top of page
Search


How to Build a Board Cybersecurity Report That Actually Works: A Deep Dive into TRIP
In a recent post, we introduced TRIP, our framework for structuring board-level cybersecurity reporting around four components: Threats, Risks, Incidents, and Program. The core idea is that metrics alone don't tell the board what they need to know. Context does. And TRIP provides a repeatable narrative structure that gives the board context, exposure, evidence, and action in a logical sequence they can follow every quarter. This post goes deeper. If you're building or rebuild
3 days ago11 min read


Risk Quantification in Practice
What if your risk register could answer: "What's our probable loss, and what's the cheapest way to reduce it?" In this video, TBDCyber Senior Consultant, Alexandra Reibel walks through how risk quantification works in practice, including modeling frequency and impact as ranges, running simulations, and tying results directly to budget and control decisions. No vibes. Just data.
Mar 161 min read


Cybersecurity Risk Quantification: A Logical Approach
In today’s boardrooms, cybersecurity leaders are being asked questions they were never trained to answer with confidence: How much risk are we carrying? What is the financial impact of a breach? Are we investing in the right controls? Too often, cyber risk is still communicated using subjective ratings like “high,” “medium,” or “low.” While useful at a technical level, these labels fail to support executive decision-making, budget prioritization, and risk ownership at the ent
Jan 122 min read


Outsourcing Third-Party Risk Management: Faster, Cheaper, and More Effective Vendor Risk Reduction
In today’s interconnected business environment, organizations rely on hundreds, sometimes thousands, of third parties to deliver critical services. Each of these relationships introduces potential risk: data breaches, operational disruption, regulatory violations, and reputational damage. According to SecurityScorecard’s 2025 Global Third-Party Breach Report, approximately 35% of breaches in 2024 involved a third party. Why Third-Party Risk Management Matters A well-structure
Sep 24, 20252 min read


What is cybersecurity risk management, and why does it matter?
🔐 What is cybersecurity risk management, and why does it matter? In a world where threats evolve daily, cybersecurity risk management helps organizations prioritize what really matters: protecting the systems, data, and operations that drive the business. In this quick video, TBDCyber's senior partner, Graeme Payne, breaks down what cybersecurity risk management means and how it drives security. 🎥 Tune in to hear. At TBDCyber, we help organizations build security programs t
Sep 23, 20251 min read


The Future of Third-Party Risk Management: AI & Automation
The Future of Third-Party Risk Management: AI & Automation Third-party risk programs are evolving—fast. AI is no longer just a buzzword; it’s reshaping how organizations manage vendor risks. In this video, Joe Mendygral, Senior Director at TBDCyber, breaks down the latest trends in AI-driven automation for third-party risk management. ✅ More vendors, less manual work – AI-driven platforms now analyze surveys, policies, and compliance reports automatically. ✅ Risk scoring & re
Jul 22, 20251 min read


Is your cybersecurity program actually protecting what matters most?
Is your cybersecurity program actually protecting what matters most? In this short video, TBDCyber's Alexandra Reibel explains why a risk-focused cybersecurity program is the smartest, most effective approach for today’s threat landscape. Too many organizations fall into the trap of chasing the latest threats or checking compliance boxes — but that’s not where true resilience comes from. ⛔ A threat-focused approach keeps you in constant reaction mode. ⛔ A compliance-focused p
Jul 22, 20251 min read


Scaling Your TPRM Program
Struggling to scale your third-party risk management program without blowing your budget? In this video, Joe Mendygral, who leads Third-Party Risk at TBDCyber, shares how we helped an organization boost analyst productivity by 250%—without compromising risk insight. How? 🔹 Smarter use of security monitoring tools 🔹 Streamlined surveys for inherent risk + security controls 🔹 Thoughtful automation through existing platforms If you’re trying to assess thousands of vendors eff
Jul 22, 20251 min read


Have you considered outsourcing Third-Party Risk Management?
Most organizations outsource IT services or MSSPs—but third-party risk often gets overlooked. In this quick video, Joe Mendygral, who leads our TPRM services at TBDCyber, shares how we help clients: ✅ Assess vendors ✅ Identify and remediate risk ✅ Provide clear, actionable reporting ✅ Scale from 10 to 100,000 vendors ✅ Tailor programs to your security framework or unique needs
Jul 17, 20251 min read


How CISOs Can Navigate Digital Transformation & Cyber Risk
Graeme Payne, Co-Founder and Senior Partner at TBDCyber, shares his thoughts on how CISOs can navigate digital transformation and cyber risk in this short video.
Jul 10, 20251 min read


Unpacking the Changes from NIST CSF 1.1 to 2.0
In the ever-evolving cybersecurity landscape, organizations must stay ahead to protect their digital assets and sensitive information. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) has been a guiding light for businesses seeking a comprehensive approach to managing and improving their cybersecurity posture. With the release of NIST CSF 2.0, organizations are presented with an updated roadmap designed to address the challenges of an in
Jan 20, 20242 min read


Transforming Third-Party Risk Management for 2024
In the ever-evolving landscape of cybersecurity, it's crucial to ensure that every facet of our defense mechanisms is not just keeping pace with the present but also propelling us into the future. However, when we take a closer look at Third Party Risk Management (TPRM), it's akin to stepping into a time warp where the echoes of 2006 still linger. A time when Spotify was yet to grace our playlists, Saddam Hussein faced trial, the housing bubble burst, and the stock market exp
Jan 20, 20242 min read
bottom of page