Bill Murphy's RedZone 10X Podcast

S3 E9: Are IT Security Leaders Allowed to Forecast? Become Comfortable with Uncertainty


Listen Later

Jack Freund, the guest of my latest podcast, is the co-author of a book with Jack Jones on quantifying risk (Measuring and Managing Information Risk: A FAIR Approach). This book was inducted into the Cybersecurity Canon in 2016. The Cyber Security Canon is a Hall of Fame for IT Security books. The founder Rick Howard has been a previous guest on this podcast.

Some of the links that I really like from this episode are Jack's presentation called "Assessing Quality in Cyber Risk Forecasting", his most recent article in the ISSA Journal that I love called "Using Data Breach Reports to Assess Risk Analysis Quality". You will be able to find all links and show notes at redzonetech.net/podcast

This episode is sponsored by the CIO Scoreboard

Major take-aways from this episode are:

1. Elevate Your IT Security Risk Communication Game using Data Breach reports to Inspire Action in the Business 2. How to use Risk Data so that the business becomes more comfortable with uncertainty 3. New Refreshing perspectives on presenting IT Security Risk to the business 4. Predicting and Forecasting likelihood and frequency of events happening into your risk analysis 5. How to Use External Data Breach Sources of competitors and non-competitors to build your risk cases.

About Jack

Dr. Jack Freund is a leading voice in Information Risk measurement and management with experience across many industry segments. His corporate experience includes spearheading strategic shifts in IT Risk by leading his staff in executing multimillion dollar efforts in cooperation with other risk and control groups.

Jack has been awarded a Doctorate in Information Systems, Masters in Telecom and Project Management, and a BS in CIS. He holds the CISSP, CISA, CISM, CRISC, CIPP, and PMP designations. Jack's academic credentials include being named a Senior Member of the ISSA, IEEE, and ACM, a Visiting Professor, and an Academic Advisory Board member.

Find transcript here

How to get in touch with Jack Freund
  • LinkedIn profile
  • Twitter
Key Resources:
  • Jack's personal blog and website The Risk Doctor
Books/Publications
  • Jack's book Measuring and Managing Information Risk: A FAIR Approach inducted into the Cyber Security Canon Hall of Fame – Books every cyber security professional should read
  • ISSA Journal Article , Feb 2016, that has links to important external data sources for risk analysis: (see page 21)
  • Assessing Quality in Cyber Risk Forecasting Presentation
  • Article in ISACA "Cloudy with a chance of risk"

This episode is sponsored by the CIO Scoreboard, a powerful tool that helps you communicate the status of your IT Security program visually in just a few minutes.

Credits: * Outro music provided by Ben's Sound

Other Ways To Listen to the Podcast iTunes | Libsyn | Soundcloud | RSS | LinkedIn

Leave a Review If you enjoyed this episode, then please consider leaving an iTunes review here

Click here for instructions on how to leave an iTunes review if you're doing this for the first time.

...more
View all episodesView all episodes
Download on the App Store

Bill Murphy's RedZone 10X PodcastBy Bill Murphy