Cyber risk,
in plain terms.
Short, practical reading on quantifying cyber risk, the vCISO model, and making cyber defensible to a board, an investor, or an insurer.
Articles
-
AI risk
What Is Shadow AI?
The AI running in your business that nobody recorded. Why it is an inventory problem rather than a new risk category, and what it does to your exposure number.
Read → -
Governance
Cyber Materiality Under the SEC Rules
The four-day clock starts when you decide an incident is material. Why that decision is the hard part, and how boards set the threshold before they need it.
Read → -
Cyber insurance
How Risk Quantification Lowers Your Cyber Insurance Premium
Premiums are set on evidence, not effort. How a quantified, validated view of your risk changes the renewal conversation.
Read → -
Governance
NIST CSF 2.0: What Boards Need to Know
The new Govern function puts cyber on the board's agenda. The six functions, and the questions directors should be asking.
Read → -
Cyber risk quantification
What Is Cyber Risk Quantification?
Exposure in dollars instead of a red-yellow-green heat map: what CRQ is, how it works, and what a number lets you do.
Read → -
Private equity
Cyber Risk for Private Equity Portfolios
Why thirty assessments are not a portfolio view, what one operating view looks like, and how to roll it out across the book.
Read → -
vCISO
vCISO vs. Fractional CISO: What's the Difference?
Two names for the same role, one distinction that actually matters, and the questions to ask before you hire one.
Read → -
Board reporting
How to Report Cyber Risk to the Board
What directors actually need, why heat maps fall short, and how to put cyber risk in terms a board can govern against.
Read →
Have a question
behind the reading?
If something here maps to a decision you are facing, that is a good reason to talk. No pitch on the first call.