top of page
Search


Risk Quantification in Practice
What if your risk register could answer: "What's our probable loss, and what's the cheapest way to reduce it?" In this video, TBDCyber Senior Consultant, Alexandra Reibel walks through how risk quantification works in practice, including modeling frequency and impact as ranges, running simulations, and tying results directly to budget and control decisions. No vibes. Just data.
Mar 161 min read


Coming Soon: Cyber Smokehouse
đ¨ Big news! TBDCyber is dropping something huge⌠and itâs đĽ Weâre thrilled to officially announce Cyber Smokehouse , a brand-new podcast from TBDCyber where we grill the minds, dig into the experience, and serve up the stories of leaders shaping the cybersecurity world. đď¸ Hosted by Ernie Anderson and Graeme Payne , Cyber Smokehouse isnât your typical cybersecurity show, itâs a place where real conversations, no-fluff insights, and the lived experience of todayâs c
Jan 281 min read


Hardening Your Microsoft 365 Tenant: A Practical Four-Pillar Approach
Setting up a Microsoft 365 (M365) tenant is often straightforward, thanks to the quick-start wizards. While ease and convenience are great, they don't always translate into strong security. When we created TBDCyber, we set up our M365 tenant in a matter of minutes. We had immediate access to all the productivity applications we needed, from Outlook to Teams. We had all the ease and convenience we needed to start operating our business, but the next question was: Are we doing
Jan 264 min read


Cybersecurity Risk Quantification: A Logical Approach
In todayâs boardrooms, cybersecurity leaders are being asked questions they were never trained to answer with confidence: How much risk are we carrying? What is the financial impact of a breach? Are we investing in the right controls? Too often, cyber risk is still communicated using subjective ratings like âhigh,â âmedium,â or âlow.â While useful at a technical level, these labels fail to support executive decision-making, budget prioritization, and risk ownership at the ent
Jan 122 min read


Outsourcing Third-Party Risk Management: Faster, Cheaper, and More Effective Vendor Risk Reduction
In todayâs interconnected business environment, organizations rely on hundreds, sometimes thousands, of third parties to deliver critical services. Each of these relationships introduces potential risk: data breaches, operational disruption, regulatory violations, and reputational damage. According to SecurityScorecardâs 2025 Global Third-Party Breach Report, approximately 35% of breaches in 2024 involved a third party. Why Third-Party Risk Management Matters A well-structure
Sep 24, 20252 min read


Vulnerability Management shouldn't be an afterthought?
đ¨ Why do most organizations only focus on Vulnerability Management after a major incident? In this short video, TBDCyber's Jeff Caranna highlights a hard truth: too often, the trigger for revamping a Vulnerability Management (VM) program is a security breach or significant incident. Post-incident reviews frequently reveal the causeâan unpatched or known vulnerability that could have been addressed earlier. At TBDCyber, we believe VM shouldnât be an afterthought. Itâs a core
Sep 23, 20251 min read


How prepared is your organization for the unexpected?
đ§Š How prepared is your organization for the unexpected? Tabletop exercises arenât just checkbox activities. Theyâre a powerful tool for identifying gaps, clarifying roles, and building confidence across teams before a real incident hits. In this short clip, TBDCyber's own Darrell Switzer shares why tabletop exercises are essential to any mature cybersecurity or business continuity program, and how they help turn chaos into coordinated response. đĽ Watch the video to hear Dar
Sep 23, 20251 min read


How TBDCyber Supports the CISO's Agenda
đ¨ CISOs are facing more pressure than ever. Are we setting them up for success, or for burnout? In this short video (just under a minute!), TBDCyber Senior Partner, Graeme Payne, shares key insights into the biggest challenges CISOs are grappling with todayâfrom evolving threats to boardroom expectations. With cybersecurity risks increasing and regulatory scrutiny tightening, CISOs need more than just technologyâthey need the right strategy, support, and execution to succeed
Sep 23, 20251 min read


