CyFun 2025 and the Rise of Continuous Cyber Assurance
CyFun 2025 and the Rise of Continuous Cyber Assurance
For years, cybersecurity assurance followed a familiar rhythm.
Assess.
Collect evidence.
Fix gaps.
Prepare for the audit.
Repeat next year.
But the systems organizations are trying to secure no longer operate on an annual cycle.
Cloud environments change continuously. Software is deployed daily. Access permissions evolve. Third-party relationships expand. AI systems are introduced into business processes faster than traditional governance programs can document them.
The result is a growing gap between how fast technology changes and how often cybersecurity is traditionally assessed.
This is why continuous cyber assurance is becoming one of the most important conversations in cybersecurity and compliance.
And it is also why the release of CyFun 2025 is particularly relevant.
CyFun 2025 introduced stronger alignment with NIST CSF 2.0, expanded its focus on supply-chain security and operational technology, improved control clarity and auditability, and added Governance Measures for stronger cybersecurity oversight.
The framework update reflects a much larger shift:
Cybersecurity can no longer be managed as a point-in-time compliance exercise.
It needs to become an ongoing assurance capability.
The Problem With Point-in-Time Cybersecurity
Imagine an organization completes a cybersecurity assessment in January.
All required evidence is collected.
Controls are reviewed.
Gaps are remediated.
The organization receives a positive assessment.
By February, however:
- New employees have joined.
- Cloud configurations have changed.
- A new SaaS provider has been added.
- Software has been deployed.
- Access permissions have evolved.
- Infrastructure has been updated.
The January assessment may still be useful.
But it no longer represents the organization's complete cybersecurity posture.
This is the fundamental limitation of point-in-time assurance.
It tells you what was true when the assessment happened not necessarily what is true today.
Why Continuous Assurance Is Becoming the New Direction
The shift toward continuous assurance is being accelerated by several major trends.
1. Technology Environments Are Moving Faster
Modern organizations are increasingly built around:
- Cloud infrastructure
- SaaS applications
- APIs
- Microservices
- Automated workflows
- AI systems
- Distributed technology teams
These environments do not remain static between audit periods.
Cybersecurity assurance therefore needs to become more closely connected with operational technology environments.
2. AI Is Increasing the Speed of Change
AI adoption is creating new challenges for cybersecurity teams.
Organizations are rapidly introducing:
- Generative AI tools
- AI assistants
- Agentic workflows
- AI-powered automation
- Machine learning systems
But governance programs are struggling to keep up.
A 2026 SANS survey found that AI use in cybersecurity had risen significantly, while governance and workforce structures were not keeping pace with adoption.
At the same time, the World Economic Forum reported that organizations are increasingly moving toward periodic and continuous reviews of AI tools, although significant assurance gaps remain.
The implication is clear.
Organizations cannot simply approve technology once and assume it remains safe indefinitely.
They need ongoing assurance.
CyFun 2025 Moves the Conversation Beyond Controls
CyFun has always provided organizations with a structured approach to cybersecurity.
However, the latest evolution reflects the growing importance of operating cybersecurity as a continuous program.
CyFun 2025 includes:
- Alignment with NIST CSF 2.0
- Governance Measures
- Greater supply-chain security focus
- Greater OT coverage
- Clearer controls
- Specific control goals
- Improved auditability
- More detailed implementation guidance
These changes matter because cybersecurity assurance is no longer only about asking:
"Do we have this control?"
Organizations increasingly need to ask:
"Is this control operating effectively right now?"
That is a very different model.
From Control Existence to Control Confidence
Traditional compliance programs often focus on whether a control exists.
For example:
✔ A policy exists.
✔ Access reviews are scheduled.
✔ Security monitoring is configured.
✔ Incident response procedures are documented.
But continuous assurance asks additional questions:
- Is the policy still current?
- Did the access review actually happen?
- Are there overdue reviews?
- Is monitoring still active?
- Has the configuration changed?
- Is evidence available?
- Are exceptions being addressed?
This shift moves organizations from control documentation to control confidence.
The Five Layers of Continuous Cyber Assurance
Organizations looking to operationalize CyFun 2025 can think about continuous assurance in five layers.
Layer 1: Continuous Visibility
Organizations need a current view of:
- Controls
- Risks
- Assets
- Evidence
- Open findings
- Remediation
The objective is to reduce the gap between what leadership believes is happening and what is actually happening.
Layer 2: Connected Evidence
Evidence should not only appear when an auditor requests it.
Organizations should work toward maintaining evidence throughout the year.
This may include information from:
- Cloud platforms
- Identity systems
- Security tools
- Ticketing platforms
- Asset inventories
- Internal workflows
The closer evidence collection is connected to operational systems, the less manual work is required later.
Layer 3: Change Awareness
Continuous assurance depends on recognizing change.
Examples include:
- Configuration drift
- New privileged users
- Missing reviews
- Unresolved vulnerabilities
- New suppliers
- Technology changes
Not every change represents a compliance failure.
But important changes should trigger visibility and review.
Layer 4: Continuous Remediation
Finding a problem is not the same as fixing it.
Continuous assurance requires organizations to track:
- Findings
- Owners
- Risk priority
- Remediation deadlines
- Progress
- Closure validation
This turns cybersecurity assurance into an operational workflow rather than a report that sits in a folder.
Layer 5: Executive Assurance
Leadership teams do not need every technical event.
They need confidence.
They need to understand:
- What has changed?
- What is the current risk posture?
- Which issues need attention?
- Where are controls weakening?
- Is remediation progressing?
This is where governance and cybersecurity operations meet.
Why This Trend Matters for CyFun Organizations
CyFun 2025 is arriving at a time when the cybersecurity landscape is becoming more complex.
NIST's CSF 2.0 has now been in use for two years and has been widely adopted globally, with NIST highlighting its increased focus on governance and cybersecurity supply-chain risk management.
At the same time, organizations are managing faster AI adoption, changing regulations, and increasingly connected technology environments.
The question is no longer:
Can we complete our next cybersecurity assessment?
The more important question is:
Can we maintain confidence in our cybersecurity posture between assessments?
How Quantarra Supports Continuous Cyber Assurance
Quantarra helps organizations move from fragmented compliance activities toward a more continuous operating model.
Organizations can centralize:
Controls
Manage cybersecurity controls and ownership from a unified platform.
Evidence
Organize and automate evidence collection from relevant technology environments.
Risks
Track cybersecurity risks and associated remediation activities.
Frameworks
Map controls across CyFun and other relevant frameworks.
Monitoring
Maintain greater visibility into control activities and potential compliance gaps.
Assurance
Create a more continuous view of audit and compliance readiness.
The goal is not simply to make the next audit easier.
The goal is to make cybersecurity assurance part of everyday operations.
Conclusion
CyFun 2025 represents more than a framework update.
It reflects the direction cybersecurity is moving.
From periodic.
To continuous.
From evidence collection before an audit.
To evidence readiness throughout the year.
From asking whether controls exist.
To understanding whether controls can still be trusted.
The organizations that build continuous cyber assurance today will be better prepared for tomorrow's audits, technology changes and regulatory expectations.
CyFun provides the structure. Continuous assurance provides the operating model.