Home / Insights
Insights
Find the piece that matches the pressure you are under.
Each of these ends in something you can actually do next, rather than in a newsletter signup. Below them is a glossary of the terms we can say something useful about. If none of it describes your situation, the four sentences on the home page are a faster way in.
White paper · CyberCon 2026 Think Tank
From prompt injection to policy
Building a practical AI control framework for RAG, copilots and agents: why six authoritative sources produce overlap rather than coverage, the AI-assisted mapping error that survived review, and why the right output was four amended cyber standards rather than an AI security policy.
Read the white paper →For the person who gets asked to prove it
The CISO Playbook
Ten cyber assurance use cases, and the argument for starting with one rather than a transformation programme. Audit evidence, third-party risk, control monitoring, policy, AI risk and risk acceptance.
Read the playbook →Published research · ISACA Journal, 2015
A practical approach to continuous controls monitoring
Which controls are worth monitoring continuously, how to turn an ISO 27002 or COBIT 5 control objective into an assertion a test can actually decide, and the seven test types and pass conditions that go with them. Peer reviewed and published, republished here with permission.
Read the article →Published research · ISACA Journal, 2022
The cyber risk quantification journey
Why qualitative risk scoring cannot prioritise remediation or win funding, and how COBIT, NIST CSF and FAIR combine into a quantified profile that ranks controls in dollars. Peer reviewed and published, republished here with permission.
Read the article →Why there are so few
Everything here has to name a pressure someone is actually under and end in a step they can take. Writing that takes longer than writing opinions, so the list grows slowly — which we prefer to a blog nobody finishes.
Where a piece was first published elsewhere, it says so. An article that survived an editorial review is worth more with that provenance attached than without it.
Glossary
The terms, and what we actually do about them.
Each entry gives the plain definition, then says where MyRISK fits — and where it doesn't. Several say we are not the answer, which is more useful than a definition that pretends otherwise.
Board risk reporting
Reporting risk to a board or executive committee in a form it can act on.
CIS Controls
A prioritised set of defensive actions published by the Center for Internet Security.
COBIT
ISACA's framework for the governance and management of enterprise IT.
Continuous control monitoring
Testing control operation on an ongoing basis rather than at a point in time.
Crosswalking
Mapping the controls of one framework onto another so a single control answers both.
Cyber resilience
The ability to keep operating through a cyber incident and recover afterwards.
Enterprise risk management (ERM)
Managing risk across a whole organisation rather than function by function.
Governance, risk and compliance (GRC)
The combined discipline of directing an organisation, managing what could go wrong, and evidencing obligations.
Information security risk management
Applying risk management to the confidentiality, integrity and availability of information.
Integrated risk management (IRM)
Connecting risk, control, assurance and performance information so they inform one another.
Internal audit risk management
The independent function that tests whether controls and governance work as described.
ISMS
An information security management system — the governing structure ISO 27001 requires.
ISO 27001
The international standard for an information security management system.
IT risk management
Identifying and treating risk arising from technology systems, data and their operation.
NIST Cybersecurity Framework
A voluntary US framework organising cyber security into functions: govern, identify, protect, detect, respond, recover.
Operational risk management
Managing the risk of loss from failed internal processes, people, systems or external events.
Policy management
Creating, approving, publishing, attesting and reviewing organisational policy.
Responsible AI
Governing AI systems so their use is accountable, explainable and reviewable.
Risk assessment
The process of identifying what could go wrong, how likely it is, and what it would cost.
Risk categories
The groupings an organisation uses to sort risk — strategic, operational, financial, compliance, technology and others.
Risk management framework
The structure that says how an organisation identifies, assesses, treats and reports risk.
Risk register
A list of identified risks with their owners, assessments and treatments.
SOC 2
A US attestation report on a service organisation's controls, issued by an auditor.
Third-party risk management (TPRM)
Assessing and governing the risk introduced by suppliers, vendors and partners.
Not sure which of these you are?
The home page asks it in four sentences, in your words rather than ours.