Home / Insights

Insights

Find the piece that matches the pressure you are under.

Each of these ends in something you can actually do next, rather than in a newsletter signup. Below them is a glossary of the terms we can say something useful about. If none of it describes your situation, the four sentences on the home page are a faster way in.

News · 9 September 2026

MyRISK named a Cool Vendor™ in the 2026 Gartner® report

Named a Cool Vendor in Gartner Coolest Vendor Innovations for Assurance: GRC and TPRM. What MyRISK does, and where each of the four routes starts.

Read the announcement →

White paper · CyberCon 2026 Think Tank

From prompt injection to policy

Building a practical AI control framework for RAG, copilots and agents: why six authoritative sources produce overlap rather than coverage, the AI-assisted mapping error that survived review, and why the right output was four amended cyber standards rather than an AI security policy.

Read the white paper →

For the person who gets asked to prove it

The CISO Playbook

Ten cyber assurance use cases, and the argument for starting with one rather than a transformation programme. Audit evidence, third-party risk, control monitoring, policy, AI risk and risk acceptance.

Read the playbook →

Published research · ISACA Journal, 2015

A practical approach to continuous controls monitoring

Which controls are worth monitoring continuously, how to turn an ISO 27002 or COBIT 5 control objective into an assertion a test can actually decide, and the seven test types and pass conditions that go with them. Peer reviewed and published, republished here with permission.

Read the article →

Published research · ISACA Journal, 2022

The cyber risk quantification journey

Why qualitative risk scoring cannot prioritise remediation or win funding, and how COBIT, NIST CSF and FAIR combine into a quantified profile that ranks controls in dollars. Peer reviewed and published, republished here with permission.

Read the article →

Why there are so few

Everything here has to name a pressure someone is actually under and end in a step they can take. Writing that takes longer than writing opinions, so the list grows slowly — which we prefer to a blog nobody finishes.

Where a piece was first published elsewhere, it says so. An article that survived an editorial review is worth more with that provenance attached than without it.

Glossary

The terms, and what we actually do about them.

Each entry gives the plain definition, then says where MyRISK fits — and where it doesn't. Several say we are not the answer, which is more useful than a definition that pretends otherwise.

Board risk reporting

Reporting risk to a board or executive committee in a form it can act on.

CIS Controls

A prioritised set of defensive actions published by the Center for Internet Security.

COBIT

ISACA's framework for the governance and management of enterprise IT.

Continuous control monitoring

Testing control operation on an ongoing basis rather than at a point in time.

Crosswalking

Mapping the controls of one framework onto another so a single control answers both.

Cyber resilience

The ability to keep operating through a cyber incident and recover afterwards.

Enterprise risk management (ERM)

Managing risk across a whole organisation rather than function by function.

Governance, risk and compliance (GRC)

The combined discipline of directing an organisation, managing what could go wrong, and evidencing obligations.

Information security risk management

Applying risk management to the confidentiality, integrity and availability of information.

Integrated risk management (IRM)

Connecting risk, control, assurance and performance information so they inform one another.

Internal audit risk management

The independent function that tests whether controls and governance work as described.

ISMS

An information security management system — the governing structure ISO 27001 requires.

ISO 27001

The international standard for an information security management system.

IT risk management

Identifying and treating risk arising from technology systems, data and their operation.

NIST Cybersecurity Framework

A voluntary US framework organising cyber security into functions: govern, identify, protect, detect, respond, recover.

Operational risk management

Managing the risk of loss from failed internal processes, people, systems or external events.

Policy management

Creating, approving, publishing, attesting and reviewing organisational policy.

Responsible AI

Governing AI systems so their use is accountable, explainable and reviewable.

Risk assessment

The process of identifying what could go wrong, how likely it is, and what it would cost.

Risk categories

The groupings an organisation uses to sort risk — strategic, operational, financial, compliance, technology and others.

Risk management framework

The structure that says how an organisation identifies, assesses, treats and reports risk.

Risk register

A list of identified risks with their owners, assessments and treatments.

SOC 2

A US attestation report on a service organisation's controls, issued by an auditor.

Third-party risk management (TPRM)

Assessing and governing the risk introduced by suppliers, vendors and partners.

Not sure which of these you are?

The home page asks it in four sentences, in your words rather than ours.