Home / Insights
Insights
Find the piece that matches the pressure you are under.
Each of these ends in something you can actually do next, rather than in a newsletter signup. If none of them describes your situation, the four sentences on the home page are a faster way in.
For the person who gets asked to prove it
The CISO Playbook
Ten cyber assurance use cases, and the argument for starting with one rather than a transformation programme. Audit evidence, third-party risk, control monitoring, policy, AI risk and risk acceptance.
Read the playbook →For an investment or acceptance decision
Cyber risk quantification
Scenarios, exposure and the assumptions behind them, framed so the decision they support can still be explained a year later.
How the work runs →Published research · ISACA Journal, 2015
A practical approach to continuous controls monitoring
Which controls are worth monitoring continuously, how to turn an ISO 27002 or COBIT 5 control objective into an assertion a test can actually decide, and the seven test types and pass conditions that go with them. Peer reviewed and published, republished here with permission.
Read the article →Published research · ISACA Journal, 2022
The cyber risk quantification journey
Why qualitative risk scoring cannot prioritise remediation or win funding, and how COBIT, NIST CSF and FAIR combine into a quantified profile that ranks controls in dollars. Peer reviewed and published, republished here with permission.
Read the article →Why there are so few
Everything here has to name a pressure someone is actually under and end in a step they can take. Writing that takes longer than writing opinions, so the list grows slowly — which we prefer to a blog nobody finishes.
Where a piece was first published elsewhere, it says so. An article that survived an editorial review is worth more with that provenance attached than without it.
Not sure which of these you are?
The home page asks it in four sentences, in your words rather than ours.