I wrote a piece for ISACA about how the rise of the Chief Trust Officer role is changing the landscape for cyber security and cyber risk leadership. Borrowing from the CISO, CSO, CPO, CIO, and digital transformation roles, the Chief Trust Officer can become the go to role to govern technology and ensure customer’s trustContinue reading “Rise of the Chief Trust Officer”
In my latest piece for the @ISACA newsletter, I address the US SEC’s interest in enhancing the cyber risk reporting requirements. The SEC has asked for feedback on this matter from the public. I used my feedback to them in the writing of this piece.
I have a “warehouse” full of good cyber risk things to share with you below: Here is an ISACA piece I was asked to write about things Cyber Risk professionals need to focus on in 2022 This ISACA column I wrote speaks to the role that bias plays in how cyber news is fed toContinue reading “Cyber Risk Warehouse – 2022 April YTD ICYMI”
My piece for the NACD was published today. Here I outline the connection that is being made by ratings agencies between cyber risk and business risk. For those of us in cyber risk, this will seem obvious but it’s profound that it is now gaining traction in business ratings.
I had the pleasure of doing a live session on David Spark and Spark Media’s CISO Series with Nick Esponosa. Things got wacky but we also had a good time discussing with CRQ is and how it can help companies make better decisions. You can check out the highlights reel here and the full videoContinue reading “Featured on CISO Series – Hacking Cyber Risk Quantification”
I was interviewed by ISTARI on Zero Trust a little while ago. You can check out the short podcast here: I was also quoted in an article on Zero Trust here:
The Open Group recently highlighted me in the Individual Contributor Spotlight. I’ve been working with the Open Forum in various capacities since 2012 with the introduction of the Open FAIR certification. Met lots of great people and got to give back. Here’s what they wrote: The Security Forum thanks Jack for his foundational role inContinue reading “Open Group Security Forum”
Join Derek Vadala and I tomorrow at 12:45PM PDT as we talk about building a Global Cyber Rating at RSA Conference 2021 https://www.rsaconference.com/Library/presentation/USA/2021/building-a-global-cyber-rating-how-to-objectively-rate-cyber-capabilities
A new whitepaper was released this week from the World Economic Forum. I was very honored to be a part of the group that authored this (you can see my contributions in section 2.2 – Understand the economic drivers and impact of cyber risk). The paper is free to download here.
Here is a mega update on several items I’ve been working on lately. First, I did a podcast with ThreatConnect talking about CRQ. We did a bit of a retrospective on the FAIR book as well which was nice. Next is a piece I wrote for ISACA about how to not over-respond to current workContinue reading “CRQ, Zero Trust, NACD, and Risk Treatment Options”