ISACA asked me to write a short piece on my Journal article about risk communication. They published that here.
I also wrote a blog post for the @ISACA newsletter about the trouble with positive risk.
Lastly, NIST released an update to their ERM-Cyber integration standard and my friends at the FAIR Institute asked me to comment on it, so I wrote a short piece here.