4 min read
How to Turn a Risk Appetite Statement Into a Usable Curve
Somewhere in your board policy there is a sentence like this: "The credit union will not accept cyber risk exceeding 3 percent of net worth." The...
Cybersecurity management insights, tips, and trends for security leaders, CISOs, vCISOs, and MSSPs who want to work smarter, not harder.
4 min read
Somewhere in your board policy there is a sentence like this: "The credit union will not accept cyber risk exceeding 3 percent of net worth." The...
5 min read
Pull up your current risk assessment and look at what the rows actually are. For most institutions, they are threats: ransomware, phishing, insider...
5 min read
The most common objection to cyber risk quantification does not come from boards. It comes from security leaders, and it goes like this: the number...
4 min read
You have three proposals on your desk and the numbers are thousands of dollars apart for what each vendor calls the same thing: an IT risk...
8 min read
A security officer at a credit union told me that in his entire time at the institution, they had never once talked about risk in numbers. Colors,...