I recently coauthored an article for the ISACA Journal with a coworker about imputing the cost of a data breach from record count. We also recorded a podcast based on the article. You can read the article here and listen or watch the podcast. I also authored a piece for the @ISACA newsletter on theContinue reading “ICYMI – Mega ISACA Update – Data Breach Costs and Hanlon’s Razor”
Category Archives: ISACA
Learning From Other’s Mistakes
I wrote this piece after I read one person’s take on the relationship between near misses and audit findings. I wanted to reflect my thinking on the matter in a way that gave risk organizations a useful function to pursue after an incident. You can read about the role that your near misses (and other’s)Continue reading “Learning From Other’s Mistakes”
Rise of the Chief Trust Officer
I wrote a piece for ISACA about how the rise of the Chief Trust Officer role is changing the landscape for cyber security and cyber risk leadership. Borrowing from the CISO, CSO, CPO, CIO, and digital transformation roles, the Chief Trust Officer can become the go to role to govern technology and ensure customer’s trustContinue reading “Rise of the Chief Trust Officer”
Cyber Risk Warehouse – 2022 April YTD ICYMI
I have a “warehouse” full of good cyber risk things to share with you below: Here is an ISACA piece I was asked to write about things Cyber Risk professionals need to focus on in 2022 This ISACA column I wrote speaks to the role that bias plays in how cyber news is fed toContinue reading “Cyber Risk Warehouse – 2022 April YTD ICYMI”
Featured on CISO Series – Hacking Cyber Risk Quantification
I had the pleasure of doing a live session on David Spark and Spark Media’s CISO Series with Nick Esponosa. Things got wacky but we also had a good time discussing with CRQ is and how it can help companies make better decisions. You can check out the highlights reel here and the full videoContinue reading “Featured on CISO Series – Hacking Cyber Risk Quantification”
Cyber Resilience & Board Communication Interview
My piece on Cyber Resilience was recently published by ISACA. Note that their style guide requires that everything with cyber in it be a compound word which makes it read weird. I had a good laugh with them about this. They also interviewed me for ISACA TV on communicating cyber risk to the board andContinue reading “Cyber Resilience & Board Communication Interview”
ISACA CRQ Whitepaper, a Webinar, and More CRQ
A whitepaper I recently wrote for ISACA was published. You can access it here. In this paper I wanted to write about how cyber risk quantification worked broadly, not just in a FAIR context. I hope it gives you a good primer to this topic. I’m also doing an ISACA webinar with my good friendContinue reading “ISACA CRQ Whitepaper, a Webinar, and More CRQ”
CRQ, Zero Trust, NACD, and Risk Treatment Options
Here is a mega update on several items I’ve been working on lately. First, I did a podcast with ThreatConnect talking about CRQ. We did a bit of a retrospective on the FAIR book as well which was nice. Next is a piece I wrote for ISACA about how to not over-respond to current workContinue reading “CRQ, Zero Trust, NACD, and Risk Treatment Options”
How to Report Cyber Risk to the Board
I’m giving a webinar tomorrow based on the whitepaper I authored for ISACA: Reporting Cybersecurity Risk to the Board of Directors. It’s a free download. I cover Board reporting from the technologists perspective, covering the role of the Board and how to communicate to them in a way they understand. You can register for theContinue reading “How to Report Cyber Risk to the Board”
Pandemic Lessons and Record Count
I was asked to write a piece for ISACA about cyber risk in the Pandemic. I used some popular memes as a bouncing off point to talk about how to manage risk in these crazy times. You can read this here. I also had my article about why using record counts as your risk appetiteContinue reading “Pandemic Lessons and Record Count”