![]()
Used by 150+ leading enterprises, Commugen puts Cyber GRC on autopilot as security leaders face accelerating regulation & expanding attack surfaces
LONDON, UNITED KINGDOM, October 7, 2026 /EINPresswire.com/ — Commugen, a Cyber GRC (Governance, Risk & Compliance) automation provider founded in 1999, today shared its observations on how enterprise security and compliance teams are restructuring their GRC programs as 2026 draws to a close. According to the company, three developments are pushing organizations away from spreadsheet-based and siloed processes: new obligations under frameworks such as the EU AI Act, NIS2, and DORA; growing demand from boards and auditors for continuous visibility into cyber risk; and the adoption of AI agents inside GRC workflows.
The observations draw on Commugen’s work with more than 150 enterprises, including roughly a third of Israel’s financial institutions, and its selection as a national platform for Supply Chain Risk Management and Organizational Cyber Defense in Israel.
Regulatory Obligations Are Arriving Faster
Security and compliance teams are absorbing several regulatory changes at once. DORA has applied to EU financial entities since January 2025, NIS2 enforcement is maturing across member states, and EU AI Act obligations continue to phase in through 2026 and 2027. At the same time, established frameworks such as ISO 27001 and NIST continue to be updated, creating new control obligations faster than manual processes can absorb them.
The attack surface is expanding in parallel. According to Commugen, every new tool, every new vendor, and every new cloud environment is a potential gap, and GRC processes that cannot scale with the environment become a liability rather than a safeguard. Evolving regulatory requirements, expanding attack surfaces, and a surge in cybersecurity threats have made manual GRC management significantly more error-prone and costly; the company notes that approaches that worked in 2018 do not scale in 2026.
Fragmented GRC Practices Under Strain
Industry research shows that manual GRC processes don’t just create inefficiency; they create blind spots that auditors find and attackers exploit. Many organizations have historically practiced governance, risk management, and compliance as three separate disciplines, with separate owners, separate tools, and separate reporting cycles, which can lead to duplicated effort and gaps that surface only during an audit or an incident.
Commugen reports that organizations which moved from spreadsheets to first-generation GRC platforms often face a different challenge: rigid systems that require heavy IT involvement for minor workflow changes and offer limited real-time visibility into actual risk posture.
Commugen describes a pattern it sees regularly: three weeks before an ISO 27001 audit, a compliance team is reconciling five different spreadsheets, chasing control owners over email, and manually cross-referencing policy documents that were last updated eight months earlier. According to the company, this is not a failure of effort but a failure of architecture. The cost of getting it wrong extends beyond an audit finding to reputational damage, regulatory fines, and security incidents.
Effective GRC enables data-driven decision-making, responsible operations, and shared policy alignment across the organization. AI-powered GRC tools can continuously monitor controls, identify potential risks, and strengthen compliance management in ways that manual processes cannot replicate, which Commugen says is widening the gap between organizations that have modernized and those that have not.
“Cyber GRC is broken, and security leaders feel it every day,” said Itai Sassoon, CEO of Commugen. “Teams are spending their best hours reconciling spreadsheets instead of reducing risk. The shift we’re seeing across the market is from point-in-time audits to continuous oversight, where CISOs and GRC teams can see their real posture today, not last quarter.”
From Point-in-Time Audits to Continuous Compliance
Auditors and boards are increasingly asking for continuous compliance visibility rather than quarterly snapshots. In response, Commugen sees enterprises connecting GRC processes to data already flowing through their security stack, such as SIEM logs, alerts, asset inventories, and vulnerability scan results, instead of re-entering it manually.
Organizations are also consolidating multiple frameworks, including ISO 27001, NIST, SOC 2, GDPR, NIS2, and DORA, into a single program so that one control can serve several regulatory obligations.
The company also observes growing demand for no-code GRC tools that let GRC and security teams change workflows themselves when a control owner changes, a new framework is added, or an incident response process evolves, without waiting on IT or developers.
