<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://riskpublishing.com/wp-content/plugins/pretty-rss-feeds/xslt/pretty-feed.xsl" type="text/xsl" media="screen" ?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Cybersecurity &#8211; Risk Publishing</title>
	<atom:link href="https://riskpublishing.com/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://riskpublishing.com</link>
	<description>Connecting Risk Professionals</description>
	<lastBuildDate>Tue, 16 Jun 2026 13:58:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://riskpublishing.com/wp-content/uploads/2021/12/cropped-favicon2-32x32.png</url>
	<title>Cybersecurity &#8211; Risk Publishing</title>
	<link>https://riskpublishing.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>FFIEC Cybersecurity Assessment Tool Walkthrough for Community Banks</title>
		<link>https://riskpublishing.com/ffiec-cybersecurity-assessment-tool/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 26 May 2026 09:50:28 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cyber Insurance Risk Assessment]]></category>
		<category><![CDATA[cybersecurity risk]]></category>
		<category><![CDATA[Cybersecurity Risk Key Risk Indicators Examples]]></category>
		<category><![CDATA[FFIEC Cybersecurity Assessment Tool]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=36546</guid>

					<description><![CDATA[On June 26, 2024, Evolve Bank &#38; Trust, a roughly $1.5 billion community-class bank headquartered in Arkansas, disclosed a LockBit ransomware breach that ultimately affected about 7.6 million customers. The Federal Reserve enforcement action issued that same June cited deficiencies in IT, risk management, and vendor governance. For community banks still running their FFIEC Cybersecurity ... <a title="FFIEC Cybersecurity Assessment Tool Walkthrough for Community Banks" class="read-more" href="https://riskpublishing.com/ffiec-cybersecurity-assessment-tool/" aria-label="Read more about FFIEC Cybersecurity Assessment Tool Walkthrough for Community Banks">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>OSHA Recordkeeping Risks for US Warehouses Under 50 Employees</title>
		<link>https://riskpublishing.com/osha-recordkeeping-risks-for-us-warehouses/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 26 May 2026 08:29:36 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=36539</guid>

					<description><![CDATA[US warehouse workers logged injuries at a rate of 4.5 cases per 100 full-time equivalents in 2024, almost double the 2.3 average across all private industry. The Bureau of Labor Statistics released the figure in January 2026. For a warehouse with 40 FTE, that benchmark predicts about two recordable cases each calendar year, every year. ... <a title="OSHA Recordkeeping Risks for US Warehouses Under 50 Employees" class="read-more" href="https://riskpublishing.com/osha-recordkeeping-risks-for-us-warehouses/" aria-label="Read more about OSHA Recordkeeping Risks for US Warehouses Under 50 Employees">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>SOC 2 vs ISO 27001: Which Security Certification to Pursue</title>
		<link>https://riskpublishing.com/soc-2-vs-iso-27001-which-security-certificatio/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 05:35:05 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34954</guid>

					<description><![CDATA[Figure 1. SOC 2 vs ISO 27001 at a glance — a US attestation report and an international certification meeting around a shared security agenda. In December 2025, a Series B SaaS company in Austin lost a $2.4M enterprise contract to a competitor. The reason was not price, features, or security. The reason was paperwork ... <a title="SOC 2 vs ISO 27001: Which Security Certification to Pursue" class="read-more" href="https://riskpublishing.com/soc-2-vs-iso-27001-which-security-certificatio/" aria-label="Read more about SOC 2 vs ISO 27001: Which Security Certification to Pursue">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>NIST CSF 2.0 vs 1.1: What Changed and How to Transition</title>
		<link>https://riskpublishing.com/nist-csf-2-0-vs-1-1-what-changed-and-how-to/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 04:58:20 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34949</guid>

					<description><![CDATA[Figure 1. NIST CSF 2.0 vs 1.1 at a glance — a decade-apart structural reset with governance moved to the center. In January 2026, the CISO of a 1,400-employee regional bank in Charlotte, North Carolina, walked into an audit committee review with what she thought was a solid story: SOC 2 Type II renewed, NIST ... <a title="NIST CSF 2.0 vs 1.1: What Changed and How to Transition" class="read-more" href="https://riskpublishing.com/nist-csf-2-0-vs-1-1-what-changed-and-how-to/" aria-label="Read more about NIST CSF 2.0 vs 1.1: What Changed and How to Transition">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>DORA vs NIS2: How EU Cyber Resilience Regulations Differ and Overlap</title>
		<link>https://riskpublishing.com/dora-vs-nis2-how-eu-cyber-resilience-regulation/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 21 Apr 2026 04:44:12 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34900</guid>

					<description><![CDATA[Figure 1. DORA vs NIS2 at a glance — scope, timing, and core obligations across both EU cyber resilience regimes. On 18 March 2026, BaFin — Germany’s financial supervisor — closed its submission window for the DORA Register of Information. Within 48 hours, a mid-sized Frankfurt asset manager received its first formal DORA supervisory letter: ... <a title="DORA vs NIS2: How EU Cyber Resilience Regulations Differ and Overlap" class="read-more" href="https://riskpublishing.com/dora-vs-nis2-how-eu-cyber-resilience-regulation/" aria-label="Read more about DORA vs NIS2: How EU Cyber Resilience Regulations Differ and Overlap">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>CISSP vs CISM vs CRISC: Comparing Cybersecurity and Risk Certifications</title>
		<link>https://riskpublishing.com/cissp-vs-cism-vs-crisc-comparing-cybersecurity/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Mon, 20 Apr 2026 11:34:40 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34810</guid>

