Understanding cyber risk from the enterprise level on down

0
137
Appropriate attention to both understanding and mitigating cyber risk is valuable at the enterprise level because it increases the entire organization’s readiness to deal with the risk at all levels. Appropriate attention to both understanding and mitigating cyber risk is valuable at the enterprise level because it increases the entire organization’s readiness to deal with the risk at all levels. (National Underwriter P&C magazine)

It’s impossible to escape the barrage of news about cyber attacks. At the enterprise level, we also observe varying degrees of insight into how to understand and manage it.

Boards of directors are turning attention from understanding the risk to understanding management’s readiness to deal with the risk. That translates into questions such as, “Do we understand the risk well enough to prevent, mitigate and recover from a large-scale cyber event?”

Common sense risk analysis

Risk analysis starts with awareness of the risks an organization faces. The better an organization understands the risks it’s dealing with, the more robust its risk analysis and risk-based decision making will be.

Some common suggestions for improving risk awareness include the following:

  1. Harvest the risk information you already have. Whether it’s through formal risk assessment activities already underway,…

Read More…