A whitepaper I recently wrote for ISACA was published. You can access it here. In this paper I wanted to write about how cyber risk quantification worked broadly, not just in a FAIR context. I hope it gives you a good primer to this topic.
I’m also doing an ISACA webinar with my good friend Jack Jones next Thursday based on this whitepaper. (Cue the “pair of Jacks” memes like this one from my friend Ed). You can register for the webinar here.
Lastly, I wrote a piece for @ISACA where I make a distinction between what CRQ is and how we can’t abandon other security assessments when pursuing CRQ. I called it ‘CRQ Purity Tests’ and I hope you like it.