• I’ve got a busy October speaking calendar this year! I will be participating on a panel discussion at the inaugural FAIR Conference this year, as well as signing books with Jack Jones. Should be a fun time! Be sure and stop by to say hello!

    ·

    ,
  • I will be speaking this Wednesday, 5 Oct at the 2016 UNCC Cyber Security Summit. The last time I spoke there was 2013. I’m doing a hybrid joint-presentation/panel discussion with Chris Houser from Wells Fargo and the panel discussion will be moderated by Todd Innskeep from Booz Allen Hamilton. I will be talking about how…

  • Sometimes, the organization you work for will need to make budget cuts. And sometimes that means cuts to the security budget. How that should be handled is the subject of my latest @ISACA column.

    ·

    , ,
  • Recently, I was discussing faux names for the risk department with a colleague in Operational Risk. We were trying to come up with a good subheading that poked fun of our role in the organization. My suggestions tended towards the subversive (my favorite suggestion was “Risk: Hide All the Bowls Of Cheerios”). My humor belied…

    ·

  • My latest @ISACA article posted today. I was really pleased with this one as it uses an easily understandable metaphor to call out the often experienced desire of people to live life without risk (as evidenced by statements such as “We don’t accept any risk…”). Take a look and let me know what you think.…

    ·

    , ,
  • Bill Murphy‘s interview with me for his RedZone podcast was posted today. I had a great time talking with Bill about risk, FAIR, and forecasting. You can find the podcast here. It was a great discussion, and Bill was a very gracious host. His entire podcast series is worth subscribing to: he interviews some really…

    ·

    , , ,
  • The final post of the interview/blog series I did with the FAIR Institute was posted last night.

    ·

    ,
  • Part 2 of the interview/blog series I did with the FAIR Institute was posting this morning.  

    ·

  • The folks over at the FAIR Institute were nice enough to interview me recently and turn it into a series of blog posts. Part 1 is up right now and sets the stage for how to assess quality in your Cyber Risk assessments.

    ·

    ,
  • I’m very pleased to announced that the book I coauthored with Jack Jones (Measuring and Managing Information Risk: A FAIR Approach) has been inducted today into the Cybersecurity Canon at the Palo Alto Networks 2016 Ignite Conference. The Canon includes books both fiction and nonfiction that accurately depict the history, milestones, and culture of the…

    ·

    ,