
Sign up to save your podcasts
Or


What threats does your project, or business, face? What opportunities have you identified that you could pursue? What strengths do you have that you can leverage to achieve your goals? What weaknesses might hold you back or cause you to fail? Underlying all of these questions, is your situation and the external factors in play. The answers influence the direction you should take.
In this episode Martin and Maurice explore the elements of SWOT analysis, provide some pointers to help you differentiate the different factors, and highlight why this is important in the planning and execution of the course you take. Informally they discuss: the context you're operating within; the capabilities you have, and those you don't have; and the challenges thrust upon you and those you choose to undertake. Only by understanding these can you set your course with confidence.
Does the CISO own all cyber related risks to the business? It depends, but in many businesses that is the default position. Who is responsible for risk identification and analysis; identification, rating and selection of treatment options; and for managing residual risks within the defined risk appetite? Is it the security function, the business service owner, the application owner, the data owner, or is it potentially none of these? Should we not logically separate risk management responsibility and risk ownership? What about systemic risks?
In this episode regular hosts Martin and Maurice are joined by Bill Schultz from Vanderbilt University Medical Center to discuss cyber risk management. We’ll discuss our ideas, VUMC’s architected approaches, and the realities of cyber risk management in a business where lives are at risk and privacy is paramount.
In our previous episode we referenced not being in business to be compliant. Of course, that doesn't mean that compliance is never important; in some instances, it is critical to maintaining a licence to operate in an industry or market.
Compliance isn’t a mission, a purpose or a goal. Compliance provides some fenceposts, an approach to measurement, and in many cases a degree of reassurance. But is compliance alone sufficient to protect our organisations? How does a compliance led approach compare to a security led approach?
In this episode we discuss compliance and how it relates to information security, whose interests it serves, and the value business driven security can deliver beyond compliance.
Ransomware does not appear to have fallen victim to the pandemic. On the contrary, successful attacks appear to have increased and the impacts are escalating too. Hardly a day goes by without news of another ransomware attack on a prominent organisation or further details of a previous attack are shared. Has the massive increase in remote working improved the success rate, have organised crime groups switched focus from other income streams that have been hit? Maybe, but answering those questions probably won't give you actionable insights into what you need to do to protect your assets.
Join us as we discuss how you can prepare for a ransomware attack and whether paying should ever be considered.
In the light of recurring instances of security issues in foundational components of modern IT and software stacks, and the superfast world our businesses are operating in, Maurice and Martin talk about trust. What can it mean to say we trust a vendor or a partner? Can we ever really trust one of the Internet giants? Can we secure trust?
Join us as we explore the role of trust in organisational cyber security.
From the publisher's feed