• About
  • Resources
    • Risk Analysis Evaluator
    • Business-ECRM Alignment Diagnostic
    • Cyber-Crisis Comm Blueprint
  • Books
    • Stop the Cyber Bleeding
    • ECRM As a Value Creator
  • Blog
  • Contact
Order Now
  • About
  • Resources
    • Risk Analysis Evaluator
    • Business-ECRM Alignment Diagnostic
    • Cyber-Crisis Comm Blueprint
  • Books
    • Stop the Cyber Bleeding
    • ECRM As a Value Creator
  • Blog
  • Contact
The Common Architecture of Every Credible Risk Assessment

The Common Architecture of Every Credible Risk Assessment

by Bob Chaput | Jul 27, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment

Why Cyber Risk Governance Depends Less on Choosing the “Right” Methodology—and More on the Quality of the Assessment It Produces Introduction Imagine sitting in a board meeting six months after a major cyber incident. The immediate crisis has passed. Systems have been...
Boards Oversee Risk. Management Owns the Decision.

Boards Oversee Risk. Management Owns the Decision.

by Bob Chaput | Jun 25, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment

Cybersecurity failures are often described as technology failures. Sometimes they are. A missing patch mattered. A compromised credential mattered. A weak control mattered. A flawed configuration mattered. A delayed detection mattered. But many of the most...
Methodology Matters: Why Defensible Risk Assessment Is More Than a Compliance Checkbox

Methodology Matters: Why Defensible Risk Assessment Is More Than a Compliance Checkbox

by Bob Chaput | Jun 4, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment

What’s the Problem? Many organizations still treat risk assessment as a compliance task. A rule requires it. An auditor asks for it. A customer expects it. An insurer wants to see it. A regulator may later review it. So, the organization produces something. A...
Most Organizations Can Produce a Risk Assessment. Fewer Can Defend One.

Most Organizations Can Produce a Risk Assessment. Fewer Can Defend One.

by Bob Chaput | May 31, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment, Regulations, Legal Cases, and Increasing Liability

Introduction Recently wrapping up our latest Healthcare Enterprise Cyber Risk Management course at The University of Texas at Austin, I have been thinking and writing about a problem I now call Defensible Risk Assessment. Our Capstone Project requires students to...

Recent Posts

  • The Common Architecture of Every Credible Risk Assessment
  • Boards Oversee Risk. Management Owns the Decision.
  • Methodology Matters: Why Defensible Risk Assessment Is More Than a Compliance Checkbox
  • Most Organizations Can Produce a Risk Assessment. Fewer Can Defend One.
  • Raising the Bar for HIPAA Risk Analysis and Risk Management

Recent Comments

No comments to show.
  • About
  • Resources
    • Risk Analysis Evaluator
    • Business-ECRM Alignment Diagnostic
    • Cyber-Crisis Comm Blueprint
  • Books
    • Stop the Cyber Bleeding
    • ECRM As a Value Creator
  • Blog
  • Contact
  • Follow
  • Follow
  • Follow

Bob Chaput 2024. | Privacy | Cookies

Website Designed by Book Launchers