Insights

The CER Directive Forces a Rethink of Risk & Resilience

Europe has been quietly re-engineering the rules of resilience. A few years ago, the Critical Entities Resilience Directive (CER) officially entered into force, marking a watershed moment for how the EU approaches the safeguarding of essential services across borders and sectors.

What UK Business Leaders Should Know About the Cyber Security & Resilience Bill

The UK government’s plan to modernize its cyber defenses isn’t just another legislative checkbox. It’s a pointed response to a threat that’s evolving faster than policy typically can. With ransomware attacks delaying over 11,000 NHS appointments last year and state-sponsored actors regularly probing UK infrastructure, the forthcoming Cyber Security and Resilience Bill is just trying to catch up.

Cybersecurity & the NIS2 Directive: The EU’s Evolving Cybersecurity Landscape

Picture this, it’s 2024, and the EU has just dropped a new bombshell in the world of cybersecurity. It’s called the NIS2 Directive, and while its name might not scream "party," it’s definitely something organizations need to pay attention to. For all the tech nerds and cybersecurity folks out there, this is more than just a new set of rules—it's a whole new way of doing business when it comes to securing networks, reporting incidents, and managing risk. But don’t worry, this article isn’t going to sound like it was written by a robot (unless, of course, that robot had an excellent sense of humor and personality). We’re diving into what NIS2 means, how it impacts AI, and what exactly you should be doing to stay ahead of the game. And spoilers, AI is going to be your best friend in this one.

Risk Appetite & Common Sense

In this article, Norman Marks inspects the concept of "risk appetite," challenging its validity and questioning its role in decision-making. Drawing from personal experiences and real-world examples, Marks argues that the traditional approach to defining and managing risk is overly simplistic and fails to capture the complexity of real-world risk. He critiques the common practice of quantifying risk as a single number and suggests that a more dynamic, objective-driven approach is needed. Rather than focusing on a static "risk appetite," Marks proposes that organizations should consider the likelihood of achieving their objectives, using risk as a factor in the decision-making process.

Strengthening Third-Party Risk Management and Governance Across the Extended Enterprise

In the increasingly interconnected world of modern business, organizations rely more than ever on third-party relationships. While these partnerships offer significant opportunities for growth and innovation, they also expose businesses to a range of risks that can threaten resilience and success. As geopolitical tensions and economic uncertainties continue to rise, it is essential for companies to reassess and strengthen their third-party governance, risk management, and compliance strategies. This article expands on the insights from my previous piece, Navigating the Storm: Strengthening Third-Party Governance and Risk Management in Your Extended Enterprise, offering a deeper look into how businesses can build robust, proactive frameworks to navigate these challenges and ensure sustained success across their extended enterprise.

Rethinking Risk & Internal Audit as Strategic Decision Support

In this article by Tim Leech, he delves into the evolving roles of risk and internal audit functions, exploring how they can transition from their traditional, compliance-focused image to become key decision-support partners for management and the board. Drawing on his extensive experience, Tim outlines the need for change in how internal audit and risk functions operate, emphasizing the importance of aligning with mission-critical objectives to drive better decision-making and organizational success.

Return on Investment (ROI) is an Essential Element in Risk Management

In this article by Norman Marks, he explores the critical intersection of Return on Investment (ROI) and risk management. The evolving landscape of risk management requires organizations to make informed decisions about how they treat and mitigate risk, ensuring that each investment aligns with strategic goals. In this piece, we’ll dive deeper into the concept of ROI as it relates to risk management and explore why every risk treatment should be evaluated not just for its effectiveness but also for the return on that investment.