The Risk Dr ®

  • 2023 EOY Cyber Risk Wrap Up

    Here is a mega-update of things I meant to post since Sept(!) In the September 2023 ISSA Journal, I worked with my colleague Natalie Jorion to publish this piece about SEC cyber materiality. You can access the article here. I did a webinar with ISS Corporate about the SEC materaility rule. You can watch the…

    23 December 2023

    ·

    @ISACA, ICYMI, Risk, SEC Cyber Materiality
  • The Risk of Quantifying Cyber Risk

    In this @ISACA newsletter column, I talk about some real-world perspectives I encountered where one organization was told they shouldn’t quantify cyber risk.

    16 August 2023

    ·

    @ISACA, Legal, Quantification
  • ICYMI – Mega ISACA Update – Data Breach Costs and Hanlon’s Razor

    I recently coauthored an article for the ISACA Journal with a coworker about imputing the cost of a data breach from record count. We also recorded a podcast based on the article. You can read the article here and listen or watch the podcast. I also authored a piece for the @ISACA newsletter on the…

    23 May 2023

    ·

    @ISACA, Data, Forecasting, ICYMI, ISACA, podcast, Psychology, Publications, Risk
  • Business Process Maps are Boring

    I recently wrote this piece for ISACA on business process maps. Clearly, this is tongue in cheek – there are a lot of benefits to building a map of business processes and for a security professional, these maps can become the basis of lots of security and risk reporting. You can read my thoughts on…

    15 March 2023

    ·

    @ISACA, Reporting, Taxonomy, Working in Risk
  • ICYMI – Interviewed on CISO Insiders Podcast

    I had a great time talking with Ben Ben-Aderet on the CISO Insiders Podcast. He asked really interesting questions about not only information security but also caused me to reflect on myself and what I learned during my time in the industry. You can check it out here (he bookmarked different topics so you can…

    28 January 2023

    ·

    podcast, Risk, Risk Profession, Working in Risk
  • Learning From Other’s Mistakes

    I wrote this piece after I read one person’s take on the relationship between near misses and audit findings. I wanted to reflect my thinking on the matter in a way that gave risk organizations a useful function to pursue after an incident. You can read about the role that your near misses (and other’s)…

    16 January 2023

    ·

    @ISACA, Data, ISACA, Metrics, Risk, Risk Reporting
  • ICYMI: Digital Trust and Improving Risk Programs

    For my final update this year, I want to discuss my last two pieces for the @ISACA newsletter and ISACA Now Blog. The first is a piece on how Cyber Ratings are quickly becoming a standard for measuring digital trust. As the investor community wants more insight into which firms have a greater propensity for…

    22 December 2022

    ·

    @ISACA, Board Reporting, Digital, ICYMI, Ratings
  • Cyber Insurance Market Analysis

    I wrote this piece as an analysis of what Marsh is experiencing in the marketplace. I wanted to have a cyber risk analyst’s take on the same data and to see where we could learn from their analysis and apply that in our practice. One edit, it looks like I made a typo. The line…

    30 August 2022

    ·

    @ISACA, Cyber Insurance, Quantification, Risk
  • Rise of the Chief Trust Officer

    I wrote a piece for ISACA about how the rise of the Chief Trust Officer role is changing the landscape for cyber security and cyber risk leadership. Borrowing from the CISO, CSO, CPO, CIO, and digital transformation roles, the Chief Trust Officer can become the go to role to govern technology and ensure customer’s trust…

    5 July 2022

    ·

    @ISACA, Economics, ISACA, Risk, Risk Communication, Risk Ownership, Risk Profession, Working in Risk
  • The Future of Quantitative Cyber Risk Reporting

    In my latest piece for the @ISACA newsletter, I address the US SEC’s interest in enhancing the cyber risk reporting requirements. The SEC has asked for feedback on this matter from the public. I used my feedback to them in the writing of this piece.

    22 June 2022

    ·

    @ISACA, Risk, Risk Communication, Risk Profession, Risk Reporting
Previous Page
1 2 3 4 … 16
Next Page

The Risk Dr ®

About

  • Subscribe Subscribed
    • The Risk Dr ®
    • Join 33 other subscribers
    • Already have a WordPress.com account? Log in now.
    • The Risk Dr ®
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar