I’m giving a webinar tomorrow based on the whitepaper I authored for ISACA: Reporting Cybersecurity Risk to the Board of Directors. It’s a free download. I cover Board reporting from the technologists perspective, covering the role of the Board and how to communicate to them in a way they understand. You can register for the webinar here
Lastly, I wrote another piece for ISACA on Zero Trust that people are finding interesting. You can check it our here
Two weeks ago I was named a Distinguished Fellow of the ISSA. It’s really a great honor for me as I really didn’t think I was qualified. Thanks to everyone who made this possible, including Clarke Cummings for getting me involved in the ISSA to begin with and to Joel Weise for helping with my application.
In case you missed it, the Cyentia Institute published the IRIS2020 Xtreme report. I was very happy to have written the conclusions for this report. In it, I speak about how the data in the report can be useful for Board Directors. You can read the full report here.
Dark Reading quoted me in their coverage here as did Duo Security here.
I was asked to write a piece for ISACA about cyber risk in the Pandemic. I used some popular memes as a bouncing off point to talk about how to manage risk in these crazy times. You can read this here.
I also had my article about why using record counts as your risk appetite is a bad idea. You can read this here.
Lastly, there was some more press on the (ISC)2 Award I won:
I was asked to write a piece about how umbrella frameworks like NIST can be incomplete without detailed implementation guidance, but also how such detailed methodologies like CVSS were also lacking. The result was this piece I wrote for the FAIR Institute.
I was also pleasantly surprised to discover that NIST released an IR draft that referenced FAIR directly as a way to tie together cyber risk and enterprise risk. You can read my hot take on this here and read the standard here.
I was very honored to be able to speak at the Inaugural Volatility and Risk Institute Conference hosted by NYU Stern, where I was interview by the inestimable Phil Venables. He write his thoughts about this here and you can watch the interview here, where you can see my amazing Zoom background (h/t to Digital Blasphemy where I’ve been a lifetime member since the late 90s)
Here is a piece I wrote for Dark Reading where I describe how to integrate MITRE ATT&CK into your risk modeling
Lastly my article on Risk Communication was published in this month’s ISACA Journal, available here. It was published as a feature article in their Human Element of Risk issue.
First off, here was my recounting of my time in Davos last month. It was a good event with lots of fascinating people, each an expert in their field.
Ian Amit (CISO, Cimpress) and I held a webinar about integrating FAIR with NIST. You can access that on-demand here.
I wrote an article about application rationalization during cloud migration for Homeland Security Today. It’s focused on the Federal Cloud Smart policy, but if you look closely, you’ll see this applies to virtually every organization. The FAIR Institute wrote about this article here.
I was quoted in Risk Management, a publication of RIMS on some predictions I made (Boards are going to be pressed for more risk quantification).
Lastly, I finalized the Risk Management Maturity Report for the FAIR Institute. You can read this here.