					<description><![CDATA[In March 2026, a CISO at a mid-cap US bank described her last three hires to me. Each had a different certification stack: a Director of Security Architecture holding CISSP, a Head of Information Security Governance holding CISM, and an Enterprise IT Risk Lead holding CRISC. &#8220;I used to think these were interchangeable,&#8221; she said. ... <a title="CISSP vs CISM vs CRISC: Comparing Cybersecurity and Risk Certifications" class="read-more" href="https://riskpublishing.com/cissp-vs-cism-vs-crisc-comparing-cybersecurity/" aria-label="Read more about CISSP vs CISM vs CRISC: Comparing Cybersecurity and Risk Certifications">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>NIST CSF vs ISO 27001: Which Cybersecurity Framework Is Right for You?</title>
		<link>https://riskpublishing.com/nist-csf-vs-iso-27001-which-cybersecurity/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Sat, 18 Apr 2026 04:09:46 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34616</guid>

					<description><![CDATA[Between the first half of 2023 and the first half of 2024, mentions of the NIST Cybersecurity Framework in US public-company 10-K filings jumped from 51 to 1,141 — a 22x increase driven almost entirely by the SEC cybersecurity disclosure rules. Over the same window, worldwide ISO/IEC 27001 valid certificates doubled from 48,671 to 96,709 ... <a title="NIST CSF vs ISO 27001: Which Cybersecurity Framework Is Right for You?" class="read-more" href="https://riskpublishing.com/nist-csf-vs-iso-27001-which-cybersecurity/" aria-label="Read more about NIST CSF vs ISO 27001: Which Cybersecurity Framework Is Right for You?">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Ransomware Business Impact Analysis: Linking Cyber Incidents to BIA and BCP</title>
		<link>https://riskpublishing.com/ransomware-business-impact-analysis-guide/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Tue, 14 Apr 2026 09:41:27 +0000</pubDate>
				<category><![CDATA[Business continuity management]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34355</guid>

					<description><![CDATA[Change Healthcare lost $2.46 billion from a single ransomware incident because its BIA failed to account for cascading third-party dependencies across the healthcare ecosystem. On February 21, 2024, the ALPHV BlackCat ransomware group encrypted significant portions of Change Healthcare, a subsidiary of UnitedHealth Group that processes 15 billion healthcare transactions annually and touches one in ... <a title="Ransomware Business Impact Analysis: Linking Cyber Incidents to BIA and BCP" class="read-more" href="https://riskpublishing.com/ransomware-business-impact-analysis-guide/" aria-label="Read more about Ransomware Business Impact Analysis: Linking Cyber Incidents to BIA and BCP">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Cyber Risk Quantification in Financial Services: FAIR Model Applied</title>
		<link>https://riskpublishing.com/cyber-risk-quantification-in-financial-services/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Wed, 08 Apr 2026 14:59:46 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cyber Risk Quantification in Financial Services]]></category>
		<category><![CDATA[risk assessment]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=34132</guid>

					<description><![CDATA[Cyber risk quantification in financial services has become an urgent priority. In January 2024, the IMF&#8217;s Managing Director Kristalina Georgieva issued an unusually direct warning: the financial sector urgently needs cyber risk quantification capabilities because &#8216;extreme losses from cyber incidents are increasing&#8217; and the sector&#8217;s interconnectedness means one institution&#8217;s breach can cascade across the system. ... <a title="Cyber Risk Quantification in Financial Services: FAIR Model Applied" class="read-more" href="https://riskpublishing.com/cyber-risk-quantification-in-financial-services/" aria-label="Read more about Cyber Risk Quantification in Financial Services: FAIR Model Applied">Read more</a>]]></description>
		
		
		
			</item>
		<item>
		<title>CPS 234 vs NIST CSF: Cyber Risk Framework Comparison for Multinationals</title>
		<link>https://riskpublishing.com/cps-234-vs-nist-csf-cyber-risk-framework/</link>
		
		<dc:creator><![CDATA[Chris Ekai]]></dc:creator>
		<pubDate>Thu, 02 Apr 2026 09:40:53 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[CPS 234 vs NIST CSF]]></category>
		<category><![CDATA[cybersecurity risk]]></category>
		<category><![CDATA[Cybersecurity Risk Key Risk Indicators Examples]]></category>
		<guid isPermaLink="false">https://riskpublishing.com/?p=33967</guid>

					<description><![CDATA[The debate over CPS 234 vs NIST CSF matters most when real breaches expose framework gaps. In September 2022, Australian telecommunications giant Optus disclosed a data breach affecting 9.8 million customers, roughly 40% of the Australian population. APRA-regulated entities that relied on Optus infrastructure scrambled to assess their own exposure, and many discovered an uncomfortable ... <a title="CPS 234 vs NIST CSF: Cyber Risk Framework Comparison for Multinationals" class="read-more" href="https://riskpublishing.com/cps-234-vs-nist-csf-cyber-risk-framework/" aria-label="Read more about CPS 234 vs NIST CSF: Cyber Risk Framework Comparison for Multinationals">Read more</a>]]></description>
		
		
		
			</item>
	</channel>
</rss>
