Sharpen your skills in IT risk management
Top 5 objections to using quantitative models within cyber risk management
Changing habits and mindsets take time and persistence. Especially within IT risk management. Again and again, we at ACI meet tonnes of objections to changing behaviour despite witnessing the benefits of moving from qualitative to quantitative. So, I felt...
Managing Cyber Risk With Tactical and Strategic Management Information
Communication is difficult, also when it comes to the risk of cyberattacks. The board and management need a clear basis for decision-making, but the communication needs to improve because it is often too technical or too high-level and abstract. Both cases are useless...
When a robot gives better estimates than a human
For organisations with many (several hundred) systems, quantitative IT risk management can be likened to a window cleaner being asked to clean the United Nations headquarters in New York. He will never finish before the first couple of windows need cleaning again. The...
The organisation’s dripping faucets
A clear agenda for the organization is: "Understand and reduce the risk of cyber-attacks". The management and the board have gradually joined the agenda and understand that we are dealing with a risk that they must deal with. We estimate that cyber can cause extreme...
A guide to a simple probabilistic risk assessment
When you assess IT-risk, you want to understand the probability of certain risk scenarios together with their potentiel loss in monetary values. This is where quantitative solutions come handy. How does a quantitative risk assessment work? How do I get started with...
Risk appetite – Why and how to determine it?
A skilled offshore engineer with whom I collaborated gave me a very concrete example of the application of risk appetite. The height of a drilling platform is set according to legislation and standards but also according to the company's risk appetite. How big a wave...
Risk scenarios – why and how?
If you are an IT expert and are asked to estimate, you may have experienced the frustration of having to estimate based on poorly formulated scenarios. If you are a risk manager and have had to build a risk register, you may also have experienced that it can be tiring...
The art of producing a 90% confidence interval using decomposition and calibration
When speaking about future events, it's inherently subject to uncertainty. A risk assessment tries to understand future loss events and is therefore also subject to uncertainty. The less history or fewer measurements, the greater the uncertainty. How can one predict...
Risk matrices for IT risk assessments – the most used method that doesn’t work
Avoid causing harm. It is part of the classical Hippocratic oath. It should also be part of the risk management specialist's promise. Nevertheless, the use of risk management methods that do more harm than good has become widespread. Fortunately, we are seeing...