Integration with existing security infrastructure, including SIEM tools, is emerging as a key requirement, as security teams look to avoid rip-and-replace projects and parallel systems. Commugen reports that GRC platforms built on no-code architecture are typically deployed with time to value measured in weeks, not quarters, compared with the extensive IT-led implementations common to traditional enterprise GRC platforms.
The company also acknowledges the limits of the approach: no-code platforms can face constraints in highly customized enterprise environments, where complex legacy integrations or deeply bespoke workflows push against what no-code configuration handles gracefully. Commugen recommends that organizations address these questions during evaluation rather than discovering them after deployment.
AI Agents Enter the GRC Workflow
The AI GRC category in 2026 includes GRC co-pilots that answer regulatory questions and draft policy language, multi-agent systems for continuous control monitoring, large language models that interpret regulatory text as it changes, and machine learning models that score risk and flag anomalies before they become incidents. Commugen, whose platform includes native AI GRC agents that work inside existing workflows, notes that adoption depends on explainability: AI-generated compliance outputs still require human review for high-stakes decisions.
One of the most practical implications, according to Commugen: when a framework such as the EU AI Act or an updated NIST profile introduces new control requirements, AI can help identify what needs to be addressed, rather than waiting for a compliance analyst to manually reconcile the changes. The company describes this as the difference between continuous compliance and point-in-time snapshots.
Commugen also points to a growing architectural divide in the market. AI-native GRC platforms have multi-agent systems and LLM-driven regulatory interpretation built into their architecture, while many legacy platforms are retrofitting these capabilities onto foundations that were not designed for them. According to the company, that gap shows up in implementation timelines, in the flexibility of the AI layer, and in how quickly a platform adapts when regulations change.
For heavily regulated industries, Commugen advises additional due diligence when adopting AI in GRC. Audit trail integrity, data handling practices, and evidence of enterprise deployments are all worth examining closely. The company states that customer data in its platform is never used for model training, that processing runs through secure APIs, and that its AI can be deployed on a customer’s own infrastructure.
A CISO of a global financial enterprise described the change: “Commugen’s AI Agent explanations and justifications made our risk conversations much more credible internally. If leadership pushes back on a number, we can actually explain how we arrived there.”
Organizations using AI-powered GRC can automate routine compliance tasks, reduce manual processes, improve the accuracy of compliance documentation, and compress audit cycles. Commugen attributes these gains to the removal of the manual reconciliation steps that currently consume most of the time in a compliance cycle, freeing expert time for the judgment calls that still require people.
Looking Ahead to 2027
Commugen expects boards to increasingly require cyber risk to be reported in business terms, driving wider use of cyber risk quantification, and expects AI risk management to become a standard part of GRC programs as EU AI Act requirements take effect. The company plans to continue expanding its AI GRC agents and its presence across the UK, Europe, the US, and Asia-Pacific.
“Regulation isn’t slowing down, and neither are attackers,” added Sassoon. “The organizations that will be best prepared for 2027 are the ones that can prove their posture continuously, not scramble before every audit.”
About Commugen
Commugen is a no-code Cyber GRC automation platform that puts Cyber GRC on autopilot with automated workflows, powerful dashboards, and built-in AI, all in one flexible, easy-to-use platform. Founded in 1999, Commugen is used by more than 150 leading enterprises. Its solutions cover cyber risk management, multi-framework compliance (ISO 27001, SOC 2, GDPR, NIS2, DORA and more), third-party risk management, AI risk management, cyber risk quantification, and more. Commugen is ISO 9001, ISO 27001, and SOC 2 Type 2 certified, available as SaaS or on-premise, and has offices in the USA, UK, Germany, and Israel. Learn more at cyber.commugen.com.
Adam Babayoff
Commugen
+44 20 4591 9206
Visit us on social media:
LinkedIn
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery
