Risk Management

A computer monitor displaying a fine-grained time-series line chart on a dark background.
Disaster Recovery: RTO, RPO and Recovery Planning
Almost every organization has a recovery plan. Rather fewer can state, per system, how long recovery would take and how much data would be lost, and fewer still have measured either. Those two numbers are the whole desig...
A dirt path dividing into two separate tracks at the edge of a group of trees.
Disaster Recovery and Business Continuity
Disaster recovery restores technology. Business continuity keeps the organization functioning while the technology is unavailable. Organizations often build the first, call it the second, and discover the gap during an i...
A row of weathered brass and steel padlocks fastened side by side along a metal rail.
Cloud Security and Shared Responsibility
Cloud security failures are rarely failures of the platform. They are usually a misunderstanding about where the provider's obligation ends, acted on for long enough that nobody rechecks it. This page sets out the model,...
Team members review a large process map covered in colorful sticky notes on a conference table beside a laptop.
The Managed Cybersecurity Lifecycle
Almost every organization we assess has already bought good security controls. Rather fewer are still operating them as designed a year later. The gap between those two sentences is what managed cybersecurity exists to c...
A row of weathered brass and steel padlocks fastened side by side along a metal rail.
What Are Managed Cybersecurity Services?
Managed cybersecurity services are the continuing operation of an organization's security controls by somebody whose job that is. Not the purchase of the controls, and not a one off review of them. The operation: the pat...
Two people seated at a desk reviewing printed statements and documents together.
Cybersecurity Risk Assessments
A cybersecurity risk assessment answers one question: what could go wrong here that would matter, and which of those things is worth spending money on first. Everything else in the method exists to make that answer defen...
A code editor displaying a project file tree alongside source code and dependency files.
Vulnerability Management
Vulnerability management is the discipline of finding weaknesses in your environment and closing them before somebody else uses them. Almost every organization does the finding. Rather fewer do the closing at a rate that...
A web performance dashboard showing summary metric tiles above coloured trend charts.
Security Monitoring and Incident Detection
Security monitoring is the practice of collecting enough evidence about what is happening in an environment to notice when something is wrong, and having somebody act on it. Both halves are load bearing. Organizations th...
Three colleagues gathered around a laptop, one pointing at the screen while explaining.
Incident Response and Cybersecurity Recovery
Incident response is the set of activities that begin when something has gone wrong and end when the organization is back to a state it understands. It is the part of a security program that is dormant until it is the on...
Two professionals review a multi-lane organizational workflow diagram on a dual-screen laptop; with a customer journey map on the lower display.
The CIS Critical Security Controls
Most security frameworks tell you what good looks like. Very few tell you what to do on Monday. The CIS Critical Security Controls are an attempt at the second problem, and that is the reason to be interested in them. Th...