Rise of the Chief Trust Officer

I wrote a piece for ISACA about how the rise of the Chief Trust Officer role is changing the landscape for cyber security and cyber risk leadership. Borrowing from the CISO, CSO, CPO, CIO, and digital transformation roles, the Chief Trust Officer can become the go to role to govern technology and ensure customer’s trustContinue reading “Rise of the Chief Trust Officer”

Cyber Risk Warehouse – 2022 April YTD ICYMI

I have a “warehouse” full of good cyber risk things to share with you below: Here is an ISACA piece I was asked to write about things Cyber Risk professionals need to focus on in 2022 This ISACA column I wrote speaks to the role that bias plays in how cyber news is fed toContinue reading “Cyber Risk Warehouse – 2022 April YTD ICYMI”

Featured on CISO Series – Hacking Cyber Risk Quantification

I had the pleasure of doing a live session on David Spark and Spark Media’s CISO Series with Nick Esponosa. Things got wacky but we also had a good time discussing with CRQ is and how it can help companies make better decisions. You can check out the highlights reel here and the full videoContinue reading “Featured on CISO Series – Hacking Cyber Risk Quantification”

Cyber Resilience & Board Communication Interview

My piece on Cyber Resilience was recently published by ISACA. Note that their style guide requires that everything with cyber in it be a compound word which makes it read weird. I had a good laugh with them about this. They also interviewed me for ISACA TV on communicating cyber risk to the board andContinue reading “Cyber Resilience & Board Communication Interview”

ISACA CRQ Whitepaper, a Webinar, and More CRQ

A whitepaper I recently wrote for ISACA was published. You can access it here. In this paper I wanted to write about how cyber risk quantification worked broadly, not just in a FAIR context. I hope it gives you a good primer to this topic. I’m also doing an ISACA webinar with my good friendContinue reading “ISACA CRQ Whitepaper, a Webinar, and More CRQ”

CRQ, Zero Trust, NACD, and Risk Treatment Options

Here is a mega update on several items I’ve been working on lately. First, I did a podcast with ThreatConnect talking about CRQ. We did a bit of a retrospective on the FAIR book as well which was nice. Next is a piece I wrote for ISACA about how to not over-respond to current workContinue reading “CRQ, Zero Trust, NACD, and Risk Treatment Options”

How to Report Cyber Risk to the Board

I’m giving a webinar tomorrow based on the whitepaper I authored for ISACA: Reporting Cybersecurity Risk to the Board of Directors. It’s a free download. I cover Board reporting from the technologists perspective, covering the role of the Board and how to communicate to them in a way they understand. You can register for theContinue reading “How to Report Cyber Risk to the Board”

Pandemic Lessons and Record Count

I was asked to write a piece for ISACA about cyber risk in the Pandemic. I used some popular memes as a bouncing off point to talk about how to manage risk in these crazy times. You can read this here. I also had my article about why using record counts as your risk appetiteContinue reading “Pandemic Lessons and Record Count”

Welcome to 2020! Cyber Risk Prospectuses and a “Manifesto”

Welcome to 2020! I kept busy last month, even with the holidays. Here are some updates: I wrote a piece for ISACA about how much spending is being done in aggregate for cyber security and how we need to rationalize the controls we are spending on. The FAIR Institute called this my manifesto here :-)Continue reading “Welcome to 2020! Cyber Risk Prospectuses and a “Manifesto””