Episode 4

full
Published on:

27th Sep 2020

#4 Business Risk & Risk Ownership (with Bill Schultz)

Does the CISO own all cyber related risks to the business? It depends, but in many businesses that is the default position. Who is responsible for risk identification and analysis; identification, rating and selection of treatment options; and for managing residual risks within the defined risk appetite? Is it the security function, the business service owner, the application owner, the data owner, or is it potentially none of these? Should we not logically separate risk management responsibility and risk ownership? What about systemic risks?

In this episode regular hosts Martin and Maurice are joined by Bill Schultz from Vanderbilt University Medical Center to discuss cyber risk management. We’ll discuss our ideas, VUMC’s architected approaches, and the realities of cyber risk management in a business where lives are at risk and privacy is paramount.

Show artwork for Attributive Security

About the Podcast

Attributive Security
The podcast anchored in the expression “security is a property of something else”.
There is often a lot happening in the world of cyber security: new threats, new exploits and new products. Don’t get us wrong, there is a lot of cool technology, and we appreciate that. But, at least on the surface, a lot of the defensive advances look to be very bottom up and technology focused. It is easy to lose sight of the context, what matters to us that we want to protect, and yes even enable.

Join us as we get together for unscripted conversations about a broad range of topics and relate them to cyber security. We’ll draw on various disciplines, and our own experiences, as we discuss ideas and practical approaches to tailored information security. We won’t be afraid to challenge one size fits all and best practice norms, or the misapprehension that bespoke security frameworks are infeasible for all but the biggest of enterprises. Be prepared to reimagine what an effective cyber security program can look like when it is engaged with and aligned to the business.

About your hosts

Martin Hopkins

Profile picture for Martin Hopkins
Martin is a cyber security leader and an experienced consultant most recently specialising in technical and business security advisory, and enterprise and technical security architecture. A regular speaker on cyber security topics, he is a strong advocate of business driven security, balanced risk management, and enterprise security architecture.

With over 25 years' experience in technology, primarily in security related fields, Martin has extensive experience in financial services having been engaged by leading global institutions.

Prior to his current focus on security architecture and risk he was a security testing consultant working on everything from mainframe systems to IoT devices and has a background in system software development for information security and virtualisation.

Maurice Smit

Profile picture for Maurice Smit
A Principal Security Consultant and SABSA Instructor, with over 20 years of experience in IT Security operations, management, governance and architecture, in a variety of industries including finance, healthcare, OT and pharmaceuticals. Maurice delivers accredited SABSA training in Europe, India, Africa and the Middle East

He is a founding member of the SABSA Institute Board of Trustees and was one of the first people in Europe to achieve SABSA Master Certification.

Maurice has contributed significantly to the development of the SABSA methodology, including co-authoring the “SABSA for Enterprise Risk Management” training course and leads the volunteer effort “SABSA World” with the aim of establishing regional SABSA communities of interest.