It is too late to start figuring out what to do when a cyber security incident occurs. If your organisation has not thought about how to identify a significant incident, who needs to be involved and what steps it needs to take to resolve the incident then it is likely to struggle to bring the incident to a timely resolution.
The Blog
There is still only one way to eliminate risk
This is not a new post, I originally wrote and published it nearly six years ago. However, based on a number of discussions I have been party to over the last few weeks, not much has changed since it was published so I thought I would repost it as a prologue for a new series of blog posts about risk, risk assessment and risk management.