FAIR Institute Blog

Jack Jones

Jack Jones

Recent Posts

What Is Cyber Risk Quantification (CRQ) and How Does It Help Risk Management Decisions?

[fa icon="calendar'] Mar 7, 2023 11:12:41 AM / by Jack Jones posted in Guides & Tips

[fa icon="comment"] 0 Comments

As a relatively new discipline within cybersecurity, cyber risk quantification isn’t well-understood by many within the profession. Amongst other things, there is confusion about what CRQ is (and isn’t), and why it matters.

Read More [fa icon="long-arrow-right"]

Jack Jones on the Wrong Lessons from the Conviction of Former Uber CSO Joe Sullivan

[fa icon="calendar'] Dec 7, 2022 11:21:28 AM / by Jack Jones posted in Jack Jones

[fa icon="comment"] 0 Comments

The Wall Street Journal recently published an article, “Whistleblower Reports of Lax Cybersecurity Expected to Rise,” reacting to the conviction of Joe Sullivan for his handling of two data breaches as CSO at Uber

Read More [fa icon="long-arrow-right"]

Why Cyber Risk Quantification (CRQ) Demos Aren't Enough

[fa icon="calendar'] Aug 2, 2022 2:44:24 PM / by Jack Jones posted in Jack Jones

[fa icon="comment"] 0 Comments

Imagine that you’re looking for an encryption solution.  There are many providers on the market, all of whom use one of the well-vetted public encryption standards.  But let’s imagine there’s a new player in the market — one that claims to have a vastly improved, but proprietary, solution. 

Read More [fa icon="long-arrow-right"]

Attacking FAIR - A Reply by Jack Jones

[fa icon="calendar'] Jul 27, 2022 5:42:49 PM / by Jack Jones posted in FAIR, Jack Jones

[fa icon="comment"] 1 Comment

It was bound to happen.  For years, Factor Analysis of Information Risk (FAIR™) was, for all intents and purposes, the only Cyber Risk Quantification (CRQ) model out there.

Read More [fa icon="long-arrow-right"]

Jack Jones Rebuts ‘FAIR Fatigue’, an Article Filled with Misrepresentations of Factor Analysis of Information Risk (FAIR), the Standard for Risk Quantification

[fa icon="calendar'] Jul 11, 2022 3:50:04 PM / by Jack Jones posted in FAIR

[fa icon="comment"] 1 Comment

It’s not often that I’m surprised by someone’s actions on the Internet, but I’ll admit to being surprised today.

Read More [fa icon="long-arrow-right"]

Jack Jones: Automating Cyber Risk Quantification (Part 5 of 5)

[fa icon="calendar'] May 10, 2022 7:45:00 AM / by Jack Jones posted in Jack Jones, Jack Jones on Automating CRQ

[fa icon="comment"] 0 Comments

In the previous post, I provided examples of some controls-related data that can’t be used to support automated cyber risk quantification (CRQ).  But the news isn’t all bad.  There are some data that can be used to support CRQ.

Read More [fa icon="long-arrow-right"]

Jack Jones: Automating Cyber Risk Quantification (Part 4 of 5)

[fa icon="calendar'] May 3, 2022 1:50:19 PM / by Jack Jones posted in Jack Jones, Jack Jones on Automating CRQ

[fa icon="comment"] 0 Comments

I covered a lot of ground in the previous posts, and rather than summarize them here I’ll assume you’ve read those posts already.  So, let’s dive into the last analytic dimension…

Read More [fa icon="long-arrow-right"]

Jack Jones: Automating Cyber Risk Quantification (Part 3 of 5)

[fa icon="calendar'] Apr 25, 2022 11:45:38 AM / by Jack Jones posted in Jack Jones, Jack Jones on Automating CRQ

[fa icon="comment"] 0 Comments

In the previous two posts, I briefly discussed that:

  1. The CRQ market is rapidly growing, and there’s a strong desire to automate CRQ analysis...
Read More [fa icon="long-arrow-right"]

Jack Jones: Automating Cyber Risk Quantification (Part 2 of 5)

[fa icon="calendar'] Apr 18, 2022 12:05:26 PM / by Jack Jones posted in Jack Jones, Jack Jones on Automating CRQ

[fa icon="comment"] 2 Comments

In Part 1 of this series, I discussed that the market for cyber risk quantification (particularly automated CRQ) is growing rapidly, but that automation, done poorly, can to more harm than good.  In this post, I’ll begin to discuss what it takes to automate CRQ responsibly.

Read More [fa icon="long-arrow-right"]

Jack Jones: Automating Cyber Risk Quantification (Part 1 of 5)

[fa icon="calendar'] Apr 12, 2022 7:45:00 AM / by Jack Jones posted in Jack Jones, Jack Jones on Automating CRQ

[fa icon="comment"] 0 Comments

Until recently, it’s mostly been organizations with visionary and early adopter tendencies who have embraced cyber risk quantification (CRQ).  They understood the value and were willing to deal with the challenges. 

Read More [fa icon="long-arrow-right"]
LEARN MORE
Content not found

Subscribe to Email Updates

417NjDVYgtL._SX404_BO1204203200_.jpg
Learn How FAIR Can Help You
Make Better Business Decisions

Recent Posts