Who Owns the Risk?
Physical, Cyber, and Insider Threats Converged Into One Surface. Accountability for It Did Not. The Case for a Single Owner of Integrated Risk.

| ID | Statement | p | Made on | Resolves by | Status | Outcome |
|---|---|---|---|---|---|---|
| CLM-2026-178 | Baseline, rising spend against divided ownership, is the most probable path. | 0.65 | 2026-06-19 | 2027-06-19 | Locked |
A claim is entered in the brief's own words and carries its publication date and the day it entered the ledger: the register's briefs on 8 September 2026, when the standard was first applied; the forward benchmark on the day it was locked. It resolves only against a dated public source. The scoring rule is on the Methodology page.
The evidence base combines vendor- and recruiter-commissioned surveys from publishers such as the ASIS Foundation, Deloitte, PwC, and Verizon with primary legal and regulatory sources including the SEC final rule, DOJ prosecutions, and CISA advisories, plus market-sizing reports presented as ranges. Claims are structured as six key judgments with explicit confidence levels and per-section assessments carrying confidence grades and rationale, keyed by numbered citations to a source registry.
Limitations: Most prevalence figures are drawn from vendor- or recruiter-commissioned surveys and flagged as such, the headline 24 percent convergence figure is a dated 2019 baseline, and the absence of a current independent census of converged security leadership is itself a finding.
Estimative language in this report follows the firm’s published standard: judgments carry HIGH, MODERATE, or LOW confidence, and each carries its rationale in the full report. The framework, source tiers, and anti-fabrication perimeter are public on the methodology page. Corrections issue as numbered addenda.