Cybersecurity Risk’s “New Math”

Mary K. Pratt posted an article, “The new math of cybersecurity value,” on CSOonline on September 21, 2021, available at The new math of cybersecurity value | CSO Online   It is a ...

Cybersecurity Lessons from the Pandemic: Avoidance

There are a number of confusing differences of opinion with respect to handling the COVID-19 pandemic. Some of the confusion seems to center around a common misunderstanding of the roles of various ...

Cybersecurity Lessons from the Pandemic: Plans, Exercises and Warnings

Like many others during this stay-at-home period, I have been sorting through old articles and reports, culling out those that are no longer of value. But, in the process, I came across ...

Cybersecurity Lessons from the Pandemic: Perception of Risk

The more “mature” among us may recall when decision-making under uncertainty was based on the concept of “rational economic man.” We estimated or calculated the probability and amount of a loss (or ...

Cybersecurity Lessons from the Pandemic – Positive and Negative Feedback

Systems use negative feedback in order to converge to stability and equilibrium (a positive quest). Positive-feedback systems diverge, which leads to instability and sometimes surging out of control (usually a negative outcome) ...

Cybersecurity Lessons from the Pandemic: Models and Predictions

There are a number of different types of models—and the output from each must be viewed and used differently depending on the form of the model. First, you have relationships derived from ...

Cybersecurity Lessons from the Pandemic: Data – Part 1

The collection and reporting of data relating to the coronavirus pandemic and related medical research and practices are in a shambles. For example, a June 7, 2020 article by Jason Slotkin cites ...

Truth, Trust and Cybersecurity Risk

It is a sad reflection on the times, but it is becoming increasingly difficult to distinguish among true and false “facts,” accurate and misleading interpretations, and personal and politically-expedient beliefs. In my ...

Cybersecurity Risk Management … Beyond the “Golden Period”

Where do we stand with the management of cybersecurity risk? Answer … Not in a good place. This position was further augmented upon reading an article in the January 23, 2020 Washington ...
A Cyber Incident Response Plan for Your Web Applications

A Cyber Incident Response Plan for Your Web Applications

Barely a day goes by without reports of a data breach or costly outage in yet another organization, and hundreds of similar incidents go unreported. With so many businesses dependent on web ...