Skip to main content

Cyber Risk Management

Showing posts tagged with "Cyber Risk Management".

ris-blog-fallback-featured-image

New Guidance Clarifies GDPR's Data Protection Impact Assessment (DPIA) Requirements

The Data Protection Impact Assessment (DPIA) is a significant new burden on data controllers under GDPR. As many have noted, GDPR does not clearly out…

Read more

Build a Security Program and Run It Like a Business

I recently finished the book "Traction" by Gino Wickman. Next to Scaling-Up by Verne Harnish, I think it is one of the most actionable business books …

Read more

How to Turn the Risk Committee Meeting into the Most Valuable Meeting on Your Calendar

Mention "Risk Committee" or "Enterprise Risk" to upper management and you will probably get an eye role. If you suggest a standing meeting about risk …

Read more

SEC Issues New Cybersecurity Guidance: What you need to know

On February 21, 2018, the SEC issued new guidance on cybersecurity disclosures for public companies. As an “interpretive release,” the new guidance in…

Read more

Quality Work Does Not Mean Quality Service

Quality Work Does Not Mean Quality Service "Managing the Professional Services Firm" by David Maister is considered to be "core canon" among consultin…

Read more

Key Due Dates and Deliverables for the NYDFS Cybersecurity Regulation

The NYDFS Cybersecurity regulation is relevant to all financial services, banking, and insurance organizations doing business in the state of New York…

Read more

Meltdown and Spectre - A Quick Overview

Bottom Line Up Front Security Researchers have publicly disclosed the details of CPU design flaws that are the result of design decisions made industr…

Read more

Takeaways from SANS SEC560- Ethical Hacking and Pen Testing

This past week I completed the SANS SEC560 - Network Penetration Testing and Ethical Hacking course at the SANS Cyber Defense Initiative in Washington…

Read more
CISSP

Advice for Studying and Passing the CISSP Exam

This past week I sat for the (ISC)2 CISSP exam and passed on my first attempt! With the entire preparation and test taking experience still fresh on m…

Read more

Pen Testing: Malicious File Execution

What is a Malicious File Execution Vulnerability? Malicious file execution vulnerabilities (also called File Inclusion Vulnerabilities) is a vulnerabi…

Read more

What is a Stateful Firewall

Stateful refers to the “state” of the connection between the outside internet and the internal network. A stateful firewall keeps track of the connect…

Read more

Tags

See all