Cyber & IT Risk

Cyber risk, quantified and governed

NIST CSF 2.0, FAIR quantification, DORA compliance, and supply-chain cyber risk after Log4j and SolarWinds.

🛡️

Frameworks & Governance

NIST CSF 2.0's Govern function, Zero Trust framing for the board, and control mapping that holds up in audit.

📐

Quantification

FAIR-based loss modeling that turns "high/medium/low" into numbers a CFO can plan against.

🔗

Third-Party & AI Risk

Supply-chain concentration, cloud exit strategies, and the new risk surface of AI systems.

🛡️

NIST CSF 2.0 Govern Function: What Changed and Why It Matters

Overview: The revised NIST Cybersecurity Framework (CSF) version 2.0 introduces significant updates to the Govern function, affecting CROs, risk managers, internal auditors, and co…