Cybersecurity

Cyber risk stopped being a technology topic the moment regulators started asking boards to evidence oversight of it. The hard part is no longer knowing that NIST CSF exists. It is deciding which of the six overlapping frameworks and four supervisory regimes on your desk actually applies, and how to avoid running the same assessment four times.

The emphasis here is therefore comparative and practical: what changed between CSF 1.1 and 2.0 and how to transition, how NIST CSF and ISO 27001 differ in use, whether SOC 2 or ISO 27001 is the right certification to pursue, where DORA and NIS2 overlap, and walkthroughs of the FFIEC assessment tool, the FTC Safeguards Rule and 23 NYCRR 500. Quantification gets real treatment too, including the FAIR model applied in financial services.

Pair this with information security management systems, third-party risk and governance, risk and compliance.

Receive the latest articles in your inbox