Looking at the bigger picture of IT, there are a lot of amazing technicians, architects, and analysts. There are also great leaders in higher levels of management such as CTOs and CIOs. These are all people that “keep the joint running” and ensure that IT remains the critical business function that we often forget it is. But there's one thing that I've noticed that is sorely missing across the board and that is the ability to properly analyze risks. I'm not talking about simple black-and-white comparisons of whether or not a penetration test or audit finding is a worthy of addressing. Rather, I’m talking about true, in-depth analysis that determines actual risk for each specific issue in the unique situation of that particular business.
The post Risk analysis – how to overcome an enterprise weakness appeared first on algosec.