I have found that asking people to estimate the probability of a risk occurring as a percentage leads to them performing a pseudo-mathematical calculation in their head (System 2 thinking I suspect) which often ends up with a fairly high probability being estimated, especially when compared to base rates. However,…
Category: Risk
Homebrew Monte Carlo Simulations for Security Risk Analysis
I cannot say enough good things about Doug Hubbard’s work. I’ve been obsessed with How to Measure Anything and The Failure of Risk Management so when he published How to Measure Anything in Cybersecurity Risk with Richard Seierson I could not have been happier. The whole book is worth reading…
Writing a good risk statement
I often review documents describing risks that fail to either make an impression as to the seriousness of the risks or fail to explain the cause and impact of those risks, both results leading to a less well informed risk decision by a non-specialist executive. It is vital when stating…
Portfolios of Risk
I’ve been thinking, and worrying, about portfolio risk and especially cross-portfolio risk in federated environments. In federated environments or extended enterprises it is not unheard of for strong programme management to have a good clear view of the risks in their scope of activity and in some more effective enterprises…