Cyber Risk Management: Prioritize Threats, Identify Vulnerabilities and Apply Controls

  • 7h 29m
  • Christopher Hodson
  • Kogan Page
  • 2019

Most organizations are undergoing a digital transformation of some sort and are looking to embrace innovative technology, but new ways of doing business inevitably lead to new threats which can cause irreparable financial, operational and reputational damage. In an increasingly punitive regulatory climate, organizations are also under pressure to be more accountable and compliant. Cyber Risk Management clearly explains the importance of implementing a cyber security strategy and provides practical guidance for those responsible for managing threat events, vulnerabilities and controls, including malware, data leakage, insider threat and Denial-of-Service.

Examples and use cases including Yahoo, Facebook and TalkTalk, add context throughout and emphasize the importance of communicating security and risk effectively, while implementation review checklists bring together key points at the end of each chapter. Cyber Risk Management analyzes the innate human factors around risk and how they affect cyber awareness and employee training, along with the need to assess the risks posed by third parties. Including an introduction to threat modelling, this book presents a data-centric approach to cyber risk management based on business impact assessments, data classification, data flow modelling and assessing return on investment. It covers pressing developments in artificial intelligence, machine learning, big data and cloud mobility, and includes advice on responding to risks which are applicable for the environment and not just based on media sensationalism.

About the Author

Christopher J Hodson is Chief Information Security Officer (CISO), EMEA at Tanium. He has 18 years' experience across the financial, retail, energy and media industry sectors and was previously CISO, EMEA and Data Protection Officer at Zscaler. He holds an MSc in Cyber Security from Royal Holloway and retains an active role in the Infosec industry through directorship of the Institute of Information Security Professionals (IISP) and membership of CompTIA's Cyber Security Committee.

In this Book

  • Why Now? The Only Constant is Change
  • Technologies and Security Challenges
  • Data Breaches
  • What are Cybersecurity and Cybercrime?
  • Establishing a Cybersecurity Programme
  • Threat Actors
  • Threat Events
  • Vulnerabilities
  • Controls
  • Cyber Risk Management—A Conclusion