Dr. Bill Souza

Cybersecurity Risk

Feeling overwhelmed by cyber risk? You're not alone. In today's digital world, cyber threats are a complex issue and a strategic opportunity to strengthen your organization's resilience. This podcast dives deep into the world of cyber governance and risk management . We'll have open conversations with experts to help you take your organization's cybersecurity posture from "as-is" to the next level. Here's what you'll learn: Program and control assessments: Identify weaknesses in your current defenses. Risk identification and mitigation: Proactively address threats before they strike. Building...

Author

Dr. Bill Souza

Category

Technology

Podcast website

www.execcybered.com

Latest episode

Aug 29, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Mission-Centric Risk Metrics 23.02.2023

Send us Fan Mail Mission-Centric Cyber Risk Metrics Understanding what to measure in a mission-critical risk program is important, so today, I'll discuss a framework you can use. 1. Identify the system's environment (production, development, test, etc.) 2. System's criticality 3. Business Area ownership 4. Solution(s) being hosted on the identified systems 5. Top controls being viol...

Expanding Cyber Risk Beyond IT 16.02.2023

Send us Fan Mail Retail banking takes care of regular daily banking, for which most people know banks. This includes providing checking and saving services and issuing credit cards. Retail banking divisions may also be in charge of providing loans, mortgages, and other financings. Some other products and services may be offered under retail banking divisions: Lines of credit, Investment management...

Three Cybersecurity Checkups 09.02.2023

Send us Fan Mail Technologies and the methods used to hack into them continuously evolve. If you’re looking for an effective and efficient way to check the cybersecurity health of your organization, I suggest the following three checkups: Vulnerability and Penetration: Test Once you know the mission-critical systems in your organization, I suggest performing these two cybersecurity tests on a cont...

Cybersecurity - A Core Business Risk 02.02.2023

Send us Fan Mail Do you believe these are business challenges? Upskilling Low morale or quiet quitting Hiring and talent retention Keeping up with technology and tools If so, why aren’t you considering cybersecurity as a core business challenge? It takes 280 on average days to identify and contain a data breach, and the average cost is $3.86 million. Stolen or compromised employee credentials init...

A Worthy Mention - Antivirus Software 26.01.2023

Send us Fan Mail Antivirus has become a necessary tool for preventing cyber incidents; while the market is crowded, you need to look for antivirus software that fits your organization’s needs. NIST has guidance that you can leverage; NIST 800-83 recommends key capabilities that an antivirus software must have: Scanning startup files and boot records Real-time scanning of emails and email attachmen...

Greater than Cybersecurity 19.01.2023

Send us Fan Mail Greater than Cybersecurity When we realize that our cybersecurity challenges are complex and intertwined with conscious living people who view their actions in light of stories with emotions and ideas attached, one sees the need for many different perspectives. Therefore, the solution for your cybersecurity challenges will require knowledge beyond its discipline; it will involve c...

Protective Techology 12.01.2023

Send us Fan Mail Protective Technology The last item I want to mention under the Protect function that supports the  attack surface reduction and limits the cyber events' impact on your systems is “protective technologies.”  Remember, protecting your organization involves six critical cybersecurity categories: Access Control Awareness and Training Data Security Information Protection Processe...

Information Protection - Processes & Procedures 05.01.2023

Send us Fan Mail Ideally and preferably, your cybersecurity program should follow established policies, standards, and procedures. These documents will govern all organization members, including staff, vendors, volunteers, and anyone working on the organization’s behalf. The first step towards information protection is to develop and maintain a baseline configuration for IT and OT systems if this...

Protect - Data Security 29.12.2022

Send us Fan Mail Data Security The third of the six critical cybersecurity categories I presented previously is “data security.” An organization's most valuable asset is data; hackers seek data sources to steal from businesses, governments, and non-profit organizations, including small and midsized companies. Data must be protected in transit and at rest.  The NIST CSF addresses data security...

Protect - Awareness and Training 22.12.2022

Send us Fan Mail Securing and protecting your organization also takes a village to make happen, so cybersecurity awareness and training become very important; there’s so much technology can do to protect against phishing and its infinite variations, including the most efficient one, the Business Email Compromise (BEC); the FBI calls it “one of the most financially damaging online crimes.” The NIST...

Education 15.12.2022

Send us Fan Mail The problem educational narrative about “college” has created a false dichotomy between the two well-discussed college purposes. Some say college is about preparing a person for work – to help them get better employment or career. The other camp says college is about preparing an individual for success in life. Many of us see the purpose of college as both a job-driven and a caree...

Addressing the Highest Risks Podcast 08.12.2022

Send us Fan Mail Addressing the Highest Risks As we conclude the risk assessment and governance process, the last part will deal with the organization's highest risks, not the highest vulnerability, but rather the highest risks. This work could take the form of desktop exercises or brainstorming sessions. NIST cover this effort in the subcategory ID.RA-6 “Risk responses are identified and pri...

