Cyber security today requires an approach that is Top Down, Risk Based, and Business Focused.
Intro: In April 2025, NIST updated its primary guidance for cyber incident response plans (CIRPs), Special Publication 800-61 Revision 3. In 2023, the SEC also issued guidance on board cybersecurity oversight. Together, these developments significantly affect your current CIRP and…
Quick Summary: 2,250,000 reasons why you should have both your CIRP and your IR policy at least reviewed, and most likely updated. April 2025, NIST significantly upgraded the requirements for CIRPs. CIRPs need to integrate incident response into broader cybersecurity…
A recent Board of Director (BOD) level post from Victor Font (https://www.linkedin.com/pulse/premiums-exclusions-governance-blind-spot-victor-m-font-jr--lu3ie/) which I believe was “Spot On”, got me thinking about this topic further. (I have a previous post on cyber insurance here on this website from 3-4 years…
The SEC & NIST have issued new mandates regarding cybersecurity due diligence. This impacts the way you do Tabletop Exercises (TTX). Your TTXs are going to have to conform to the new mandates: “Strategic”, “Risk Based”, and “Business Aligned” beyond…
Last April (2025) the (US) NIST updated its 800-61 series documentation to Revision 3 which established new standards for CIRPs. My previous posts regarding the NIST 800-61r3 changes focused on “The NIST [800-61] Revision 3 integrating incident response into broader…
Summary: Public companies are now required to disclose their cyber risks and their Board of Director (BOD) cybersecurity risk oversight in their Annual Reports (SEC 10-K) These Cybersecurity disclosures incur fiduciary / due diligence obligations. Should any of these efforts…
Most organizations require a formal cyber incident response plan (CIRP) so they can pass an audit, remain compliant with current laws and regulations, and satisfy any cybersecurity requirements outlined by their Board of Directors (BOD). Plus, the CIRP must be actionable so that your IT team can use it in the event of a cyber incident.
Organizations today should have a clear link between those risks that have been identified by the Board (and published in their annual reports) and their cyber security program, spanning policies, plans, and procedures.
Cyber risks are now considered “corporate” risks and must function in the realm of Enterprise Risk Management (ERM) just like any other. The CISO will need to illustrate how the technical and non-technical components of both their CIRP and their overall InfoSec efforts specifically address each of these risks.
It is critical to address the many other business implications of a cyber incident, including statutory and contractual reporting, cyber insurance integration, protecting the organization’s reputation and market share, preparing for potential litigation, as well as many others.
With 10+ years of experience writing Comprehensive Cyber Incident Response Plans (CIRP) and conducting management level Tabletop Exercises (TTXs), you can feel comfortable that we address your industry specific needs.
In this new era of Board of Director (BOD) Cyber Risk oversight, we prepare you and your team to successfully protect your organization from cyber risks. Take advantage of our Top Down, Risk Based, and Business Focused approach and elevate your InfoSec program beyond the typical “Tactical” & “Technical” mindset and ensure that you and your InfoSec program are BOD ready. We have leveraged this approach with hundreds of global clients for the past 10 years and stand ready to assist you.
About Me
Neal is an ISC2 distinguished subject-matter expert with decades of cyber security experience in the military, law enforcement, and business domains. For the past decade, he has focused on management-level CIRPs and TTXs, including Board of Directors-level involvement.
“I can’t thank you enough. The value that we received out of the TTX was kind of like an Amex card; priceless. Within only 2 weeks after conducting the TTX, I was able to secure the following resources & support:
I had been pushing for and setting the stage for many of the above items for months and in some cases years. However, within the first 15 minutes of our TTX, our Executives immediately saw the need to implement better source code and application security protections. It was also evident to me within the first 15 minutes that I was now going to have the support and resources I needed. Coincidentally, the Solar Winds breach that was announced only 2 days later helped make the theoretical IR test scenario all too real, and that also helped our Execs realize this wasn’t just a hypothetical scenario.
To me, the value in the TTX is more than just identifying a gap here and there. It’s about getting the Executive level support that I need to better protect our company. Thank you so much for helping me accomplish that!”
Jennifer was one of many incredible InfoSec leaders that I’ve had the privilege of working with over the last decade, and I am so grateful she took the time to write this review when this project closed back in 2020. Executive Management TTXs are very different events. If done well, you get outcomes like this. Over the last 10 years, Executive Management TTX’s have become my specialty. Unfortunately, this type of a result is not that uncommon. On any given year, there have been 6-12 of these “Business Extinction epiphanies”. And it wasn’t me telling them they had this risk. These exercises are specifically designed to get the Executive team thinking & talking about their fears. I simply guide them along. More to the point, the minute I feed them the industry standard FUD (Fear, Uncertainty, Doubt) or try to “schlep” them a technology solution, the opportunity is lost. I try to be an honest broker and provide my clients the best advice I can. The Leadership team ultimately needs to make the call. But when they sincerely feel there is an existential risk to their organization, you will get the resources you need to protect the organization.
“Neal’s expertise really helps our team understand the threats we may face, and, more importantly, what we can do to discover and mitigate them. Creating a business-focused CIRP was also important and improves our ability to implement it. Well done! This was a great experience. I’m looking forward to working with Neal in the future!”
Lead cyber security incidents with confidence and improve your InfoSec program.