cyber risk
High-profile cyber incidents are forcing boards to take security more seriously. But CISOs still need to balance the business strategy with basic defensive measures, and demands for resilience.
CISOs are now risk managers, argues Qualys' CEO. This means prioritising what threatens the business and thinking about windows of weaponisation, as well as...
"Risk management is about 'how much' -- and 'how much' is about money"
'Do not state anything that is subjective and avoid adjectives (e.g., "state of the art," "mature," "advanced," "appropriate," "comprehensive," or "reasonable")' say experts.
New metrics for Operational Technology exposure include whether the "consequences of the vulnerability meet definition of IEC 61508 consequence categories of "marginal," "critical," or "catastrophic."
Terminals are "operating with limited capacity" as company declares force majeure