Skip to main content

Looking Back on 2025 and What's Next for 2026

As the new year starts, I’ve been reflecting on 2025 and honestly, I just wanted to take a moment to say thank you. You’re reading this because you’ve been some of our most engaged supporters, collaborators, and thoughtful voices in the community.

We don’t take that lightly.

Last year was about building in the open, sharing what we’re learning, and putting real capability into the hands of practitioners. Here’s a quick look back and a preview of what we’re focused on headed into 2026.

Agentic AI & the “xLM” Suite

2025 was a big year for our Agentic AI work.

We introduced our GRC Agentic AI roadmap and made the model openly available to the entire GRC community and all of our customers. Watching nearly 1,000 GRC professionals join live for the Agentic AI series was incredibly energizing and reaffirmed our belief that there is practical value for GRC professionals found amongst all of the AI hype.

We also built and deployed the first agents in our “lifecycle management” AI suite. These are now being deployed inside multiple customer environments, including two Fortune 500 organizations you’d definitely recognize. The early results have been strong - high value use cases, meaningful ROI, and real operational relief for teams that needed it most.

Heading into 2026, our focus is expanding the suite to round out the full ecosystem of Controls and Evidence Lifecycle Management, Vendor Risk Lifecycle Management, and a lot more.

This is just the beginning.

Helping Harmonize Across Frameworks

One of the problems we hear about most from GRC teams is framework sprawl across frameworks like SOC 2, ISO 27001, PCI DSs and more. In 2025 we made meaningful progress toward solving it with fullCircle.

We launched context-aware AI directly in fullCircle, enabling GRC professionals to ask and answer questions about their actual program. Not generic guidance or theoretical mappings, but answers grounded in their controls, evidence, scope, and environment - right where the work is happening in platform.

We also launched what I believe is a true industry first: a framework deployer that helps organizations intuitively launch and harmonize across multiple frameworks. What makes this so powerful is how it embraces reality. It accounts for the nuance of different business units, scoping considerations, and product lines rather than forcing everything into a single, oversimplified model.

This is the first platform I’ve ever seen approach framework mapping this way, and it genuinely nails the real problem teams struggle with: not mapping on paper, but operationally harmonizing frameworks in a way that actually works and makes managing a compliance program more efficient.

The First Wave of ISO 42001 Certifications

One of the most exciting milestones of the year was helping implement the first batch of ISO 42001 certifications globally including with organizations pushing the boundaries of current AI use cases. That includes folks on the cutting edge of model training, automated decision making, and agentic AI.

That kind of experience matters because the lessons learned here are already shaping how we coach, guide, and support clients moving into 2026. We’ve seen what works, what’s hard, and where teams need the most help.

To support the broader community, we also completed two 42001 courses (here and here) and made them available for free.

You can check out this webinar on YouTube: Here

Armada Attack Surface Management

We continued expanding the Armada Attack Surface Management platform, adding depth, scale, and practical visibility for security teams that are tired of chasing blind spots. This is an area we’ll continue to invest in heavily going into next year.

Our offensive security team also spoke at events like DefCon, DistrictCon, and represented Red Team Village across the country. We did a lot of original research including on ransomware gangs and found and reported a 0-day exploit for a popular Netgear router. Cory Wolff, our offensive security practice leader was awarded the offensive security practitioner of the year by SANS institute. And last but certainly not least we achieved CREST accreditation.

A lot of folks think of risk3sixty as a “GRC” company, but we have one of the best offensive security teams in the nation. I’d consider it perhaps our “best kept secret.”

Cory Wolff speaking at DEFCON this year at Red Team Village where he serves as a board member.

Awards & Recognition

Finally, I feel like I need to take a few moments to recognition some of the accomplishments earned by our team as a collective and the great people behind the work we do:

  • Inducted into the Atlanta Business Chronicle Hall of Fame for Best Companies to Work For and Fastest Growing Companies (7 years in a row)
  • Named one of Consulting Magazine’s Best Firms to Work For for the third consecutive year
  • Successfully completed our peer review with the AICPA
  • Earned CREST Accreditation
  • Earned CMMC Registered Practitioner Firm status with CyberAB
  • Completed our ISO 27001, 27701, and 22301 certifications (we are the only firm in our space with all three!)

I’m incredibly proud of this team and grateful for the culture we’ve built together.

Looking Ahead to 2026

As we move into 2026, our focus remains the same:

  • Build practical, usable AI that solves real GRC problems
  • Focus on giving back to the community, and
  • Help organizations build great security and GRC programs as efficiently as possible without compromising trust or integrity

Thanks for being part of this journey with us. More to come soon and as always, if you ever want to talk through ideas, challenges, or what you’re seeing in the field, we are a message away.

With gratitude,

— Christian Hyatt & the risk3sixty team

Like our content? Subscribe and stay informed.

Tags

See all