[{"data":1,"prerenderedAt":574},["ShallowReactive",2],{"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment":3,"blog-all-posts":498},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"titleLines":10,"descriptionLines":14,"bodyLeadTitle":18,"publishedAt":19,"updatedAt":20,"tags":21,"coverImage":25,"coverAlt":26,"heroLayout":27,"heroTitleSize":28,"heroOverlayStrength":29,"heroTagBreakAfter":30,"featured":6,"draft":6,"body":31,"_type":492,"_id":493,"_source":494,"_file":495,"_stem":496,"_extension":497},"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment","blog",false,"","The Necessity of an Enterprise Risk Assessment","Effective Cybersecurity is both a Technical and Procedural Endeavor",[11,12,13],"The Necessity","of an Enterprise","Risk Assessment",[15,16,17],"Effective Cybersecurity","is both a Technical","and Procedural Endeavor","Technology Alone Is Not Enough","2026-05-26","2026-06-22",[22,23,24],"enterprise risk assessment","risk management","cybersecurity governance","\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment\u002Fcover.jpg","CISO in an aircraft cockpit overlooking clouds with technical and procedural cybersecurity displays","overlay","compact","soft",2,{"type":32,"children":33,"toc":476},"root",[34,42,47,56,63,68,73,78,84,89,99,105,110,120,126,131,136,220,225,233,238,244,249,256,261,269,283,291,304,310,315,322,335,342,355,361,366,372,377,420,425,430,436,446,452,457,463,468],{"type":35,"tag":36,"props":37,"children":38},"element","p",{},[39],{"type":40,"value":41},"text","Every year organizations spend hundreds of millions of dollars on cybersecurity technologies. They deploy firewalls, endpoint detection, multi-factor authentication, and vulnerability scanners. Yet despite these investments, organizations continue to suffer costly ransomware attacks, business email compromise, data theft, and operational disruption.",{"type":35,"tag":36,"props":43,"children":44},{},[45],{"type":40,"value":46},"Why?",{"type":35,"tag":36,"props":48,"children":49},{},[50],{"type":35,"tag":51,"props":52,"children":53},"strong",{},[54],{"type":40,"value":55},"Because cybersecurity is not merely a technology problem - it is fundamentally a business risk management problem.",{"type":35,"tag":57,"props":58,"children":60},"h2",{"id":59},"cybersecurity-beyond-the-technical",[61],{"type":40,"value":62},"Cybersecurity Beyond the Technical",{"type":35,"tag":36,"props":64,"children":65},{},[66],{"type":40,"value":67},"When companies address cybersecurity they first think of the technical issues surrounding it such as network architecture, firewalls, patching, MDR, vulnerabilities and so on.",{"type":35,"tag":36,"props":69,"children":70},{},[71],{"type":40,"value":72},"This is a logical approach since the first implementation of cybersecurity within a business is a technical undertaking. This could be in the form of deploying zScaler, a secure web gateway, or Proofpoint, an email security platform - to name a few.",{"type":35,"tag":36,"props":74,"children":75},{},[76],{"type":40,"value":77},"If Cybersecurity was exclusively a technical exercise - the world would have solved the cyber threats facing businesses years ago. The greater the threat - the more technical solutions would then be applied. It would be a simple one-to-one mapping of a cyber threat to a technical solution.",{"type":35,"tag":57,"props":79,"children":81},{"id":80},"companies-still-get-breached",[82],{"type":40,"value":83},"Companies Still Get Breached",{"type":35,"tag":36,"props":85,"children":86},{},[87],{"type":40,"value":88},"But companies invest vast sums of money on technical cybersecurity solutions - and still get breached. This is because the scope of a company's cybersecurity posture goes far beyond technical security solutions.",{"type":35,"tag":36,"props":90,"children":91},{},[92,94],{"type":40,"value":93},"Technical controls are designed to reduce specific attack vectors. They cannot compensate for poor governance, excessive privileges, weak vendor oversight, inadequate change management, poor executive decision making, or a lack of security awareness. Many successful cyber incidents occur because ",{"type":35,"tag":51,"props":95,"children":96},{},[97],{"type":40,"value":98},"organizational risks, not technological shortcomings, remain