Dr. Bill Souza
Cybersecurity Risk
Feeling overwhelmed by cyber risk? You're not alone. In today's digital world, cyber threats are a complex issue and a strategic opportunity to strengthen your organization's resilience. This podcast dives deep into the world of cyber governance and risk management . We'll have open conversations with experts to help you take your organization's cybersecurity posture from "as-is" to the next level. Here's what you'll learn: Program and control assessments: Identify weaknesses in your current defenses. Risk identification and mitigation: Proactively address threats before they strike. Building...
Author
Dr. Bill Souza
Category
Podcast website
Latest episode
Aug 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Mission-Centric Risk Assessment - Preparation 01.09.2022 7:00
Send us Fan Mail Mission Centric Risk Assessment In a mission-based risk assessment, the question is, how do you perform one? A four-layer approach will be a good start: Mission layer Operational layer Application layer Infrastructure layer ======== Blog: https://www.execcybered.com/blog Training: https://www.execcybered.com/iso27001foundationcourse Linkedin: https://www.linkedin.com/company/exc...
Top 2 Measurement Challenges 25.08.2022 3:47
Send us Fan Mail When measuring risk in your organization, you’ll typically discover two challenges: First, top key risk measures that do not have supporting data (aspirational). Second, you’ll be developing middle to low measures with supporting data that do not entirely address the risk. The lack of data to calculate a particular measure is no reason not to measure the risk; these are your aspi...
Cybersecurity Report BoD 18.08.2022 2:08
Send us Fan Mail Cybersecurity Report Framework to the Board of Directors There is a three-point framework to keep in mind when preparing a report to the Board, especially if you are a small to medium-size business with annual revenue between $100M to $700M with [potentially] no CISO in your organization. What are key risks the Board should be aware of at a high level? What should they be offered...
Business Value 11.08.2022 3:03
Send us Fan Mail How do you understand a digital asset's business value? First, let’s define what a digital asset is; a digital asset is a system, process, data, and technology that is used. A cyber event could affect one or more of these digital assets, resulting in a loss for the business. These digital assets have a hierarchical relationship: Organization Function Business Unit Own & U...
SMB 4 Risk Management Pillars 04.08.2022 3:01
Send us Fan Mail NIST has developed a cybersecurity risk management framework that addresses the issue as a comprehensive process that requires organizations to: Frame risk Assess the vulnerabilities Respond to risk once determined Monitor risk on an ongoing basis These four pillars must be addressed by all small and midsize businesses. A small and midsize business (SMB) is a business that, due to...
Risk Owners 28.07.2022 5:09
Send us Fan Mail There are many stakeholders in cybersecurity, and it makes sense to outline roles and responsibilities in terms of how each role impacts cyber resiliency. The board of directors February 21, 2018, SEC guidance requires board oversight in terms of cyber (https://www.sec.gov/rules/interp/2018/33-10459.pdf). Chief Information Security Officer (CISO) There are two types of CISOs; a go...
NISTIR 8286D 21.07.2022 4:58
Send us Fan Mail The initial public draft of NIST IR 8286D provides comprehensive asset confidentiality and integrity impact analyses to accurately identify and manage asset risk propagation from system to organization and from organization to enterprise, which in turn better informs Enterprise Risk Management deliberations. This document adds expanded BIA protocols to inform risk prioritization a...
Cyber Frameworks - 3 Common Pitfalls 14.07.2022 3:01
Send us Fan Mail Choosing a Cybersecurity Framework Three common pitfalls of cybersecurity or risk frameworks: Finding the “perfect” framework. No single framework fits an organization’s risk profile perfectly. Frameworks like ISO 27001, ISO 3100, NIST CSF, NIST RMF, COBIT, and many others. Using custom frameworks that do not map to regulators or industry standards. Failing to assign a single pro...
Cybersecurity - 5 Measures & Metrics 07.07.2022 5:53
Send us Fan Mail There are several measurements or metrics an organization can put in place to monitor; some of them can be turned into Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs). ======== Training: https://www.execcybered.com/iso27001foundationcourse Linkedin: https://www.linkedin.com/company/exceccybered/ Twitter: https://twitter.com/DrBillSouza Instagram: https://www.insta...
Risk Assessment - What to Assess 28.06.2022 4:04
Send us Fan Mail These 3 steps you can take to perform a risk assessment: Identify and document the scope and assets to be assessed. I suggest starting with your critical assets. Identify and collect your assessment data. Vulnerability scan (including applications) Minimum security baseline scan Access management at the OS and application levels Standard exceptions against your scoped systems Secu...
What to Focus First 27.06.2022 2:58
Send us Fan Mail What to Focus on FIRST Mission-based cybersecurity Systems supporting the mission, vision, and services Regulatory systems - PCI, HIPAA, SOX, GDPR Prioritizing remediation is based on quantifying the three primary financial impacts: Business interruption cost Data exfiltration cost Regulatory cost === Blog: https://www.execcybered.com/blog Training: https://www.execcybered.com/sto...
