How to Pre-Plan Assessment Remediations
Make your assessments meaningful by pre-planning remediations Upon first glance, this may seem backward. Remediations come after the assessment where you discover what needs to be remediated, right? Yes, but if you’ve been involved with risk management for a few cycles of assessment and “reassessment” activities, you’re likely familiar with a common theme: Most post-assessment […]
Align Stakeholders on Your Cybersecurity Strategy
Overview We see that companies of all sizes often lack a strategy to gain buy-in from their stakeholders and thus fail to align on the purpose of assessments. Cyber risk assessments are a vital cornerstone of any risk management strategy. To make sure your organization is getting the maximum value of time and resources invested in these […]
10 Steps for a Successful Assessment Strategy
The key to successful assessment planning begins with clear communication throughout the initial planning phases. To ensure technical and non-technical leaders are aligned on the purpose of the cyber assessment, use the 10 steps below to facilitate communication prior to beginning the assessment. (Note: many of these steps can be done simultaneously.)
Chevron Discusses Scaling Cybersecurity With SecurityGate.io.
Some of the biggest challenges that companies with ICS and operational environments face when running assessments and remediations are time, resources, and staff. Whether you’re just getting started, or are in the midst of building out these processes, there are companies who have been there before, made some mistakes, and have learned lessons worth sharing.
Top 3 mistakes made when going through a business impact analysis and how to avoid them
Edit: If you missed the LIVE show, don’t worry. We recorded it for you and have the video embedded at the bottom of this post. Or, if you prefer, listen to the podcast version on Apple and Spotify. When our customers are going through Business Impact Analysis (BIA) it’s pretty common for them to […]
The first 3 things to focus on in cybersecurity risk management.
Edit: In case you missed the show, we have a video of it posted at the bottom of this blog post. Enjoy! Listen on Spotify or Apple Podcasts We’ve been working on a knowledge base of helpful content for the cybersecurity community and one of the open questions we asked was, How do […]
How to Escape from Spreadsheet Hell (Cyber Risk Manager’s Edition)
First a pop quiz. (Don’t worry, I won’t call on you to answer in front of the class 😉)
Update: GDPR and its Lack of Precise Standards
Numerous cases under the GDPR standards are now in process or have already resulted in fines being levied:
Recent Russian Cyber Attacks and How to Defend Your Business from Cybersecurity Threats
A Brief Explanation of the Russian Cyber Attacks On March 15, 2018, a Technical Alert (TA) was released jointly by the Department of Homeland Security (DHS) and the FBI which implicated Russian government cyber actors in the targeting of numerous US, Canadian, and European targets. The cyberattacks used a variety of infection vectors, including malicious […]