by Bob Chaput | Jul 27, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment
Why Cyber Risk Governance Depends Less on Choosing the “Right” Methodology—and More on the Quality of the Assessment It Produces Introduction Imagine sitting in a board meeting six months after a major cyber incident. The immediate crisis has passed. Systems have been...
by Bob Chaput | Jun 25, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment
Cybersecurity failures are often described as technology failures. Sometimes they are. A missing patch mattered. A compromised credential mattered. A weak control mattered. A flawed configuration mattered. A delayed detection mattered. But many of the most...
by Bob Chaput | Jun 4, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment
What’s the Problem? Many organizations still treat risk assessment as a compliance task. A rule requires it. An auditor asks for it. A customer expects it. An insurer wants to see it. A regulator may later review it. So, the organization produces something. A...
by Bob Chaput | May 31, 2026 | Defensible Risk Assessment, Governance, Strategy, and Alignment, Regulations, Legal Cases, and Increasing Liability
Introduction Recently wrapping up our latest Healthcare Enterprise Cyber Risk Management course at The University of Texas at Austin, I have been thinking and writing about a problem I now call Defensible Risk Assessment. Our Capstone Project requires students to...
by Bob Chaput | Mar 7, 2025 | Board and CISO Interaction – Best Practices, Costs of Cyber Attacks and Data Breaches, Governance, Strategy, and Alignment, Regulations, Legal Cases, and Increasing Liability
Introduction As my readers know, I have an affinity for risk analysis and risk management, which I often pose in the form of this question: How will you make informed, intelligent decisions about what safeguards you should invest in and implement until you understand...
by Bob Chaput | Jan 27, 2025 | Board and CISO Interaction – Best Practices, Costs of Cyber Attacks and Data Breaches, Governance, Strategy, and Alignment, Regulations, Legal Cases, and Increasing Liability
“As the world is increasingly interconnected, everyone shares the responsibility of securing cyberspace.” ― Newton Lee “And it starts with C-suite and board accountability.” ― Bob Chaput Introduction In today’s rapidly evolving digital landscape, enterprise cyber risk...