top of page
Search


The Six Questions Every Board Is Now Asking CISOs About AI
By TBDCyber | CISO & Executive Advisory Something has shifted in boardrooms over the past 18 months. It used to be that a CISO could walk into a board meeting, present a security update, field a few questions about ransomware or regulatory compliance, and walk out. The questions were predictable. The conversation was manageable. That's no longer the case. AI has upended the boardroom dynamic, not because boards have suddenly become cybersecurity experts, but because AI has be
6 hours ago6 min read


Introducing The Human Error: Why Cybersecurity Failures Are Never Just a Technology Problem
TBDCyber co-founder Graeme Payne's new book is available Every major breach of the last decade followed the same sequence. A risk was acknowledged. A control was inadequately implemented. The gap was deprioritized. An attacker found it. SolarWinds. Colonial Pipeline. MGM. The technology changes. The human and organizational conditions that turn threats into catastrophes do not. That pattern is the subject of The Human Error: Why Cybersecurity Failures Are Never Just a Technol
Aug 173 min read


How to Build a Board Cybersecurity Report That Actually Works: A Deep Dive into TRIP
In a recent post, we introduced TRIP, our framework for structuring board-level cybersecurity reporting around four components: Threats, Risks, Incidents, and Program. The core idea is that metrics alone don't tell the board what they need to know. Context does. And TRIP provides a repeatable narrative structure that gives the board context, exposure, evidence, and action in a logical sequence they can follow every quarter. This post goes deeper. If you're building or rebuild
Jul 1411 min read


Risk Quantification in Practice
What if your risk register could answer: "What's our probable loss, and what's the cheapest way to reduce it?" In this video, TBDCyber Senior Consultant, Alexandra Reibel walks through how risk quantification works in practice, including modeling frequency and impact as ranges, running simulations, and tying results directly to budget and control decisions. No vibes. Just data.
Mar 161 min read


Unpacking the Changes from NIST CSF 1.1 to 2.0
In the ever-evolving cybersecurity landscape, organizations must stay ahead to protect their digital assets and sensitive information. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) has been a guiding light for businesses seeking a comprehensive approach to managing and improving their cybersecurity posture. With the release of NIST CSF 2.0, organizations are presented with an updated roadmap designed to address the challenges of an in
Jan 20, 20242 min read
bottom of page