Is Measuring Risk Possible? I saw a discussion question recently asking how to measure risk? My first reaction was…do you measure risk?  I say no. Do you measure security?  Do you measure prevention?   I would say no and no. Do you measure cake? Not usually, unless you are paying for cake by the pound, but measuring the cake does not guarantee the cake is any good. Determining if the cake is any good depends on how the cake looks and how the cake tastes.  To make a good cake, you need to measure each of the ingredients for the cake (internal) and you needRead More →

  As the end of 2010 approaches, it is a great time to review lessons learned and decide where you need to be to ensure better results in 2011. Lessons learned from WikiLeaks, OCR and NSBA Dear Colleague letters, breaches, lawsuits, fines and numerous other failures clearly reveal how risks, threats, regulations, liabilities, vulnerabilities and obligations are changing.  Are you, your entire organization and your partners prepared for 2011? Status quo is not the way to keep up with change and status quo is clearly taking a serious toll on organizations around the world. Status quo is also expensive and perhaps Albert Einstein said itRead More →

All of this TSA stuff on the news is getting a little crazy…it almost seems like the media is looking for passengers who are looking for attention. But once again the lessons learned are clear…at least if we all agree on the primary goal. Hopefully everyone agrees that our main goal is safety and national security, because I don’t know about you, but when I am flying through the clouds at 35,000 feet I do not want the plane to blow up. So if we are all in agreement, then it comes down to human beings – pilots, passengers and security personnel – having situationalRead More →

  General Information Personally Identifiable Information Intelligence Information Industry Information Regulatory Information Legal Information Risk Information Customer Information Emergency Information Competitive Information Etc…. Most people and their organizations would agree they are overwhelmed by information that is spread all over in e-mails, web sites, binders, intranets, etc. BUT, most people and their organizations would also agree they are not overwhelmed by awareness, and more specifically they are not overwhelmed by Situational Awareness. Lessons learned continue to reveal that just having information is not enough.  Most of the highly publicized tragedies and incidents reveal that information in the form of red flags or intelligence or riskRead More →