Evolving Board Priorities:
On Evidence-Based Security:
On AI and Governance:
On Continuous Risk Monitoring:
On Third Party Risk:
On Prioritization:
| Timestamp | Topic / Quote | |-----------|---------------| | 01:00 | Rajakovich introduction, what Acuity does | | 01:52 | CEO/board shifts, link between breaches and share price | | 04:52 | Dichotomy of tech risk and AI, need for AI governance | | 06:01 | Peer benchmarking and risk | | 07:30 | Underestimated risks: third-party risk, need for continuous monitoring | | 09:38 | Continuous risk intelligence and real-time monitoring | | 11:38 | AI’s impact, risk frameworks, AI bill of materials | | 14:01 | Key steps all businesses should take for better risk posture | | 16:34 | Acuity Risk Management and Rajakovich’s background |
The conversation is thoughtful, pragmatic, and refreshingly transparent about the challenges faced by business leaders in the cybersecurity space. Rajakovich’s approach is earnest, practical, and grounded in real-world examples, while Scott Becker maintains a journalistic yet approachable style.
Cyber risk is a boardroom issue and strategic enabler in 2026.
Evidence-based, continuously updated intelligence—powered increasingly by AI—is replacing legacy approaches, and targeted action on the most critical systems and relationships has become the gold standard. For executives looking to future-proof their organizations, the clear mandate is: move beyond one-off audits, manage third-party risks, adopt a governance-first approach to AI, and focus resources where the business is most vulnerable.