Insights

Hear from thought leaders across the CRI community.

All Insights

From Pilot to Capability: The Journey to Operationalise CRQ

CRQ can’t remain a pilot forever. To drive meaningful, repeatable value, it needs to mature into a business capability: trusted, embedded, and regularly informing decisions.
James Hanbury

Winning the First Yes: Navigating the Five Most Common CRQ Objections

Before a single scenario is modelled or a number estimated, one of first challenges in adopting cyber risk quantification (CRQ) is simply persuading stakeholders it's worth doing.
James Hanbury

Six Principles of Effective CRQ: How to Build an Engine That Lasts

In this article, I’ll share six working principles I’ve found essential for embedding CRQ in a way that sticks — not just as a project, but as a true business capability.
James Hanbury

The Art and Science of CRQ: Why Practitioners Must Lead the Change

What Shackleton Can Teach Us About Navigating Cyber Risk
James Hanbury

From Insight to Action: Making CRQ Results Actually Useful

For all the energy that organisations invest in CRQ, a frustrating truth remains: many results don't actually lead to better decisions. Quantification is a powerful tool. But like any tool, its value lies in how it’s used.
James Hanbury

Building a Common Language for Cyber Risk: Why CRQ Needs Standardised Metrics

Just like the weather, Cyber Risk Quantification (CRQ) needs a standardised set of metrics. Let's explore what they can be.
James Hanbury

Making data driven decisions on cyber security

Understanding the cyber threats you face and where best to invest in strengthening your cyber security is a business priority.

Cybersecurity considerations 2025

The digital landscape continues to evolve at an unprecedented rate, bringing forth new challenges and amplifying the urgency for robust cybersecurity measures.

Worst Case vs Most Likely vs ALE

Worst case sets a practical limit on what should be spent to manage/mitigate risk, most likely is what you should expect to occur, while ALE tells you how to do long-term financial planning or to think for (self) insurance.
Mike Yeomans

Ready to report on cyber risk? A buyer’s guide to Cyber Risk Quantification

One way to fortify your cyber security is by using cyber risk quantification (CRQ), helping you to express risk quantitatively.
Martin Tyley

Cybersecurity considerations 2024

The KPMG annual Cybersecurity considerations report identifies eight key considerations that CISOs should prioritise in 2024 to help mitigate risk, drive business growth and build resilience.
KPMG International

A new age of cybersecurity culture

Cyber Human Risk Management (HRM) is essential to cybersecurity culture, as the way people manage technology is the window through which threat actors can infiltrate organisations.
KPMG International

The hostile limelight

Organisations around the world need to factor the geopolitical risk to cyber security – and the cyber-driven elements of geopolitical risk – into their strategic decision making.
KPMG

How quantitative risk management enables proactive resilience in the Public Sector

Public sector organisations are key to our economy, providing essential services to the population. Given the importance of the sector, they are prime targets for cyber-attacks, due to data-rich environments, critical infrastructure, political and ideological motivations and interconnected systems.
Laurie Gibbett

You need to be ready to report on your cyber security risk

Cyber security threats aren’t going away. If anything, as we evolve our use of technology through continued digitisation, they’ll grow. 
Alex Lightfoot

Empowering you to make smarter cyber risk decisions.

Thank you! A member of the team will be in touch shortly.
Oops! Something went wrong while submitting the form. Please try again.