A useful starting point for a CISO board report is the decision sought. In our fictional sample, two Critical risks concern administrator access and recovery after ransomware. The proposed decisions concern engineering time and a recovery exercise w...
Read More
A cyber risk register becomes easier to discuss when a record explains what could happen to the organisation. In our fictional example, stolen administrator credentials could interrupt customer services. That gives the board a consequence to conside...
Read More