What is risk?
A function of the likelihood and impact of a security incident or data breach
What is the cyber risk equation?
risk = threats x vulnerabilities x asset value over controls
What are the components of the risk equation?
Risk Threats Vulnerabilities Asset Value Controls
What is the Lockheed Martin Kill Chain?
Reconnaissance - research, identification, select targets
Weaponisation - pairing malware with exploit to payload
Delivery - transmission of weapon to target
Exploitation - weapon is triggered
Installation - installs backdoor
Command & Control - linking weapon to outside network
Actions on Objective - exfiltrate data, ransom encryption, etc.
What is the risk management process?
Frame the risk Asses the risk Respond to the risk Monitor the risk Rinse and repeat