AI kan styrke it-risikovurdering gennem automatisering og præcision, men kræver god datakvalitet og ansvarlig brug. Den rummer store muligheder – og vigtige risici. Derfor bør AI ses som et supplement til menneskelig dømmekraft, ikke en erstatning.
Risiko
The typical leap into the darkness ends with a broken nose
A crisis plan is useless without practice. Real resilience comes from training, adapting, and learning from mistakes. As Mike Tyson said, “Everyone has a plan until they get punched in the mouth.” Train for the punch—so you can keep moving forward.
Kunsten at definere risikotolerance
Det er ikke en triviel øvelse at definere en risikotolerance. Skal vi ikke lige aftale at vi ser bort fra et 5×5 heatmap med røde, gule og grønne risici. Det er selvfølgeligt superenkelt at der ikke må være nogen gule og røde. Men disse kvalitative modeller introducerer for meget usikkerhed og bias.
Move Beyond Guesswork: Elevate Your Cyber Risk Management with Data-Driven Quantification
CRQ replaces guesswork with data-driven insights, prioritising risks by financial impact. Early adopters gain the edge. Waiting for perfect data means falling behind, while those who act can strengthen resilience and drive better outcomes.
WEBINAR: QUANTITATIVE IT-RISK ASSESSMENTS – TOOLS AND TECHNIQUES
Thursday, December 7, 2023 was an important day for ACI.We held our December seminar on IT Risk quantification.We were proud that more than 180 people had signed up for the seminar from more than 100 organizations across Europe.We shared experiences from 5 years of...
Part Two: ‘We Should Never Have Said That’ and How to Avoid It Being Used Against You Before It’s Too Late
Earlier this year, the first part of this article was published. It’s a good place to start to learn why you want to understand your company’s attack surface. Websites and online databases tend to over-share – you...
Webinar: An introduction to quantitative methods for cyber risk management
Almost daily, we hear about how cyber threats and IT risks increase globally across industries. Sadly, the methods and tools used for IT risk management today do not deliver the consistent decision support that organizations need. On March 23rd 2023, we conducted a...
ISO 27005 Is Wrong About Quantitative Risk
The International Standards Organization recently published an updated version of their guidance for information security risk management, but they have missed the mark entirely on quantitative methods. The ISO/IEC-27005 is one of the key standards published under the...
Identify your information assets in 5 steps
An important step in any IT risk management process is to clearly define the information assets in scope. But what is an information asset really? How can you best describe your important information assets? And why is it so important to spend time on establishing a...
Nu var det lige så hyggeligt
Verden er i forandring. De seneste år har mindet os om, at verden er farlig og foranderlig. Det er blevet den nye normal. Krig i Europa, klimakatastrofer, problemer med makroøkonomien og cyberangreb for blot at nævne nogle af de udfordringer, samfundet står over for....