Bob Chaput Author Blog
Enabling Board Cyber Risk Oversight
The Most Critical Cybersecurity Decision
Alignment of business strategy and risk appetite should minimize the firm’s exposure to large and unexpected losses. In addition, the firm’s risk management capabilities need to be commensurate with the risks it expects to take. —Jerome Powell Introduction In today’s...
Critical Concepts in Enterprise Cyber Risk Management and Their Importance
So difficult it is to show the various meanings and imperfections of words when we have nothing else but words to do it with. —John Locke Introduction In today’s rapidly evolving digital landscape, I cannot overstate the importance of robust enterprise cyber risk...
The Courts Are Picking Up the Cyber Pace: A New Era of Accountability for Boards of Directors
There is a higher court than courts of justice and that is the court of conscience. It supersedes all other courts. —Mahatma Gandhi Introduction In recent years, the legal landscape around cybersecurity and data breaches has shifted significantly, placing increasing...
The Strategic Value of Enterprise Cyber Risk Management (ECRM)
If you don’t invest in risk management, it doesn’t matter what business you’re in, it’s a risky business. —Gary Cohn Introduction Over the last year or so, I’ve begun to settle (at least in the recesses of my mind) on the root causes for the global mess we’re in...
Navigating SEC Cybersecurity Regulations: A Strategic Imperative for Enterprises
If you have ten thousand regulations, you destroy all respect for the law. —Winston Churchill Introduction Regulatory compliance has become a cornerstone of enterprise risk management in the ever-evolving cybersecurity landscape. Chapter 2 of my book, Enterprise Cyber...
Tackling Healthcare’s Top Challenges with Enterprise Cyber Risk Management (ECRM)
Cybercrime is the greatest threat to every company in the world. —Ginni Rometty, former CEO, IBM Introduction The healthcare industry faces unprecedented challenges, from shrinking profit margins and rising costs to regulatory complexities and the threat of new market...
Enterprise Cyber Risk Management: From Cost Center to Value Creator
Once you replace negative thoughts with positive ones, you'll start having positive results.—Willie NelsonIntroductionIn an era where digital transformation drives business growth, cybersecurity must transcend its traditional role as a defensive measure. Chapter 1 of...
The Crucial Role of Governance and Oversight in Cybersecurity: Regulations, Cases, and Standards
Corporate governance is concerned with holding the balance between economic and social goals and between individual and communal goals. The aim is to align as nearly as possible with the interests of individuals, corporations, and society. —Adrian Cadbury Introduction...
Accountability for Cyber Risk Management: A Critical Imperative for C-Suite Executives and Board Members
It is wrong and immoral to seek to escape the consequences of one’s acts.— Mahatma GandhiIntroductionAccording to the Merriam-Webster dictionary, “accountability” is “the quality or state of being accountable, especially an obligation or willingness to accept...
A Wake-Up Call for Healthcare Executives and Board Members
First, do no harm. —HippocratesIntroductionCybersecurity has become an essential aspect of modern healthcare, not just a concern for the IT department. Chapter 1 of Stop the Cyber Bleeding: What Healthcare Executives and Board Members Must Know About Enterprise Cyber...










