NIST CSF Risk Assessment: How to Run One Under CSF 2.0
On February 21, 2024, UnitedHealth Group detected ransomware inside Change Healthcare, the clearinghouse that … Read more
Cyber risk stopped being a technology topic the moment regulators started asking boards to evidence oversight of it. The hard part is no longer knowing that NIST CSF exists. It is deciding which of the six overlapping frameworks and four supervisory regimes on your desk actually applies, and how to avoid running the same assessment four times.
The emphasis here is therefore comparative and practical: what changed between CSF 1.1 and 2.0 and how to transition, how NIST CSF and ISO 27001 differ in use, whether SOC 2 or ISO 27001 is the right certification to pursue, where DORA and NIS2 overlap, and walkthroughs of the FFIEC assessment tool, the FTC Safeguards Rule and 23 NYCRR 500. Quantification gets real treatment too, including the FAIR model applied in financial services.
Pair this with information security management systems, third-party risk and governance, risk and compliance.
On February 21, 2024, UnitedHealth Group detected ransomware inside Change Healthcare, the clearinghouse that … Read more
On June 26, 2024, Evolve Bank & Trust, a roughly $1.5 billion community-class bank … Read more
US warehouse workers logged injuries at a rate of 4.5 cases per 100 full-time … Read more
Figure 1. SOC 2 vs ISO 27001 at a glance — a US attestation … Read more
Figure 1. NIST CSF 2.0 vs 1.1 at a glance — a decade-apart structural … Read more
Figure 1. DORA vs NIS2 at a glance — scope, timing, and core obligations … Read more
In March 2026, a CISO at a mid-cap US bank described her last three … Read more
Between the first half of 2023 and the first half of 2024, mentions of … Read more
Change Healthcare lost $2.46 billion from a single ransomware incident because its BIA failed … Read more
Cyber risk quantification in financial services has become an urgent priority. In January 2024, … Read more
The debate over CPS 234 vs NIST CSF matters most when real breaches expose … Read more
FTC Safeguards Rule Compliance is a critical obligation for financial institutions, and recent enforcement … Read more