Questions I’ve been asked a lot are: Is it worth quantifying cyber risks and using well-established models to simulate the effects of those risks? Or is quantifying cyber risk a waste of time, detached from reality?
3 Lessons We Learned from Our Introduction of FAIR™ at Swisscom
[fa icon="calendar'] Dec 4, 2019 1:05:04 PM / by Laura Voicu
Save The Date and Secure Your Budget for the 2020 FAIR Conference!
[fa icon="calendar'] Dec 4, 2019 7:33:39 AM / by Luke Bader posted in FAIR Conference 2020
Mark your calendars today! The FAIR Institute’s annual FAIR Conference (FAIRCON20) will take place this year on October 6-7, 2020 in Washington, D.C., at the historic Washington Marriott Wardman Park.
Listen to the Webinar: 3 Steps to FAIR™ Program Success at Highmark Health
[fa icon="calendar'] Dec 3, 2019 11:03:03 AM / by Luke Bader posted in FAIR, Risk Management
FAIR™ program manager Jason Martin generously shared the learnings from two years of FAIR implementation at Highmark Health, the major hospital and health plan administrator
Register for the 2019 Risk Management Maturity Benchmark Survey Results Webinar
[fa icon="calendar'] Nov 26, 2019 3:50:34 PM / by Luke Bader
Join Jack Freund, PhD. and co-author of the FAIR Book “Measuring and Managing Information Risk: A FAIR Approach” and our expert panel for this engaging webinar on Thursday, December 19 at 11 AM EST.
FAIRCON19 Video: Use Case Panorama – FAIR™ Practitioner Success Stories from BB&T, Swisscom, Fidelity Investments and Daimler Mobility
[fa icon="calendar'] Nov 22, 2019 10:11:30 AM / by Jeff B. Copeland posted in FAIR Conference 2019
For ground-level, hands-on, advice on starting a FAIR™ quantitative risk management program, the Use Case Panorama session at the recent 2019 FAIR Conference was the place to be.
(Video) Meet a Member: Brandon Myers, Risk Management and Corporate Security Architect, Mastercard
[fa icon="calendar'] Nov 21, 2019 11:19:35 AM / by Luke Bader posted in Meet a Member, FAIR Conference 2019
Brandon Myers works IT security for Mastercard but also mission security for the Air Force as a member of the Reserve. We caught up with him at the 2019 FAIR Conference where he had just completed FAIR training (he rated it “amazing”). Brandon had an interesting psychological take on the value of FAIR:
NIST Maps FAIR to the CSF - Big Step Forward in Acceptance of Cyber Risk Quantification
[fa icon="calendar'] Nov 19, 2019 2:36:00 PM / by Jeff B. Copeland posted in FAIR, Risk Management
It's official: NIST has formally published FAIR as an Informative Reference to the NIST CSF, the most widely used cybersecurity framework in the U.S, a major milestone in the history of FAIR. This means that there is mapping between FAIR and the NIST CSF standard in the sections covering risk analysis and risk management.
FAIRCON19 Video: Tips on Building a Cybersecurity Program with a Risk Management Framework & FAIR
[fa icon="calendar'] Nov 14, 2019 10:43:57 AM / by Jeff B. Copeland posted in Risk Management, FAIR Conference 2019
Don’t think of cybersecurity standards and frameworks as checklists – think of them as recipes with plenty of room for “season to taste.” That was the message coming out of a panel discussion at the 2019 FAIR Conference on the topic “Building a Cybersecurity Program with a Risk Management Framework & FAIR,”
FAIRCON19 Video: CISOs from Fannie Mae, Highmark Health, Department of Energy, and Premise Health Talk FAIR Cyber Risk Quantification
[fa icon="calendar'] Nov 6, 2019 12:02:00 PM / by Jeff B. Copeland posted in FAIR Conference 2019
Led by FAIR model creator Jack Jones, the panel discussion “CISO Panel: Defining the Goals of an Effective Risk Management Program” at the recent 2019 FAIR Conference, covered a lot of ground. Four chief information security officers - speaking from hands-on experience - discussed everything from building a FAIR program, to briefing the board
(Video) Meet a Member: Daniel Davis, Security Analyst at Lyft
[fa icon="calendar'] Nov 6, 2019 10:08:57 AM / by Luke Bader posted in Meet a Member, FAIR Conference 2019
Daniel Davis, Security Analyst at Lyft in San Francisco, came to FAIR from an unusual, non-IT perspective – safety engineering. He first came to Lyft to work on safety for autonomous cars. “The way that FAIR defines risk as threat, asset and impact…is very similar to the way that safety engineering has treated hazards for years,” he says.