Improving Risk Program - 5 Tips 27.06.2022 3:18
Send us Fan Mail There are some simple rules that you can start today to ensure improvements to your cyber risk program. Define the problem Define risk Define critical Identify and inventory critical assets or systems Identify risks These rules apply to small, medium, and large businesses with corresponding difficulty levels. Thanks. Dr. Bill Souza CEO | Founder E|CE - Executive Cyber Education ht...
Tackling Risk Probability and Impact 14.10.2021 8:09
Send us Fan Mail Today I’ll discuss risk probability and impact and give you some examples to build your own impact and probability table. Probability Impact Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
5 Cybersecurity Challenges 26.09.2021 7:30
Send us Fan Mail Today I’ll touch on the topic of Cyber Risk & Cyber Investment challenges. Improving Exploits Attack paths Attacker behavior Investment Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Lacking Basic Cybersecurity Practices 09.09.2021 7:26
Send us Fan Mail The show today is based on an article titled, “Global utilities lacking basic cybersecurity practices.” Although the article was focused on utilities, the guidance is applicable to every industry, so I will touch on a few recommendations that could be useful to you as well, regardless of industry. Links mentioned on the show: Article: Global utilities lacking basic cybersecurity p...
Cybersecurity Basics - What you Need to Know 26.08.2021 10:53
Send us Fan Mail We are so focused on the threats and the vulnerabilities that allowed a hack to occur, that we forget the basics. The protection necessary to prevent or slow down these attacks already exists, and they exist for a long time. Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Cybersecurity Exceptions - Part 3 (FINAL) 19.08.2021 5:52
Send us Fan Mail In today's episode, I will discuss exceptions tracking and expirations. This is the last episode in a three-part series on cybersecurity standard exceptions. Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Cybersecurity Exceptions - Part 2 12.08.2021 5:44
Send us Fan Mail As I mentioned in my previous episode, there’s much more to discuss on cybersecurity exceptions, such as the risk they pose to the organization and the hidden dangers of cumulative risk. Blog: https://www.execcybered.com/blog/cybersecurity-exceptions-part-2 Thanks. Dr. Bill Souza Founder & CEO E|CE - Executive Cyber Education www.execcybered.com
Cybersecurity Exceptions - Part 1 05.08.2021 5:40
Send us Fan Mail If your cybersecurity standards were written to protect the organization, why do you have security exceptions? Your standard development team writes an excellent standard; it follows all the best practices of the NIST Cybersecurity Framework, the ISO 27001, or any other industry-recognized standards and frameworks, but most of all, it is common sense, right? Anyone working on or w...
Cybersecurity - Asset Classification 30.07.2021 6:16
Send us Fan Mail Asset classification is the foundation of everything else to come in cybersecurity; it will help your organization, for example, small or large, to better understand, manage, identify, and classify your assets. Episode: Cybersecurity - Asset Classification (execcybered.com) Dr. Bill Souza Founder & CEO Executive Cyber Education
Zero-Sum Game 31.12.2020 9:45
Send us Fan Mail In this episode, I will discuss three challenging areas where cybersecurity education is falling short in preparing students and professionals to succeed in the field.
Cybersecurity Investment & Risk Strategy 05.08.2020 9:51
Send us Fan Mail In this episode, I discuss how to leverage your risk framework to make sound cybersecurity investment decisions. I addressed two critical questions that you will need to know the answers; first, how can you tell your program is doing the right thing? and second, How can you tell you are protecting the organization in a financially healthy way? Dr. B. Executive Cyber Education www....
Critical Systems: Asking the Right Questions 14.06.2020 16:04
Send us Fan Mail To get results you need to ask the right question, collect the data, analyze, and develop a robust and factual interpretation. This episode will guide you through the thought process and give you some ideas on how to develop a strong argument on where you should focus your cybersecurity investments and tools. Infographic: https://executive-cyber-education.mykajabi.com/identificati...
Cyber Risk Identification 09.06.2020 16:00
Send us Fan Mail Today’s episode I will discuss a strategy to identify critical systems in your organization. The steps I will discuss today will make sure your program is objective and repeatable. The eBook mentioned in this podcast can be downloaded here: https://executive-cyber-education.mykajabi.com/risk-identification-ebook Thanks. Dr. B. https://execcybered.com/podcast-1
Key Risk Indicators 26.04.2020 13:03
Send us Fan Mail Today’s episode we will discuss how to identify KRIs (key risk indicators). I’ll discuss a simple and effective way to do it; there seems to be a lot of confusion on what to measure and for a long time, subject matter experts believe we can’t measure Cybersecurity.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.