What is cybersecurity risk management, and why does it matter?
đ What is cybersecurity risk management, and why does it matter? In a world where threats evolve daily, cybersecurity risk management helps organizations prioritize what really matters: protecting the systems, data, and operations that drive the business. In this quick video, TBDCyber's senior partner, Graeme Payne, breaks down what cybersecurity risk management means and how it drives security. đĽ Tune in to hear. At TBDCyber, we help organizations build security programs t
Sep 23, 20251 min read


Entra ID P2 Secure Your Admin Accounts Now!
đ Admin Accounts Deserve Extra Protection In this short clip, TBDCyber's Microsoft trusted advisor, Chris Goosen, explains why organizations should consider enabling Entra ID P2 licensingâespecially for administrator accounts. đŹ Key takeaway: Instead of always-on admin privileges, Entra ID P2 allows just-in-time access through Privileged Access Management (PAM). That means: âď¸ Admin accounts start with zero privileges by default âď¸ Elevated access is granted only when need
Sep 23, 20251 min read


Incident Response in Cybersecurity: A Strategic Approach
In todayâs cyber landscape, threats arenât a matter of if or whenâthey are impacting organizations right now. From ransomware attacks and data breaches to insider threats, every business is a potential target. The stakes are high: according to IBMâs 2024 Cost of a Data Breach Report, the average global cost of a breach reached $4.9 million, with most incidents taking more than 200 days to detect and contain. Why Incident Response Matters A well-structured Incident Response (I
Aug 26, 20252 min read


What actually makes a data security program effective?
What actually makes a data security program effective? Itâs not just about inventories or visibility dashboardsâitâs about reducing real-world risk. In this quick video, Zach Luze from TBDCyber breaks down the core outcomes every data security initiative should drive: â
Minimizing inappropriate access â
Detecting and preventing data loss â
Rendering data useless to attackers If your current strategy doesnât support these goals in tactical, measurable ways, it might be time to
Jul 22, 20251 min read


OT Security: Safeguarding Critical Infrastructure in a Connected World
OT Security: Safeguarding Critical Infrastructure in a Connected World As IT and OT systems continue to converge, new cybersecurity challenges emerge. Traditional OT environments werenât built with security in mind, making them vulnerable as they integrate with IT networks. Protecting critical infrastructure is non-negotiable. Watch TBDCyber's Bahaa Kutub, CISSP speak on the fundamentals of OT cybersecurity and how organizations can fortify their environments.
Jul 22, 20251 min read


The Future of Third-Party Risk Management: AI & Automation
The Future of Third-Party Risk Management: AI & Automation Third-party risk programs are evolvingâfast. AI is no longer just a buzzword; itâs reshaping how organizations manage vendor risks. In this video, Joe Mendygral, Senior Director at TBDCyber, breaks down the latest trends in AI-driven automation for third-party risk management. â
More vendors, less manual work â AI-driven platforms now analyze surveys, policies, and compliance reports automatically. â
Risk scoring & re
Jul 22, 20251 min read


Insider Threat Management - Where to Begin?
In this short video, Justin Barnett breaks down three essential steps to help organizations build a strong foundation for their Insider Risk Management (IRM) program: 1ď¸âŁ Identify Key Use Cases Start with your existing policiesâacceptable use, data classification, and user conduct. These guide your priorities for addressing insider threats like data leaks, IP theft, and misuse of resources. 2ď¸âŁ Establish Stakeholders IRM isnât just a security function. HR, Legal, and GRC play
Jul 22, 20251 min read


Is your cybersecurity program actually protecting what matters most?
Is your cybersecurity program actually protecting what matters most? In this short video, TBDCyber's Alexandra Reibel explains why a risk-focused cybersecurity program is the smartest, most effective approach for todayâs threat landscape. Too many organizations fall into the trap of chasing the latest threats or checking compliance boxes â but thatâs not where true resilience comes from. â A threat-focused approach keeps you in constant reaction mode. â A compliance-focused p
Jul 22, 20251 min read
bottom of page