Insights Into Cybersecurity Risk Management

Cybersecurity is the most significant non-financial risk faced by the public and private sectors. It is a complex risk that market forces alone have failed to manage. It is a risk that governments are starting to regulate.  It is a dynamic and unstable risk that is poorly understood and managed in general, demonstrated by the frequency, complexity and severity of cyber attacks.  The insurance industry is struggling to economically underwrite and remediate cyber risk.  All resulting in the European Commission, US Government and governments across the GCC region and Asia introducing cybersecurity risk management regulation.

Regulation that, when it turns to enforcement, will over time set precedent, reaffirm compliance standards and be tested in court. Enforcement actions that place corporate boards on notice that their decisions could be assessed, in response to their fiduciary duties in assessing, mitigating and responding to cyber risks and incidents.

We have written several papers addressing cybersecurity, cybersecurity regulatory compliance, board governance, risk management and cybersecurity risk strategy.  Our work has been reviewed by The White House Office of the National Cyber Director (ONCD), Cyberspace Solarium Commission, Academic Institutions and international professional associations.

Cyber Risk Management Moves Left of Bang 1.0

Left of Bang : Nation States are Regulating Cybersecurity Risk Management.

Cyber Risk Management Moves Left of Bang 2.0

Left of Bang : Cyber Regulation Transfers Cyber Risk Into The Board Room.

FISMA, OMB & The RMF

FISMA : The Federal Regulatory Elephant In The Room.

FISMA, SCRM & The DoD

FISMA : Why The Global Defense Supply Chain Should Care.

Augusta Plan 1.0

Augusta Plan 1.0 : An Approach for International Cybersecurity.

Augusta Plan 2.0

Augusta Plan 2.0 : Leveraging Existing Regulation To Manage US Cybersecurity.

Augusta Plan 3.0

Augusta Plan 3.0 : Harmonising Cyber Between Federal Agencies & US Allies.

Small Business Cybersecurity
Is Cyber An Insurable Risk

Cyber Insurance : Cyber Insurance Won’t Address Cyber Risk Transfer.

The Securities and Exchange Commission Cyber Rule

The SEC Cyber Rule : Requiring Boards Of Covered Companies Manage Material Cyber Risks and Incidents.

previous arrow
next arrow