Blog tag

Cybersecurity

Articles from the SimpleRisk blog tagged Cybersecurity: governance, risk management, and compliance insights.

Risk puzzle pieces containing IT Risk, Supply Chain Risk and Operational Risk

Why 2025 Needs One Complete Risk Assessment

Your IT, supply chain, and operations teams may all see the same risks—but they don’t measure them the same way. That gap could be the biggest security vulnerability in your organization today.

Probability x Impact = Risk Formula

How to Conduct a Proper Cybersecurity Risk Analysis

Risk analysis and risk evaluation aren’t interchangeable terms. They’re distinct stages within the broader process of risk assessment. This blog breaks down the differences, why they matter in cybersecurity, and how to properly analyze risks using both qualitative and quantitative methods.

A high-tech digital dashboard interface for the NIST CSF

SimpleRisk: Your Foundation for NIST CSF Compliance

Struggling to align with the NIST Cybersecurity Framework? Discover how SimpleRisk streamlines governance, risk, and compliance to help you document, track, and manage your cybersecurity controls with ease.

Streamlining an information security program using the templates created by SimpleRisk

Free Security Policy Templates from SimpleRisk

Building an information security program from scratch can be overwhelming, but SimpleRisk is here to help. Discover how our free, ready-to-use templates can simplify the process and get your security program up and running quickly.

From Zero to ISO 27001 in 18 Months

Certified in 18 Months: Our ISO 27001 Journey

On September 26, 2024, SimpleRisk proudly earned its ISO 27001 certification after a focused 18-month effort to refine security practices and address control requirements. Despite personal hurdles, their journey highlights how dedication and the right tools make ambitious compliance goals achievable.

Josh Sokol and Michael Rasmussen presenting on How to Model Security Maturity in Your Organization

Webinar Recap: Modeling Your Security Maturity

Check out this recap of the webinar, "How to Model Security Maturity in Your Organization," co-hosted by SimpleRisk and GRC 20/20. This webinar helped equip participants with a clear roadmap on how to establish a security maturity baseline within their own organizations, create a desired state of maturity, and identify where gaps exist in order to achieve their objectives.

Stock market ticker

New SEC Cybersecurity Regulation – What to Know

The Security and Exchange Commission (SEC) released its final rule on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, effective mid-December 2023. Check out this blog to learn what this ruling entails, how this new regulation may impact your organization, and what your organization needs to do ensure compliance.

Person climbing the stairs to get their information security program off the ground

Getting Your Information Security Program Off the Ground

Struggling with where to begin with your Information Security Program?  Learn how taking a risk-centric approach can help accomplish your goals.

CIS Critical Security Controls

Using the CIS Critical Security Controls with SimpleRisk

We are frequently asked about using the CIS Critical Security Controls in SimpleRisk.  In this blog post you will learn about the different ways you can use their controls with our platform.

A person manually responding to a questionnaire instead of using risk assessments

Responding to Inbound Risk Assessments with SimpleRisk

Learn how to use our Risk Assessment Extra to manage inbound assessments within SimpleRisk. Create a repeatable process without purchasing a separate tool.

Keeping things simple b y using the Secure Controls Framework in SimpleRisk

Using the ISO 27001 Control Framework with SimpleRisk

ISO 27001 has become the most requested framework to use within SimpleRisk.  In this blog post you will learn about the different ways you can use their controls with our platform.

People celebrating together about the ease of using a Common Control Framework

The Benefits of a Common Control Framework for GRC

Struggling with managing compliance across multiple different control frameworks?  Learn how a common control framework can help you to simplify your compliance, saving you time and money.

Understanding the basic principles of governance

Governance 101: Back to Basics

Let’s go back to the basics and talk about what governance is and how you can use it to ensure that the information that reaches your executive team and other key stakeholders is complete, accurate and timely.

Fist bump between SimpleRisk and a partner for GRC as a Service

What is GRC-as-a-Service?

SimpleRisk partners with various MSSP providers to give customers a one-stop "GRC-as-a-Service" offering.  Learn more about how this works and whether the SimpleRisk GRCaaS platform may be a good fit for your organization.

OWASP Risk Rating Methodology

The OWASP Risk Rating Methodology and SimpleRisk

Risk scoring methodologies vary widely, but understanding how to prioritize risks is key to managing them effectively. In this post, we take a deep dive into the OWASP Risk Rating Methodology, clarifying how it’s calculated in SimpleRisk and addressing common misconceptions.

Using the NIST Cybersecurity Framework in SimpleRisk

Simplifying the NIST Cybersecurity Framework with SimpleRisk

Learn how to use SimpleRisk's Import-Export and Risk Assessment Extras in order to efficiently use the NIST Cybersecurity Framework's controls to assess your organization's risks and perform a control gap analysis.

Risk Management for Dummies

Risk Management for Dummies

Explaining risk management to someone new to the concept can be a challenge, but it’s a skill we use daily without realizing it. Learn how a conversation about home security turned into a practical analogy for understanding risks and how SimpleRisk helps prioritize and address them.

The Security of Open Source vs Closed Source Software

The Security of Open Source vs Closed Source Software

When it comes to software security, is open source or closed source the safer choice? Dive into the pros and cons of transparency, community collaboration, and bug detection to see why SimpleRisk embraces open source for its core while prioritizing security at every step.

SimpleRisk's Plan for COVID-19

SimpleRisk's Plan for COVID-19

During these challenging times, SimpleRisk remains steadfast in our commitment to supporting you, with business continuity plans built on redundancy and resilience. Our remote operations, secure AWS hosting, and unwavering customer support ensure uninterrupted service so you can focus on what matters most.

The Dialed In Podcast with Kyle Burt

Josh Sokol Featured on the 'Dialed In' Podcast

I joined Kyle Burt's "Dialed In" podcast to discuss cybersecurity topics like Bluekeep, career paths, and improving personal security. Missed it live? Watch the replay for an hour of insights and tips!

Quantitative Risk Assessment in SimpleRisk

There is Nothing Simple About FAIR

Is precision worth the time? In this blog, we explore how SimpleRisk balances simplicity and effectiveness in risk assessment, offering a quantitative approach without the complexity of methodologies like FAIR, so you can focus more on managing risks than analyzing them.

Risk Assessments with SimpleRisk

How to Perform Risk Assessments (with SimpleRisk)

Curious about how SimpleRisk simplifies internal and third-party risk assessments? Check out this quick 1-minute animated video showcasing our key capabilities in action!

Vulnerabilities vs Risks

Should Vulnerabilities and Risks be Managed in the Same Place?

Should vulnerabilities be managed as risks? While both are essential to cybersecurity, understanding their differences and how they complement each other is key to deciding whether to track them together in a single risk management system.