Articles tagged with: cybersecurity

Who can accept a risk on behalf of the organisation?

Who can accept a risk on behalf of the organisation_Behaviour Group

Who can accept a risk on behalf of the organisation?

Accepting a risk is a management decision. Learn how authority, criteria, governance and accountability relate to risk acceptance.

⏱️ Estimated reading time: 5–6 minutes

Risk acceptance is a management decision, not simply the outcome of a technical assessment. Identifying, analysing and rating a risk does not bring the risk management process to an end. When an organisation decides to retain a particular exposure, defer treatment or accept the risk that remains after controls have been implemented, that decision must be supported by criteria, authority and evidence.

But who can accept a risk on behalf of the organisation?

The answer depends on the governance model, established responsibilities and authorities, risk criteria and the exposure concerned. Those who identify or assess a risk do not necessarily have the authority to accept it.

How to connect project management, cybersecurity, cloud auditing and risk management?

How to Connect Project Management, Cybersecurity and Risk

How to connect project management, cybersecurity, cloud auditing and risk management?

⏱️ Estimated reading time: 9–10 minutes

A cloud migration, the implementation of a new platform or the modernisation of a digital service may be delivered on time and within budget and still fail.

All it takes is for the change to result in excessive access privileges, unclear responsibilities, unassessed dependencies or controls without evidence. Connecting project management, cybersecurity and risk with cloud auditing requires continuity between the business decision, the technical controls and the evidence produced.

NIS2 and ISO/IEC 27001: the same obligation or two different requirements?

Cybersecurity obligations and requirements

NIS2 and ISO/IEC 27001: the same obligation or two different requirements?

NIS2 and ISO/IEC 27001 share a common vocabulary: risk, controls, incidents, responsibilities. But they do not have the same nature or the same purpose. Treating one as a substitute for the other is one of the most frequent misunderstandings, with practical consequences for organisations and professionals.

⏱️ Estimated reading time: 6 minutes

The entry into force of NIS2 reinforced an idea that many organisations already knew, but did not always treat with the necessary priority: cybersecurity is no longer merely a technical concern and has become a requirement of governance, risk management, operational continuity and management accountability.At the same time, many entities already had, or are preparing, information security management systems based on ISO/IEC 27001. This raises a frequent question:Is complying with ISO/IEC 27001 the same as complying with NIS2?The answer is clear: no. NIS2 and ISO/IEC 27001 are not the same obligation. But they are deeply related.