unmanaged.",{"type":35,"tag":57,"props":100,"children":102},{"id":101},"both-a-technical-and-procedural-endeavor",[103],{"type":40,"value":104},"Both a Technical and Procedural Endeavor",{"type":35,"tag":36,"props":106,"children":107},{},[108],{"type":40,"value":109},"There will always be a necessity to maintain a strong technical security posture. This is \"table stakes\" in today's threat environment. The technical side of cybersecurity is only the critical first step in securing businesses.",{"type":35,"tag":36,"props":111,"children":112},{},[113,115],{"type":40,"value":114},"For medium to large companies, once the technical baseline has been established ",{"type":35,"tag":51,"props":116,"children":117},{},[118],{"type":40,"value":119},"the greatest impact on strengthening the cybersecurity posture lies with a comprehensive enterprise risk assessment.",{"type":35,"tag":57,"props":121,"children":123},{"id":122},"risk-assessment-defined",[124],{"type":40,"value":125},"Risk Assessment Defined",{"type":35,"tag":36,"props":127,"children":128},{},[129],{"type":40,"value":130},"In cybersecurity, a risk assessment is the process of identifying, analyzing, and evaluating cyber risks to an organization's information systems, data, and operations. Its purpose is to determine which threats pose the greatest risk so that security resources can be prioritized effectively.",{"type":35,"tag":36,"props":132,"children":133},{},[134],{"type":40,"value":135},"A typical cybersecurity risk assessment involves these steps:",{"type":35,"tag":137,"props":138,"children":139},"ol",{},[140,155,168,181,194,207],{"type":35,"tag":141,"props":142,"children":143},"li",{},[144,149,153],{"type":35,"tag":51,"props":145,"children":146},{},[147],{"type":40,"value":148},"Identify Assets",{"type":35,"tag":150,"props":151,"children":152},"br",{},[],{"type":40,"value":154},"Determine what needs protection, such as servers, applications, databases, intellectual property, customer information, and critical business processes.",{"type":35,"tag":141,"props":156,"children":157},{},[158,163,166],{"type":35,"tag":51,"props":159,"children":160},{},[161],{"type":40,"value":162},"Identify Threats",{"type":35,"tag":150,"props":164,"children":165},{},[],{"type":40,"value":167},"Consider potential sources of harm, including cybercriminals, insider threats, malware, ransomware, phishing attacks, natural disasters, and system failures.",{"type":35,"tag":141,"props":169,"children":170},{},[171,176,179],{"type":35,"tag":51,"props":172,"children":173},{},[174],{"type":40,"value":175},"Identify Vulnerabilities",{"type":35,"tag":150,"props":177,"children":178},{},[],{"type":40,"value":180},"Find weaknesses that could be exploited, such as unpatched software, weak passwords, misconfigured systems, or inadequate security policies.",{"type":35,"tag":141,"props":182,"children":183},{},[184,189,192],{"type":35,"tag":51,"props":185,"children":186},{},[187],{"type":40,"value":188},"Analyze Risk",{"type":35,"tag":150,"props":190,"children":191},{},[],{"type":40,"value":193},"Evaluate the likelihood that a threat will exploit a vulnerability and the potential impact if it occurs.",{"type":35,"tag":141,"props":195,"children":196},{},[197,202,205],{"type":35,"tag":51,"props":198,"children":199},{},[200],{"type":40,"value":201},"Prioritize Risks",{"type":35,"tag":150,"props":203,"children":204},{},[],{"type":40,"value":206},"Rank risks based on their severity so the most significant ones are addressed first.",{"type":35,"tag":141,"props":208,"children":209},{},[210,215,218],{"type":35,"tag":51,"props":211,"children":212},{},[213],{"type":40,"value":214},"Recommend Controls",{"type":35,"tag":150,"props":216,"children":217},{},[],{"type":40,"value":219},"Select and implement security measures to reduce identified risks. These may include technical controls (e.g., firewalls, encryption, multi-factor authentication), administrative controls (e.g., security policies, employee training), and physical controls (e.g., access badges, surveillance).",{"type":35,"tag":36,"props":221,"children":222},{},[223],{"type":40,"value":224},"A common way to express risk is:",{"type":35,"tag":36,"props":226,"children":227},{},[228],{"type":35,"tag":51,"props":229,"children":230},{},[231],{"type":40,"value":232},"Risk = Likelihood × Impact",{"type":35,"tag":36,"props":234,"children":235},{},[236],{"type":40,"value":237},"The