Formal Operational Resilience Management Information to Build Operational Resilience (Part2):

Part 2 Good Practices for Cyber Risk Management To manage cyber risk and assess cybersecurity preparedness of its critical operations, core business lines and other operations, services, and functions organisations may choose to use standardised tools that are aligned with common industry standards and best practices. Our preference is the National Institute of Standards and […]
Formal Operational Resilience Management Information to Build Operational Resilience (Part1):

Operational resilience is the ability to deliver operations, including critical operations and corebusiness function, through a disruption from any hazard. It is the outcome of effective operational risk management combined with sufficient financial and operational resources to prepare, adapt,withstand, and recover from disruptions. Any organisation that operates in a safe and sound manner is able […]
IT Chief Information Security Officer, CISO discussion with a board, what issues matter to them and how to engage them.

Information Technology is a core business operation, it is now essential to most business operations. Technical staff – IT Mangers, Chief Information Officers, Chief Information System Officers now are being engaged by senior management and the board. Working at this level, board members are from all backgrounds and experiences, and you may be lucky to […]
Cyber threats (IT Risks) pose a very real and significant, risk to their operations.
Steps to cyber risk assessment
Once that’s completed here are the steps needed to undertake a cyber risk audit.
1. Identify threat sources and events
2. Identify vulnerabilities and how they may be exploited
3. Estimate the likelihood of these threats occurring
4. Evaluate the potential impact on your business if they do occur
5. Determine the degree of risk involved
6. Rank the risks in order of priority
7. Prioritise actions and responses to critical risks
Before You Enter an IT Contract, Plan Your Exit Strategy

Without a prepared strategy in place, your exit from the failed relationship may be more akin to jumping out of the window of a burning building, rather than a calm exit using the stairs. Both get you out of immediate danger, but one is much more likely to end in a painful landing.
Cyber Security Check List
Action Item Checklist Function Summary Description User Name and Password Protection Strictly enforce robust password security as per NIST Standards that include Upper and lower case letters, numbers and symbols Minimum of 8 characters, avoiding common words and dates Password not used for any other log in’s Changing passwords regularly – 3 months Using 2 […]
Quick little Post on Policies and Asset Registers
We are currently working with two large companies and it is interesting on my behalf on how little emphasis there has been on asset registers. An asset register of IT equipment is one of the foundations of your IT systems and security, if you dont know what you own, then you dont know what keys […]
Cost of a security breach
Much of the business discussion around cybersecurity relates to protection of key assets such as customer information and intellectual property, often after the news that another company has suffered a large data breach. While strengthening defenses against cyber attackers is important, companies also must be prepared to handle the reputational and financial hits that a […]
Insider Threats – Employee Data Theft
Employee Data Theft When most of us think about a cybercriminal, we usually think of a person from home, and probably not in your own country. But did you ever consider that a hacker could be inside your own organisation? While most business owners assume that attacks on their company, data, website or operations are […]
GUIDELINES FOR IT SECURITY IN SME’s
SME’s need advice and assistance in identifying and defining suitable actions to mitigrate the risk of Information Technology risks, data loss and the issues where the loss of an IT function brings to any organisation. Cyber crime poses a severe risk to all types of enterprises. Preventing these risks requires implementing initiatives based on both education and awareness.