Share E-Book
Scan to open this page

Scan with your phone to open this page

AuthorBrian Allen, Brandon Bapst, Terry Allan Hicks

Cyber risk management is one of the most urgent issues facing enterprises today. This book presents a detailed framework for designing, developing, and implementing a cyber risk management program that addresses your company's specific needs. Ideal for corporate directors, senior executives, security risk practitioners, and auditors at many levels, this guide offers both the strategic insight and tactical guidance you're looking for. You'll learn how to define and establish a sustainable, defendable, cyber risk management program, and the benefits associated with proper implementation. Cyber risk management experts Brian Allen and Brandon Bapst, working with writer Terry Allan Hicks, also provide advice that goes beyond risk management. You'll discover ways to address your company's oversight obligations as defined by international standards, case law, regulation, and board-level guidance. This book helps you: Understand the transformational changes digitalization is introducing, and new cyber risks that come with it Learn the key legal and regulatory drivers that make cyber risk management a mission-critical priority for enterprises Gain a complete understanding of four components that make up a formal cyber risk management program Implement or provide guidance for a cyber risk management program within your enterprise

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical framework for designing, running, and defending an enterprise cyber risk management program—written for board members, executives, security leaders, and auditors who must turn scattered security controls into a coherent, accountable, and legally defensible practice. 【Book Arc】 - **Opening (~0%–10%)**: Frames the problem: digital transformation is accelerating risk faster than traditional security can respond, and regulators (starting with the 2018 SEC guidance) now expect boards to oversee a formal cyber risk management program—yet no authoritative definition existed. - **Early (~10%–30%)**: Explains why cybersecurity is fundamentally a risk practice, surveys the five trends reshaping enterprise risk (industry convergence, globalization, oversight expectations, legal action, regulatory complexity), and shows sector-by-sector what's at stake. - **Early–Middle (~30%–45%)**: Introduces the cyber risk management program (CRMP) itself—its four components, the standards and guidance behind it, and why existing tools like risk registers and MFA aren't a program unless formalized. - **Middle (~45%–60%)**: Makes the case through failure: the Boeing 737 MAX disasters illustrate what happens without defined risk posture, escalation, and disclosure—lessons that transfer directly to cyber risk. - **Late (~60%–85%)**: Details the benefits of a functioning program—strategic standing for security, defendable budgets, protection for risk decision makers, and consistent/expected/trusted outputs—plus board accountability and legal liability. - **Ending (~85%–100%)**: Moves toward implementation and oversight obligations under international standards, case law, regulation, and board-level guidance (excerpts do not cover the closing chapters in detail). 【Key Takeaways】 - **Digitalization changes the risk equation, not just the technology** (Early): five converging trends—industry convergence, globalization, oversight expectations, legal action, and a shifting regulatory landscape—make enterprise risk faster, more volatile, and harder to manage. - **Cybersecurity is fundamentally a risk practice** (Early): treating security as a risk function (rather than a compliance or IT task) is the conceptual pivot the whole book rests on. - **A CRMP is a formal, standalone program—not a pile of tools** (Early–Middle): governance models, risk registers, MFA, and pen testing are necessary but insufficient unless integrated into a defined program with consistent outputs. - **Four components define a formal program** (Middle): the authors build their framework around four components tied to regulatory, legal, and industry guidance; the excerpts name the framework but do not enumerate all four in detail. - **Program outputs must be consistent, expected, and trusted** (Middle): these three qualities are what let the board, CxOs, and business leaders rely on risk information as a strategic input rather than an ad hoc report. - **Failure to manage risk cascades** (Middle): the Boeing 737 MAX case shows how missing risk posture, escalation, and disclosure leads to compounding bad decisions—an analog for cyber failures. - **A real program protects people, not just systems** (Late): it gives security a seat at the table, justifies budgets through risk appetite and tolerance, and shields decision makers from post-incident blame. - **Oversight obligations are legal and international** (Late): board liability, shareholder litigation, SEC guidance, WEF board frameworks, and the IIA Three Lines Model all push cyber risk management from best practice toward duty. 【Reading Tips】 - **Read Chapters 1–2 closely**: they carry the book's core argument (digitalization → risk practice → CRMP). Skim the sector table if you already know your industry's threat landscape. - **Treat the Boeing case as a teaching device, not a cyber story**: extract the risk-posture, escalation, and disclosure lessons and map them onto your own organization. - **Use the standards references as a checklist**: SEC 2018 guidance, NACD Director's Handbook, IIA Three Lines Model, AICPA CRMP, and WEF board principles are cited as drivers—look them up alongside the text. - **Bring your own program to the book**: the framework is meant to be applied; note gaps in your governance, risk register, and reporting as you read. - **Executives and board members can start with the benefits and liability sections**, then return to the framework chapters for implementation detail. 【Coverage Limits】 This guide is based on stratified excerpts covering roughly the first half of the book; the later implementation chapters, the full enumeration of the four CRMP components, and the closing oversight guidance are only partially represented.
Page 5
. . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 The Fourth Industrial Revolution 3 Cybersecurity Is Fundamentally a Risk Practice 6 Cyber Risk Mana...
View in text
Page 20
, customers—are spread across the entire world, enterprises have to recognize that the risks they face are different, highly unpredictable, and on a scale th...
View in text
Excerpt 3
nd do it with the consistent and trusted outputs they need. Regulatory bodies worldwide are making it increasingly clear that they will no longer accept a la...
View in text
Excerpt 4
and its activities recognized standing as a critical stra‐ tegic undertaking. As we pointed out earlier, a defined CRMP leads to outputs that are consistent,...
View in text
Excerpt 5
rm for Cyber Executives,” Washing‐ ton Post, June 29, 2023. 38 | Chapter 2: The Cyber Risk Management Program CHAPTER 3 Agile Governance In the preceding cha...
View in text
Excerpt 6
tanding of the organization’s overall risk landscape, lead‐ ing to more informed decision making. It ensures consistency and avoids poten‐ tial gaps or overl...
View in text
Excerpt 7
22 6.1.2, 6.1.3 ISO/IEC 27001 adopts a risk-based approach. Top management is responsible for ensuring the organization’s risks are identified, assessed, and...
View in text
Excerpt 8
ns that were almost certainly risk-informed and risk-based. Microsoft was already an investor in OpenAI, and after ChatGPT’s launch it added billions of doll...
View in text
Tags
AI categories
CybersecurityTechnologySoftware
ISBN: 1098147790
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 223
File Format: PDF
File Size: 2.8 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…