primary goal of a cybersecurity risk assessment is not to eliminate all risk. This is generally considered to be impossible. The goal is to understand risks and reduce them to an acceptable level while supporting the organization's business objectives. Over time the risk to an organization becomes manageable.",{"type":35,"tag":57,"props":239,"children":241},{"id":240},"quantitative-vs-qualitative",[242],{"type":40,"value":243},"Quantitative vs Qualitative",{"type":35,"tag":36,"props":245,"children":246},{},[247],{"type":40,"value":248},"There are two approaches to a risk assessment: Qualitative versus Quantitative.",{"type":35,"tag":250,"props":251,"children":253},"h3",{"id":252},"qualitative-risk-assessment",[254],{"type":40,"value":255},"Qualitative Risk Assessment",{"type":35,"tag":36,"props":257,"children":258},{},[259],{"type":40,"value":260},"A qualitative risk assessment evaluates risks using subjective categories rather than exact numbers. It considers factors such as the likelihood of a threat occurring and the potential impact on the organization. This approach is commonly represented with a risk matrix, where likelihood and impact are rated (e.g., Low, Medium, High) to prioritize risks.",{"type":35,"tag":36,"props":262,"children":263},{},[264],{"type":35,"tag":51,"props":265,"children":266},{},[267],{"type":40,"value":268},"Advantages",{"type":35,"tag":270,"props":271,"children":272},"ul",{},[273,278],{"type":35,"tag":141,"props":274,"children":275},{},[276],{"type":40,"value":277},"Easy to understand and communicate.",{"type":35,"tag":141,"props":279,"children":280},{},[281],{"type":40,"value":282},"Requires less data.",{"type":35,"tag":36,"props":284,"children":285},{},[286],{"type":35,"tag":51,"props":287,"children":288},{},[289],{"type":40,"value":290},"Disadvantages",{"type":35,"tag":270,"props":292,"children":293},{},[294,299],{"type":35,"tag":141,"props":295,"children":296},{},[297],{"type":40,"value":298},"Relies on subjective judgment.",{"type":35,"tag":141,"props":300,"children":301},{},[302],{"type":40,"value":303},"May use insufficient data.",{"type":35,"tag":250,"props":305,"children":307},{"id":306},"quantitative-risk-assessment",[308],{"type":40,"value":309},"Quantitative Risk Assessment",{"type":35,"tag":36,"props":311,"children":312},{},[313],{"type":40,"value":314},"A quantitative risk assessment assigns numerical values to risks, often estimating the financial impact of security incidents. This allows organizations to calculate the expected cost of risks and justify investments in security controls.",{"type":35,"tag":36,"props":316,"children":317},{},[318],{"type":35,"tag":51,"props":319,"children":320},{},[321],{"type":40,"value":268},{"type":35,"tag":270,"props":323,"children":324},{},[325,330],{"type":35,"tag":141,"props":326,"children":327},{},[328],{"type":40,"value":329},"Produces objective, measurable results.",{"type":35,"tag":141,"props":331,"children":332},{},[333],{"type":40,"value":334},"Supports budgeting and return-on-investment (ROI) decisions.",{"type":35,"tag":36,"props":336,"children":337},{},[338],{"type":35,"tag":51,"props":339,"children":340},{},[341],{"type":40,"value":290},{"type":35,"tag":270,"props":343,"children":344},{},[345,350],{"type":35,"tag":141,"props":346,"children":347},{},[348],{"type":40,"value":349},"More complex and time-consuming.",{"type":35,"tag":141,"props":351,"children":352},{},[353],{"type":40,"value":354},"Not all risks can be easily expressed quantitatively.",{"type":35,"tag":57,"props":356,"children":358},{"id":357},"semi-quantitative-semi-qualitative",[359],{"type":40,"value":360},"Semi-Quantitative & Semi-Qualitative",{"type":35,"tag":36,"props":362,"children":363},{},[364],{"type":40,"value":365},"The best approach for most businesses is a combination of both: qualitative methods to identify and prioritize risks, and quantitative methods to evaluate high priority risks in greater detail. This provides a deeper assessment within the time available for the assessment.",{"type":35,"tag":57,"props":367,"children":369},{"id":368},"risk-owned-by-one-the-responsibility-of-all",[370],{"type":40,"value":371},"Risk: Owned by One, the Responsibility of All",{"type":35,"tag":36,"props":373,"children":374},{},[375],{"type":40,"value":376},"Cybersecurity is fundamentally