The Open Group recently highlighted me in the Individual Contributor Spotlight. I’ve been working with the Open Forum in various capacities since 2012 with the introduction of the Open FAIR certification. Met lots of great people and got to give back. Here’s what they wrote: The Security Forum thanks Jack for his foundational role inContinue reading “Open Group Security Forum”
Join Derek Vadala and I tomorrow at 12:45PM PDT as we talk about building a Global Cyber Rating at RSA Conference 2021 https://www.rsaconference.com/Library/presentation/USA/2021/building-a-global-cyber-rating-how-to-objectively-rate-cyber-capabilities
A new whitepaper was released this week from the World Economic Forum. I was very honored to be a part of the group that authored this (you can see my contributions in section 2.2 – Understand the economic drivers and impact of cyber risk). The paper is free to download here.
Here is a mega update on several items I’ve been working on lately. First, I did a podcast with ThreatConnect talking about CRQ. We did a bit of a retrospective on the FAIR book as well which was nice. Next is a piece I wrote for ISACA about how to not over-respond to current workContinue reading “CRQ, Zero Trust, NACD, and Risk Treatment Options”
Two weeks ago I was named a Distinguished Fellow of the ISSA. It’s really a great honor for me as I really didn’t think I was qualified. Thanks to everyone who made this possible, including Clarke Cummings for getting me involved in the ISSA to begin with and to Joel Weise for helping with myContinue reading “ISSA Distinguished Fellow”
In case you missed it, the Cyentia Institute published the IRIS2020 Xtreme report. I was very happy to have written the conclusions for this report. In it, I speak about how the data in the report can be useful for Board Directors. You can read the full report here. Dark Reading quoted me in theirContinue reading “Cyentia Xtreme”
I was asked to write a piece for ISACA about cyber risk in the Pandemic. I used some popular memes as a bouncing off point to talk about how to manage risk in these crazy times. You can read this here. I also had my article about why using record counts as your risk appetiteContinue reading “Pandemic Lessons and Record Count”
I’m pleased to announce that I have been honored with an ISC2 Global Award in the Senior Professional Award category for the work I’ve done integrating FAIR into the NIST CSF framework. Many thanks to the FAIR Institute for their support and for ISC2 for these awards programs.
ISACA asked me to write a short piece on my Journal article about risk communication. They published that here. I also wrote a blog post for the @ISACA newsletter about the trouble with positive risk. Lastly, NIST released an update to their ERM-Cyber integration standard and my friends at the FAIR Institute asked me toContinue reading “Positive Risk, ISACA Journal, and more NIST”
Interviewed by Phil Venables, published in the ISACA Journal and Dark Reading, and more thoughts on NIST and CVSS