Cybersecurity Risk Assessment 01.12.2022

Send us Fan Mail Cybersecurity Risk Assessment Risk assessment is not necessarily scanning your network aimlessly; what should you expect from your team? First and foremost, adopt a risk assessment framework; it will be a helpful guide for determining what is assessed, who needs to be involved, and the criteria for developing risk criteria.  Some of the frameworks you should consider are: OCTAVE f...

Cybersecurity Governance 24.11.2022

Send us Fan Mail Cybersecurity Governance Once you have your hardware and software inventories, the next step might not be obvious. Still, before performing a risk assessment, you’ll need to establish a governance structure to report risk and regulatory, legal, and operational requirements. This particular governance requirement is covered in the NIST CSF subcategory ID.GV-4 “governance and risk m...

Cybersecurity Risk Management - Software Platforms 17.11.2022

Send us Fan Mail The NIST CSF subcategory ID.AM-2 deals with the inventory of software platforms and applications used in your organization. Most organizations will that creating an inventory of software to be a bit more challenging than creating one for hardware. When developing the inventory, make sure to take a holistic view of your organization’s operations and functions to build a comprehensi...

Cybersecurity Risk Management - Physical Devices 10.11.2022

Send us Fan Mail Cybersecurity Risk Management - Physical Devices The risk management process entails four fundamental concepts, which can be further broken down; however, the fundamental concepts are: Frame risk Assess risk Respond to risk once determined Monitor risk on an ongoing basis However, before getting here, other fundamental steps must be in place, and one that I have discussed here in...

Questions Boards Should Ask 03.11.2022

Send us Fan Mail Questions Boards Should Ask The challenge for directors or investors is determining the organizational overall cybersecurity maturity relative to the risk. The board of directors, in particular, has an oversight problem to solve, not a management problem. To quickly explore organizational thinking and cybersecurity management, here are five questions to get the discussion started...

Cybersecurity Confidence vs Performance 27.10.2022

Send us Fan Mail Cybersecurity Confidence vs. Performance Several studies conducted in other fields showed how spending effort on analysis improved confidence even when the actual performance was not improved. A study by the University of Chicago in 2008 tracked the probability of outcomes of sporting events as assigned by participants. These participants were given varying amounts of information...

The MOST Important Cybersecurity Principle 20.10.2022

Send us Fan Mail Asset management is most commonly associated with cybersecurity hygiene, which is associated with patching, anti-virus, access control, and other asset-specific protections. However, there are three NIST CSF sub-categories that I want to bring to your attention and how they align with a mission-based cybersecurity risk program. ID.AM-1: Physical devices and systems within the orga...

5 Focus Areas - Third-Party Risk Measurements 13.10.2022

Send us Fan Mail There are two types of third-party risk: product vendors and service providers. Product vendors outsource software, platform, and infrastructure, known as SaaS, PaaS, and IaaS. According to some estimates, only 40% of applications are hosted on-premises. The service providers are consulting third-party vendors, such as management consultants, IT consultants, Cybersecurity consulta...

5 Must-Have Cybersecurity Strategies for Small Businesses 06.10.2022

Send us Fan Mail Cyber attacks targetting small businesses that often do not have the resources to defend against devastating attacks like ransomware have grown. As a small business CEO or CIO, you have likely come across outdated security advice that does not help prevent the most common attacks. The security landscape has changed, and your cybersecurity knowledge needs to evolve with it. Here ar...

Third-Party Risk Management 29.09.2022

Send us Fan Mail Third-Party Risk Management The third-party outsourcing trend will continue to grow in the coming years, which places third-party risk as a significant concern for organizations, large or small. Depending on which statistics you read, 39-63% of breaches are caused by third parties. One of the most notorious breaches is the case of Target, where the HVAC vendor’s credential was sto...

Chasing Perfection 22.09.2022

Send us Fan Mail Chasing Perfection Pursuing perfection takes a lot of resources, financially and people. In Cybersecurity risk management, there are two key questions:  When will enough be enough?  What is the correct amount of time and effort should your organization spend to achieve a reasonable level of cybersecurity against an attacker? The answer to these questions will be your risk toleranc...

Cybersecurity Risk & Budget Challenges 15.09.2022

Send us Fan Mail Amid a global financial crisis and potentially facing cybersecurity budget challenges, you are now facing a tough decision; how to do more with less. What if I told you that you can; change the focus of your cybersecurity risk management program from a threat/vulnerability-centric focus to a mission-centric focus. Using the same people, processes, and technologies you have but tar...

5 Rules for Cybersecurity Risk Metrics 08.09.2022

Send us Fan Mail Rules for Effective Cybersecurity Metrics First, you must establish agreement among your leadership on the actual risk(s) to measure, then select which data will provide the most accurate representation of the risk. The following are 5 fundamental rules for measuring cybersecurity risk: Select informative measures with actionable value to leadership Research other subject matter e...

Listen to the Cybersecurity Risk podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.