What Is a Cybersecurity Risk Assessment (and HOW TO DO THEM!)

  Рет қаралды 48,000

Gerald Auger, PhD - Simply Cyber

Gerald Auger, PhD - Simply Cyber

Күн бұрын

Пікірлер: 91
@LuisGonzalez-qi6hn
@LuisGonzalez-qi6hn Жыл бұрын
Summarizing Risk Analysis General Structure: 1. Get all the intel on the system/solution you are interested in 2. Figure the use case for this solution to your organization 3. identify all of the vulnerabilities of the solution 4. Figure out the likelihood of those vulnerabilities being exploited 5. Identify the impact to your organization when they are exploited 6. Group the vulnerabilities by priority 7. Address the ones that are unacceptable to reduce the risk to lower level 8. Rinse & repeat
@MarcusJGrey
@MarcusJGrey 3 жыл бұрын
Its super important. Arguably the 3 most important documents you'll find in an organization is 1) the asset inventory 2) the risk analysis/inventory and 3) controls inventory. These tell you exactly what a company has, what they're afraid of and how they're protecting themselves/those assets. Great that you're shining a light on GRC topics as well!
@ArachnaeNonafel
@ArachnaeNonafel Жыл бұрын
Thanks for these vids! I'm an older person looking to change careers and these are helpful.
@robertalvarado884
@robertalvarado884 3 жыл бұрын
Wow this video just summarized my Security & Risk Analysis 311 class that I took about two years ago. Everything you taught us, I literally learned in class. Thank you.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Nailed it!
@FUNGUS_Josh_Mason
@FUNGUS_Josh_Mason 3 жыл бұрын
This was the most thorough, succinct explanation of risk management I've ever seen.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Thanks Josh. Do it a few hundred times and you can cut out the excess. :)
@doyinogunmakin
@doyinogunmakin 2 ай бұрын
This video is too dope! Very informational . Thank you
@SimplyCyber
@SimplyCyber 2 ай бұрын
thanks so much!
@TanujPandey18
@TanujPandey18 3 жыл бұрын
One of the most comprehensive video on Risk Assessment Program. I was able to relate maximum of the things. I feel happy that I found this helpful channel which is creating useful content on GRC stuff.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
You're most welcome. i've lived it a while. The pattern begins to emerge. "Rinse and repeat." lol
@SAnderson54
@SAnderson54 3 жыл бұрын
More GRC videos!! Thanks so much Gerald!
@SimplyCyber
@SimplyCyber 3 жыл бұрын
You got it! Will be sprinkling them in. Thanks AS!
@Peyo3729
@Peyo3729 8 ай бұрын
Thank you so much! This was really helpful!
@moechaudhry6412
@moechaudhry6412 3 жыл бұрын
Great video! I recently moved over from Operations into a Cyber Security role that specifically deals with Risk to our organization. Would love more videos on the Risk side and if there any good book recommendations, etc.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
This side of the house gets less love. Best reads(stay w me on this) is NIST special publication 800-37 and 800-30. Both are free and can be downloaded
@udohpele1696
@udohpele1696 2 жыл бұрын
Thanks for this Gerald. This is really awesome and well explained. 😤😤 Thanks alot.
@SimplyCyber
@SimplyCyber 2 жыл бұрын
My pleasure!
@NTG2396
@NTG2396 2 жыл бұрын
Great video I became an assurance manager and been banging my head against a brick wall trying to figure out the correct way of completing a risk assessment
@mmughal
@mmughal 2 жыл бұрын
May be a longer version where you actually do it will be great
@SimplyCyber
@SimplyCyber 11 ай бұрын
I demonstrate the process in a lab in my GRC Analyst Master course fwiw
@mmughal
@mmughal 11 ай бұрын
@@SimplyCyberis that courses here in KZbin ?
@tsuyax6054
@tsuyax6054 3 жыл бұрын
We have a GRC department on my previous company but they don't focus on IT Security but more on with company operations/financials etc.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Yes, Risk manifests in many ways. Many companies are now seeing cyber as their top risk though given all the ransomware.
@hassanjibrilkamba
@hassanjibrilkamba 5 ай бұрын
Thanks for the lecture,it's very Interesting❤
@SimplyCyber
@SimplyCyber 5 ай бұрын
Glad you liked it!
@Cwhitlock-StudyGRC
@Cwhitlock-StudyGRC 7 ай бұрын
Such a great video, even without all the fancy studio stuff. 🤣I wish everybody watched this getting started!
@SimplyCyber
@SimplyCyber 7 ай бұрын
Thanks so much!!
@realdragonking7779
@realdragonking7779 Жыл бұрын
This was a helpful video and well explained! Thank you Gerald.
@adeyinkaakinnukawe3048
@adeyinkaakinnukawe3048 10 ай бұрын
Came across this video while doing research for sort of a (cyber security) risk assessor portfolio for a beginner and i think it's a great resource. Can anyone help with ideas for how to continue practicing as a beginner? Thank you :)
@Enyalus87
@Enyalus87 3 жыл бұрын
If you're doing this professionally, like you're a security auditor or compliance manager or that's the career direction you're trying to go, do you need to know/be certified in ISO 27001 or COBIT or anything?
@SimplyCyber
@SimplyCyber 3 жыл бұрын
For the most part no, but there are a few where it’s yes (see below). You could get CISA cert to differentiate yourself but that’s it. I believe PCI auditors need to be certified by PCI to be a QSA. Also with the new us govt CMMC refs you will here to be certified to officially audit.
@lyndonmodomo2973
@lyndonmodomo2973 11 ай бұрын
Yes know ISO27001-ISO27005. I just lost a contract because I started talking about the NIST and the guy was in another country and did not like the USA. If I had known I would have talked about the ISO framework but used the NIST 800-53 behind the scenes as well as the ISO. Since things are going global, know whats in those ISOs I mentioned above. Good luck ALL!!!!
@rmcgraw7943
@rmcgraw7943 3 жыл бұрын
Very good video on Integration Risk assessments.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Thank you for the kind words.
@xssoverflow798
@xssoverflow798 3 жыл бұрын
Great Summary! Just subscribed!
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Awesome, thank you!
@SatishSingh-ni8bu
@SatishSingh-ni8bu Жыл бұрын
I just watched "Cybersecurity Risk Assessment (A Step by Step Tutorial and WHY!)" ...its awesome! beautifully explained and to the point .... May I know how should I get in touch with you to learn more about the Cyber Risk Assessment in details...
@SimplyCyber
@SimplyCyber Жыл бұрын
Simplycyber.teachable.com is a course I made all about GRC work, including a section and lab on risk assessment
@victorchez9847
@victorchez9847 Жыл бұрын
You are simply awesome.
@chrismengle
@chrismengle 3 жыл бұрын
Nice presentation, methodology is spot-on.
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Thank you kindly!
@adambala8525
@adambala8525 5 ай бұрын
❤❤❤ care is is taking need more knowledge from you sir
@waz1167
@waz1167 11 ай бұрын
Thank you!
@alieconteh7407
@alieconteh7407 Жыл бұрын
How do you approach institutions for them to provide you with risk assessment information as a start-up cybersecurity company
@SimplyCyber
@SimplyCyber Жыл бұрын
I’d offer the first few as free assessments in exchange for testimonials and then build on top of that. Especially if ur targeting other small biz that will recognize and appreciate the histle
@jashandeep8192
@jashandeep8192 3 жыл бұрын
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Thanks so much. I've got red vids in here too, but I'm an equal opportunity cyber honk. :D
@ArafatAliProfile
@ArafatAliProfile 3 жыл бұрын
Very good explanation. Thank you
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Glad it was helpful!
@ArafatAliProfile
@ArafatAliProfile 3 жыл бұрын
@@SimplyCyber Just gave an interview, your videos have given me very useful insights. Thank you again ❤️
@maisaalghamdi8068
@maisaalghamdi8068 Жыл бұрын
Amazingggggg!
@zubairusaidu6638
@zubairusaidu6638 5 ай бұрын
Very nice lecture I am Zubairu saidu cyber security
@khoapham1821
@khoapham1821 2 жыл бұрын
Thank you for the awesome video. I feel that you skip 1 big major step, is to identify all vulnerability. How one can identify them all ?
@oberlinio
@oberlinio 2 жыл бұрын
If you mean for risk assessment on organization's assets, then scope the assessment to particular system(s) and use an appropriate vulnerability scanning tool
@Ruffgemm
@Ruffgemm Жыл бұрын
Shouldn’t RAs cater beyond technical controls. Aren’t administrative, operational and physical controls a part of the risk analysis/assessment?
@manhalfamazing00
@manhalfamazing00 3 жыл бұрын
Subscribed. I need more cyber management skills. Any recommendation on reading material?
@SimplyCyber
@SimplyCyber 3 жыл бұрын
managing what? Tech, people, cyber program? I can advise, but need to know specfic.
@nicolasmaiques121
@nicolasmaiques121 Жыл бұрын
Hi Gerald, from all your experience what do you think about EBIOS RM methodology ?
@jarmandog8372
@jarmandog8372 3 жыл бұрын
Are companies obliged to share or publish their vulnerability assessments or Penetration tests? I know some publish their SOC 2 or ISO 27K compliance papers, but I haven't seen any public pentest/VA done to the services I consume
@SimplyCyber
@SimplyCyber 3 жыл бұрын
Def not. It would show your weaknesses and gaps. It would be a blueprint for bad guys to see where you’re soft
@jarmandog8372
@jarmandog8372 3 жыл бұрын
@@SimplyCyber Agree. I misunderstood you, maybe as an auditor/Compliance external you'd ask for it, but they're absolutely not required to share them to the general public 👍
@jarmandog8372
@jarmandog8372 3 жыл бұрын
@@SimplyCyber Are you planning on making videos about Threat Modeling orgs or specific apps? That'd be amazing! I'm liking the simplicity in which you explain in a short time 👌
@SimplyCyber
@SimplyCyber 3 жыл бұрын
@@jarmandog8372 it’s not on the video schedule but a great concept. Will add it. Thx
@zubairusaidu6638
@zubairusaidu6638 5 ай бұрын
What Analysis is an General description
@SimplyCyber
@SimplyCyber 5 ай бұрын
Looking at current state and understanding what is weakness and how bad it would be if it was exploited
@AMR-amr1
@AMR-amr1 3 жыл бұрын
I want to write a master's thesis on risk assessment in drones .can you help me
@SimplyCyber
@SimplyCyber 3 жыл бұрын
That’s substantial. I can speak to the concept but I don’t have the availability to actively participate in the thesis research
@AMR-amr1
@AMR-amr1 3 жыл бұрын
Thanks How can I communicate with you better ?
@SimplyCyber
@SimplyCyber 3 жыл бұрын
@@AMR-amr1 I’m on discord and LinkedIn. And just to be fully transparent I can have a conversation but I don’t have the bandwidth to help you in a material way w your thesis
@jamesclark9380
@jamesclark9380 11 ай бұрын
Content actually starts at 2:40
@SimplyCyber
@SimplyCyber 11 ай бұрын
Lil “why” before that but yes the meat of the RA workflow you can jump to at 2:40
@amarullohripai3745
@amarullohripai3745 3 жыл бұрын
How vulnerabilities assessment?
@SimplyCyber
@SimplyCyber 3 жыл бұрын
You have to factor in threat intelligence, position of the system with the vulnerability in relation to (network) access, if there is an exploit available, if its being exploited in the wild, if there is a patch out. There are a lot of factors for vuln assessment. Maybe another video idea?
@ericlb8769
@ericlb8769 2 жыл бұрын
is there a place where i can find some TRA template for cyber security ? thanks
@SimplyCyber
@SimplyCyber 2 жыл бұрын
Not really but 5 questions to start and ask them. What’s their security awareness program look like? Where do they use mfa? Do they require remote access into your environment and if so how (you prefer vpn and isolated to only systems they need) How do they handle your data when in their control? (Encrypted backed up delete when not needed) After contract termination how easy is it to get your data out and they not keep it too? Bonus questions: do you sell any of our data or meta data? Are you (and of the answer isn’t yes run) going to notify us and how quickly if your confirm a incident on systems where our data is. That’s just off the cuff w my Friday afternoon happy hour beer but would say the same if you were sitting next to me. Cheers friend!
@ericlb8769
@ericlb8769 2 жыл бұрын
@@SimplyCyber thanks a lot that s a grest start :)
@Ad000121
@Ad000121 Жыл бұрын
Does anyone know of some risk assessment case studies
@24reyeser
@24reyeser 3 жыл бұрын
Yeahhhhhhh!!!!!!
@SimplyCyber
@SimplyCyber 3 жыл бұрын
All Things Risk Assessments. Hope you enjoy. As the video goes on I get more frothed up. :)
@24reyeser
@24reyeser 3 жыл бұрын
@@SimplyCyber get better soon!!
@Compliance237
@Compliance237 Жыл бұрын
Can you please let us have the transcript of the video?
@Preshopnutrition
@Preshopnutrition 5 ай бұрын
Please what is the meaning of GRC?
@SimplyCyber
@SimplyCyber 5 ай бұрын
Governance, risk, and compliance
@lorenzoderrick1346
@lorenzoderrick1346 3 ай бұрын
@@Preshopnutrition Governance, Risk and Compliance
@JohnEButton
@JohnEButton 2 жыл бұрын
FAIR isnt semi-quantitative....totally false.
@bggees
@bggees 2 жыл бұрын
Yep, not semi-quantitative. He probably said that because you can still map your results (e.g., Loss exposure) to the Low, Mid, High (qualitative scale) that most folks are used to.
@havefun8834
@havefun8834 4 ай бұрын
All those years of experience in risk assesment and not being able to gothrough a real example or showing a real risk assesment doc ofc not mentioning company details, or atleast give real timeline of the project, resources in the project roles and responsibilities or not showing a sample risk docuement.. nothing.. just generic generic stuff which is available everywhere
@SimplyCyber
@SimplyCyber 4 ай бұрын
I’ll have to revisit this. I’ll add to my short list a video with more details. Thx for the constructive feedback. I’m dealing burnout rn but will add this to the queue
What is GRC in cybersecurity?
14:00
Gerald Auger, PhD - Simply Cyber
Рет қаралды 49 М.
Break into Cybersecurity in 2022 (Entry Level GRC Role)
18:56
Gerald Auger, PhD - Simply Cyber
Рет қаралды 28 М.
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН
"Unlock the Secret to Building the Perfect Risk Management Plan"
58:15
Cybersecurity Risk Assessment (Easy Step by Step)
20:34
The Infosec Academy
Рет қаралды 42 М.
How to Make a Risk Assessment Matrix in Excel
16:10
David McLachlan
Рет қаралды 553 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
Risk Assessment as per NIST SP 800-30
1:03:00
Ingram Micro Cyber Security
Рет қаралды 26 М.
The WORST Beginner Cyber Security Mistakes Everyone Makes (Avoid These)
15:11
UnixGuy | Cyber Security
Рет қаралды 69 М.
All The GRC Analyst Job Answers YOU Want
1:04:37
Gerald Auger, PhD - Simply Cyber
Рет қаралды 36 М.
How to Perform Effective OT Cyber Security Risk Assessments
30:36
SANS ICS Security
Рет қаралды 12 М.
Required Cybersecurity Skill: Understanding Basic Networking Concepts
37:12
Gerald Auger, PhD - Simply Cyber
Рет қаралды 84 М.
Conducting a cybersecurity risk assessment
52:42
IT Governance USA Inc.
Рет қаралды 90 М.
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН