Write-ups From the Risk Practice
Long-form notes on quantifying cyber risk, modelling loss with FAIR, and meeting Indian regulatory expectations — written for the people who have to defend the numbers, not for a keyword.
“Reasonable Security Safeguards” Is Now a Number
The DPDP Act attaches its largest penalty to a duty it deliberately declines to define. That is not a drafting gap — it is an instruction to show your reasoning. Here is what defensible reasoning looks like.
Read the write-up →FAIR Without the Folklore
Most objections to quantifying cyber risk are really objections to bad quantification. The difference between a model that survives scrutiny and one that gets dismissed comes down to a handful of disciplines — none of which require data you do not have.
Read the write-up →Your Board Doesn't Want a Heat Map
The problem with the red-amber-green grid is not that it is imprecise. It is that it cannot be compared, aggregated, or acted on — which is everything a board needs a risk report to do.
Read the write-up →No write-ups in that topic yet.
Know your cyber risk before it becomes a business crisis.
Put the ideas in these write-ups against your own environment. Start with a free assessment, or book a 30-minute walkthrough.