• About
  • Subscribe
  • Contact
Monday, May 12, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Resources Blogs

PodChats for FutureCISO: Risk quantification strategies in 2023

allantan by allantan
April 28, 2023

PodChats for FutureCISO: Risk quantification strategies in 2023

Share on FacebookShare on Twitter

We are all familiar with the concepts of risks and uncertainty. Risk is a quantifiable element of doing business, whereas uncertainty is something we'd like to be prepared for but is often challenging to quantify.

Events of the past three years, including those occurring now, have exposed us to both and while we can't predict uncertainty, we can at least work towards mitigating the risks that may result from these uncertainties.

RQ vs RA

Risk quantification (RQ) is a process of evaluating the risks that have been identified and developing the data that will be needed for making decisions as to what should be done about them. The "Guide to Project Management Body of Knowledge" describes risk quantification as evaluating risks and risk interactions to assess the range of possible outcomes.

Jonathan Jackson, director of sales engineering APJ at BlackBerry, defines risk assessment (RA) as the process of identifying and analysing potential risks to an organisation or a system. It involves evaluating the likelihood and the impact of different threats and vulnerabilities.

In describing the linkages between the two, he explains that risk quantification forms part of risk assessment. "That involves assigning a numerical value to the likelihood and the impact of that risk happening. It helps to prioritise risks and determine the appropriate level of resources that you need to allocate to mitigate against those risks," he continues.

Asked how an organisation goes about assessing whether they need risk quantification as part of their assessment or risk management strategy, Jackson says an organisation needs to consider this quantification as part of the overall assessment and management strategy if they want to gain a deeper understanding of the risks and make some good business, informed decisions about how to manage those risks.

Related:  Rethinking cybersecurity amid digital transformation

"Some of the triggers that I see that may prompt an organisation to look at risk quantification could be things like significant changes to the business environment or operations they are running in," he quips.

Are all risk quantification solutions equal, or are the approaches similar?

Jackson is adamant that not all quantification solutions are equal. "The effectiveness and the suitability of a particular risk quantification solution really will depend on several various factors. It could take into consideration the organisation size, what industry they are involved in, the complexity of that organisation," he elaborates.

Jonathan Jackson

"It is essential to carefully evaluate and select a quantification approach that is appropriate for your organisation’s specific needs, and your specific circumstances. There are a lot of resources available for organisations to evaluate different solutions out there. Five things that I would consider would be scope, accuracy, usability, flexibility, and cost."

Jonathan Jackson

Risk assessment is a team sport

Jackson believes that any risk assessment undertaking should involve multiple stakeholders in the organisation. He points out that governance, risks and compliance (GRC) typically is led by the chief risk officer.

"A CFO typically takes a strong look at risk, but key stakeholders, subject matter experts from various departments are really important within an organisation. It's not just specific to IT, or to the security and the legal teams," he adds.

He concedes the importance of strong leadership direction from executives. "Whether it's education, training, risk awareness, cyber awareness, or phishing campaigns, we are all quite good at being able to spot these. Ongoing training and management as part of the executive team are important to foster a good culture of risk aversion within an organisation," he continues.

Related:  Security priorities for 2024 centre around resilience and performance

Click on the PodChat player and hear Jackson elaborate on his recommendations for risk quantification strategies in 2023.

  1. What is risk quantification? Is it the same as risk assessment? If not what’s the difference?
  2. What conditions require risk quantification? Is it a one-time requirement? Perpetual? What are the triggers for needing to do risk quantification?
  3. How does an organisation go about assessing whether they need risk quantification as part of their assessment/management strategy?
  4. Are all risk quantification solutions/approaches equal?
  5. What questions should they be asking when evaluating a risk assessment solution?
  6. Who should be involved in making this evaluation?
    1. What is your advice for executives charged with risk assessment?
  7. How do you get board buy-in?
Tags: BlackBerrychief risk officerCISOPodchatsrisk quantification
allantan

allantan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • From endpoint defence to supply chain security
  • Legacy systems may be sabotaging bank's cyber resilience posture
  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl