惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
L
LangChain Blog
Google DeepMind News
Google DeepMind News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
About on SuperTechFans
博客园_首页
N
Netflix TechBlog - Medium
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
美团技术团队
V
V2EX

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Infosecurity Europe: How to Get Boards to Prioritize Cybe...
Danny Palmer · 2026-06-03 · via www.infosecurity-magazine.com

One of the best ways to advise boards on cybersecurity risks is is to focus on money and how a smart approach to cyber risk management can be a strong long term investment for the organization, according to a panel of security leaders at Infosecurity Europe 2026.

Cyber exposure can be difficult to measure. However, using Cyber Risk Quantification (CRQ) and data to showcase cybersecurity threats and vulnerabilities, the most important cybersecurity issues to focus on and what the financial cost of a cyber attack could be to the organization is best way to get support from the board.

Multinational Oil and Gas company BP has been using risk management across the business for decades, but in recent years, it has started applying the practice to cybersecurity.

Vital to this strategy, James Russell, digital risk management lead at BP, said during a fireside chat on the Infosecurity Europe Deep Dive Stage, is to ensure that the data that is produced and what it means can be easily understood by managers.

“It’s something that needs to connect outside of security. But communicating cyber risk, how do you make it meaningful to business leaders?” said Russell. The answer, he continued, is to quantify it around the costs of not properly managing the risk.

Why Businesses Should Measure Risk Using Dollar Value

BP's Russell said, “Quantifying risk with a dollar value makes it more meaningful, especially when you have a large organization. Measuring risk can be a complex, but dollar value is something everyone understands.”

Silas Bartlett, managing director for cybersecurity at NatWest Group, agreed that getting board buy-in was vital for any organization looking to quantify cybersecurity risk – and it was with this in mind that the bank set out its plans to do so.

“We were having internal discussion on how to improve board reporting,” he explained during the fireside chat. “There is a enough data out there that with enough modelling we can quantify what risk looks like.”

“So, we had a target from the beginning to do board reporting and worked backwards from there,” he added.

This was not without challenges, particularly around being sure that the quality and quantity data being examined, and therefore the outcome of the risk reports, was correct.

“When you look at the way banks measure credit risk, they have huge amounts of data over decades which we [cybersecurity] don’t have. And the complexity of a cyber-attack means we are asked how we can be confident we haven’t made a mistake?” Barlett explained.

“But one of the things we’ve done is put assumptions in model to say ‘what if we’re wrong about this by 10% or a new vulnerability allows an attacker to breach our perimeter?”

The more data that gets added over time, the more accurate that model will become. One of the key outputs which good data around risk can help quantify is the “dollar attribution” – and how proper cyber risk management can save the organization money by preventing or disrupting a potential future breach.

Russell suggested that because the findings are based on real data statistics, it should help eliminate making choices around gut feeling and subjective opinion.  

However, those responsible for presenting risk to must ensure that what they are sharing is based on the needs of the board. If the data is too complicated to understand, they won’t be able to do much with it.

“The biggest challenge is the amount of information for stakeholders, translating CRQ language into common lexicon to help manage risk – it should be an enabler which helps your requirements,” Russell said.