10 ms·
>We're paid to find risk and reduce risk. There's a dedicated department that already does that in most organizations -- risk management. One could argue that
by abhiminator 3y ago
>We're paid to find risk and reduce risk.
There's a dedicated department that already does that in most organizations -- risk management.
One could argue that 'cybersecurity' ought to be a component of 'risk management' versus being on its own which only adds to bloated organization structure and increases bureaucratic complexity.
- surge 3y agoYeah, and my team and larger cyber org was under risk management, until some new exec decided to shift us under the technology org (a decision I do not agree with due to conflict of interest).
- kstrauser 3y agoAt my last shop, we were under Risk, IT, Security, and Compliance, aka RISC.
- genmud 3y agoIn some orgs, that is the case. In other orgs, risk management might be a functionally absent, with legal teams being reviewers of contracts and abdicating that role to outside counsel.