Learn the 8 fundamentals we recommend to establish an effective Enterprise Risk Management process from the ground up, which will set the stage for a successful GRC program rollout.
Learn the 8 fundamentals we recommend to establish an effective Enterprise Risk Management process from the ground up, which will set the stage for a successful GRC program rollout.
In this post, SimpleRisk's Founder and CEO walks us through the different approaches to assessing and managing third-party risks.
Learn how to use our Risk Assessment Extra to manage inbound assessments within SimpleRisk. Create a repeatable process without purchasing a separate tool.
Learn how to minimize the level of effort required to track a risk’s progress over time and how to measure the effectiveness of your risk mitigation.
Today I attended a CISO roundtable where a number of the attendees talked about their GRC platforms that have taken over a year to "connect all the wires" and they're still in the process of implementing. I know why their GRCs are failing them and there is a better way.
Let’s go back to the basics and break down what enterprise risk management is and how you can use it to mitigate the risks that threaten your organization.
SimpleRisk partners with various MSSP providers to give customers a one-stop "GRC-as-a-Service" offering. Learn more about how this works and whether the SimpleRisk GRCaaS platform may be a good fit for your organization.
What is the right way to do risk management? We hear this question fairly frequently on calls with prospects and my answer is always the same. There is no "right way" or "wrong way" to do risk management. There's only your way...
Over the years, we've received a number of inquiries about the OWASP Risk Rating Methdology with some contention around how we have integrated it into SimpleRisk. Some have questioned how SimpleRisk reaches its final risk score while others have pointed to differences in the Skill Level values. Let's delve into this...
If the "textbook" definition of risk scoring is Risk = Likelihood x Impact, then a Severe (5) impact and an Almost Certain (5) likelihood should have a score of 25, right? The answer isn't quite so simple...
Learn how to use SimpleRisk's Import-Export and Risk Assessment Extras in order to efficiently use the NIST Cybersecurity Framework's controls to assess your organization's risks and perform a control gap analysis.
At the end of June 2020, a civil rights coalition, which includes the Anti-Defamation League (ADL) and the NAACP, launched the #StopHateforProfit campaign. This campaign calls upon major corporations to put a pause on Facebook advertisements, citing the company's...
Today I had a really interesting conversation with a guy from Japan via LinkedIn. It started with him trying to sell me...
When I first released SimpleRisk as a free tool back in March of 2013, I decided to license it under the open source ...
As the Information Security Program Owner at National Instruments, I spent years contemplating the answer to a ...
Back in 2013, when I first started working on SimpleRisk in my spare time on nights and weekends, I started using a ...
As the Information Security Program Owner at National Instruments, a $1.4B global enterprise, I've spent the past ...
Last week I was invited to participate in Kyle Burt's live podcast featuring leaders in tech and business called ...
Currently, SimpleRisk supports six different risk scoring methods. We have Classic Risk, which is the likelihood ...
This is just a short (1 minute) animated video explaining some of the capabilities around performing internal and ...
Unless you've been hiding under a rock for the past three weeks, you're probably familiar with CVE-2019-0708, also ...
As a CISO for a large enterprise, many times my first engagement with members of our internal teams was when ...
When I first released SimpleRisk as a free and open source risk management tool at the BSides Austin conference...
On March 29, 2019, Alex Polimeni and I presented at the BSides Austin conference on some of the work we've ...
Recently, a friend sent me a blog post by John A. Wheeler of Gartner entitled "What Ever Happened to GRC?". In ...
While the distinctions between vulnerabilities versus risks has been widely documented in various forums, we ...
Before starting SimpleRisk, I sat in the CISO chair, on the other side of the negotiating table. I learned the tricks ...
Has the number of security issues you deal with on a routine basis ever made you feel a bit like Atlas carrying the ...
A couple of weeks ago I participated in a CISO Summit with a focus on the topics of Security Visibility and Incident ...
Any CISSP will tell you that the way to calculate risk is by taking the likelihood and multiplying it by the impact...