a business governance function. Ultimate accountability rests with executive leadership and the Board of Directors. This governance model is consistently reflected across leading frameworks and standards, such as:",{"type":35,"tag":270,"props":378,"children":379},{},[380,385,390,395,400,405,410,415],{"type":35,"tag":141,"props":381,"children":382},{},[383],{"type":40,"value":384},"NIST CSF 2.0",{"type":35,"tag":141,"props":386,"children":387},{},[388],{"type":40,"value":389},"NIST SP 800-53",{"type":35,"tag":141,"props":391,"children":392},{},[393],{"type":40,"value":394},"ISO\u002FIEC 27001",{"type":35,"tag":141,"props":396,"children":397},{},[398],{"type":40,"value":399},"COBIT 2019",{"type":35,"tag":141,"props":401,"children":402},{},[403],{"type":40,"value":404},"CIS Critical Security Controls v8",{"type":35,"tag":141,"props":406,"children":407},{},[408],{"type":40,"value":409},"COSO ERM",{"type":35,"tag":141,"props":411,"children":412},{},[413],{"type":40,"value":414},"CISA Cybersecurity Performance Goals",{"type":35,"tag":141,"props":416,"children":417},{},[418],{"type":40,"value":419},"NACD Cyber-Risk Oversight Principles",{"type":35,"tag":36,"props":421,"children":422},{},[423],{"type":40,"value":424},"The execution of cybersecurity is immediately delegated by the C-Suite to security, technology, and business teams who have the knowledge and experience to implement complex cybersecurity initiatives. With many companies this is where the responsibility ends. They view cybersecurity as a “Necessary Evil” that is forever beyond the understanding of average employees.",{"type":35,"tag":36,"props":426,"children":427},{},[428],{"type":40,"value":429},"These are the companies who have a higher risk profile suffering a greater instance of breaches.",{"type":35,"tag":57,"props":431,"children":433},{"id":432},"ownership-is-absolute",[434],{"type":40,"value":435},"Ownership Is Absolute",{"type":35,"tag":36,"props":437,"children":438},{},[439,441],{"type":40,"value":440},"Although you can accept, mitigate, transfer, or avoid a risk, ",{"type":35,"tag":51,"props":442,"children":443},{},[444],{"type":40,"value":445},"you ultimately always own the risk.",{"type":35,"tag":57,"props":447,"children":449},{"id":448},"culture-of-security",[450],{"type":40,"value":451},"Culture of Security",{"type":35,"tag":36,"props":453,"children":454},{},[455],{"type":40,"value":456},"A risk assessment helps to create a culture of security by making security a shared responsibility across the organization rather than just the responsibility of the IT or cybersecurity team. By regularly identifying risks, evaluating vulnerabilities, and implementing controls, employees become more aware of security threats and understand their role in protecting organizational assets.",{"type":35,"tag":57,"props":458,"children":460},{"id":459},"the-strongest-approach",[461],{"type":40,"value":462},"The Strongest Approach",{"type":35,"tag":36,"props":464,"children":465},{},[466],{"type":40,"value":467},"A risk assessment and a technical assessment (such as a penetration test) complement each other because they evaluate different aspects of an organization's cybersecurity posture. While a risk assessment focuses on people, processes, and policies, a technical assessment focuses on identifying vulnerabilities in systems and networks. Together, they provide a more complete picture of organizational risk.",{"type":35,"tag":36,"props":469,"children":470},{},[471],{"type":35,"tag":51,"props":472,"children":473},{},[474],{"type":40,"value":475},"Companies who perform both have the best view of their security posture and can address the threats decisively.",{"title":7,"searchDepth":30,"depth":30,"links":477},[478,479,480,481,482,487,488,489,490,491],{"id":59,"depth":30,"text":62},{"id":80,"depth":30,"text":83},{"id":101,"depth":30,"text":104},{"id":122,"depth":30,"text":125},{"id":240,"depth":30,"text":243,"children":483},[484,486],{"id":252,"depth":485,"text":255},3,{"id":306,"depth":485,"text":309},{"id":357,"depth":30,"text":360},{"id":368,"depth":30,"text":371},{"id":432,"depth":30,"text":435},{"id":448,"depth":30,"text":451},{"id":459,"depth":30,"text":462},"markdown","content:blog:the-necessity-of-an-enterprise-risk-assessment.md","content","blog\u002Fthe-necessity-of-an-enterprise-risk-assessment.md","blog\u002Fthe-necessity-of-an-enterprise-risk-assessment","md",[499,511,521,532,542,550,561,572],{"_path":500,"title":501,"description":502,"cardTitle":503,"publishedAt":504,"tags":505,"coverImage":509,"coverAlt":510,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two","Understanding