Squalify Unveils Essential CRQ for Fast Financial Cyber Risk Assessment #Germany #Munich #Cyber_Risk #Squalify #CRQ
What do we mean when we say cyber risk quantification, what do we mean? In this discussion, I try to break down the core concept and make it as simple as possible (Youtube clip):
youtube.com/clip/Ugkx3B4...
Yes, there a more detailed definitions, so YMMV. #crq #riskquantification
As I leave #nyc this week after attending #faircon25 and the fascinating world of #crq, I realize I'm in the wrong business. I should be in the #nyc scaffolding business. Holy moly!
Turning Cyber Risk Into Boardroom Metrics That Matter
www.forbes.com/sites...
#CyberRiskQuantification #CRQ #boardofdirectors #riskmanagement #ROI
You can't predict the future but every important decision we make involves getting as close to it as we can. #grc #risk #crq #cybersecurity #prediction #GJP
Cybersecurity effort decisions can very easily get in the way of innovation and progress. How much to compromise innovation in favor of cybersecurity is too fine a line for guesswork. That's basically why I'm obsessed with risk modeling in this space. #grc #risk #crq #cybersecurity
Cybersecurity risks are all tails but many risk analysts continue to use arithmetic mean to sum up the distribution of possibilities. #grc #risk #crq #cybersecurity
How many data breaches can you afford to have in order to collect enough data points for statistical analysis? #grc #risk #crq #cybersecurity
What are event counts and statistics like #DBIR useful for in #Bayesian modeling? They provide what _may_ be valuable background information. #grc #risk #crq #cybersecurity
Procrastination can serve as a powerful tool in cybersecurity. By hesitating, experts allow themselves the time to gather crucial intelligence and understand the full scope of a threat before deciding on the most effective counteraction. Provided that's where the time goes. #grc #risk #crq
Do you ask these questions when choosing what cybersecurity to fund?
- "How likely are we to implement and maintain this correctly?"
- "How likely is management to reduce future funding because of too much faith in this particular control?" #cybersecurity #risk #crq
It's easier to sell risk assessment if the recommendations statements are specific and posed confidently and assertively. But that betrays the nature of chance and can be difficult to recover from when one's predicted futures fail to realize and the model isn't defensible in retrospect. #crq #risk
This should sound familiar to anyone at an organization that neglects risk modeling and management or who experienced the damage of a parachute manager. #risk #riskmanagement #crq #pra #cybersecurity
Games likes chess force you to face the facts about your skill but poker forces you to face the fact that both luck and skill are at play. A training ground much closer to real life. #risk #crq #pra #riskmanagement #riskassessment #poker
Risk modeling has a complex and fascinating history across cultures. If you're feeling disenchanted or burnt out as a risk or grc practitioner, consider books like these to breathe new life into your work. #grc #riskmanagement #crq #riskassessment #pra #cybersecurity
This is one of those insights that seems obvious when you read it but seems to slip through the cracks as a priority for analysts and decision makers requesting their analysis. #riskmanagement #riskassessment #crq #pra
The number of risk scenarios you model and monitor is worth paying attention to. You have finite resources which is why you're doing risk management but you also have finite resources to manage risk. #riskmanagement #riskassessment #crq #pra
Oh the exam. Rollercoaster of revision emotions. So want it over. But failing Primary leaves a sour taste. Repeated failure doesn’t improve confidence. Lots of concerns about #CRQ expections from all #FinalFRCA revision buddies. Whinge over back to the books before kids wake