
Why Ransomware Isn’t Just a Technology Problem (It’s Worse)
Ransomware isn’t a tech failure - it’s a market failure. If you think the hardest part is getting hacked, wait until the lawyers, insurers, and PR firms show up ...

Vendor Sales Tactics: The Good, The Bad, and the Bathroom
Most security vendors are great — but a few cross the line from persistent to downright creepy, sometimes in ways you won’t believe. With RSA Conference looming, here’s a behind-the-scenes look at ...

What the Great Hanoi Rat Massacre of 1902 and Modern Risk Practices Have in Common
When the French tried to solve Hanoi’s rat problem, they accidentally made it worse , and today’s cyber risk management is making the same mistake. Beneath the polished audits and colorful risk ...

Zines, Blogs, Bots: A Love Story
AI-generated using ChatGPT Taking a Break (But Not Really)I haven’t blogged in a while. Life, as it does, got full - between work, family, and a growing need for balance, I found ...

I-4 2022 Talk: How do I get started? Easing your company into a quantitative cyber risk program
This is a companion post for my talk titled, “Baby Steps: Easing your company into a quantitative cyber risk program.” This blog post contains links and resources to many of the items ...

The CISO’s White Whale: Measuring the Effectiveness of Security Awareness Training
Boats attacking whales | Source: New York Public Library Digital Collections I have a hypothesis about end-user security awareness training. Despite heavy investment, most - if not all - CISO’s wonder if ...

How a 14th-century English monk can improve your decision making
Nearly everyone has been in a situation that required us to form a hypothesis or draw a conclusion to make a decision with limited information. This kind of decision-making crops up in ...

A Beginner’s Guide to Cyber War, Cyber Terrorism and Cyber Espionage
Tune in to just about any cable talk show or Sunday morning news program and you are likely to hear the terms “cyber war,” “cyber terrorism,” and “cyber espionage” bandied about in ...

My 2022 Predictions — with Skin in the Game!
A new year always means one thing in any field with an ample number of armchair pundits: another round of annual predictions. The big problem with annual prediction lists is that they ...

How to write good risk scenarios and statements
Risk management is both art and science. There is no better example of risk as an art form than risk scenario building and statement writing. Scenario building is the process of identifying ...