Your True Attack Surface: Part Two","Few companies understand how they look to an attacker. Your Internet attack surface is exactly what attackers see first.","Understanding Your True Attack Surface Part Two","2026-07-28",[506,507,508],"attack surface","internet security","cybersecurity strategy","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two\u002Fcover.jpg","Cyber operations control tower monitoring a connected city and its Internet-facing attack surface",{"_path":512,"title":513,"description":514,"publishedAt":515,"tags":516,"coverImage":519,"coverAlt":520,"featured":6},"\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026","Top Cyber Threats Facing Businesses in 2026","Businesses face AI-assisted hacking, interception-proxy phishing, dark web breach data, and API attacks in 2026.","2026-06-26",[517,518,508],"cyber threats","business security","\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026\u002Fcover.jpg","A city skyline beneath a massive storm cloud embedded with cybersecurity symbols and lightning",{"_path":522,"title":523,"description":524,"publishedAt":525,"tags":526,"coverImage":530,"coverAlt":531,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two","Challenges Facing AI Frontier Models Part Two","Frontier AI models must overcome constraints in context, agent design, data quality, energy, and open-source competition.","2026-06-25",[527,528,529],"artificial intelligence","frontier models","AI safety","\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two\u002Fcover.jpg","A humanoid robot ascending a snowy mountain ridge toward the sunset",{"_path":533,"title":534,"description":535,"cardTitle":536,"publishedAt":537,"tags":538,"coverImage":540,"coverAlt":541,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one","Understanding Your True Attack Surface: Part One","The modern attack surface extends far beyond the corporate firewall.","Understanding Your True Attack Surface Part One","2026-06-21",[506,539,508],"network security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one\u002Fcover.jpg","Security leader reviewing an enterprise attack surface dashboard spanning cloud, applications, remote offices, devices, patching, identities, and internet exposure",{"_path":543,"title":544,"description":545,"publishedAt":546,"tags":547,"coverImage":548,"coverAlt":549,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models","Challenges Facing AI Frontier Models Part One","Frontier AI models face a series of challenges that threaten their viability","2026-06-12",[527,528,529],"\u002Fblog\u002Fchallenges-facing-ai-frontier-models\u002Fcover.jpg","A humanoid robot standing among clouds beneath a blue sky",{"_path":551,"title":552,"description":553,"cardTitle":554,"publishedAt":555,"tags":556,"coverImage":559,"coverAlt":560,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation","Executive Operational Security Part One: Setting the Foundation","Executive OPSEC protects senior leaders, privileged access, sensitive information, communications, travel, and personal activity from targeted threats.","Executive Operational Security Part One","2026-06-10",[557,558,23],"executive security","OPSEC","\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation\u002Fcover.jpg","Executive reviewing his phone beside a laptop in a private office",{"_path":562,"title":563,"description":564,"publishedAt":565,"tags":566,"coverImage":570,"coverAlt":571,"featured":6},"\u002Fblog\u002Fevaluating-identity-before-attackers-do","Evaluating Identity Before Attackers Do","An IAM assessment evaluates authentication, access controls, user behavior, and identity resilience before attackers can exploit them.","2026-06-07",[567,568,569],"identity security","IAM assessment","access management","\u002Fblog\u002Fevaluating-identity-before-attackers-do\u002Fcover.jpg","Open cyber vault displaying identity security controls and authentication monitoring",{"_path":4,"title":8,"description":9,"publishedAt":19,"tags":573,"coverImage":25,"coverAlt":26,"featured":6},[22,23,24],1785277054252]