Attributive Security
Episodes
#15 Enterprise (Security)? Architecture
25 Feb 2026
Contributed by Lukas
Enterprise Architecture (EA) and Enterprise Security Architecture (ESA) are viewed as distinct functions with different predominant tools, frameworks ...
#14 Is Vertical Systemic Risk a One-Way Street?
01 Oct 2022
Contributed by Lukas
If you've studied SABSA to foundation level, you may recall how systemic risk navigates the domain model. If a risk materialises in a domain, the impa...
#13 Blindsided by an Unknown Unknown
08 Nov 2021
Contributed by Lukas
With hindsight, declaring a risk an unknown unknown is often no more than an admission of a lack of foresight, a lack of imagination. How many risks t...
#12 The World is in Flux, Are You Ready to Adapt?
21 Sep 2021
Contributed by Lukas
The last two years have seen changes that few were prepared for. In the aftermath we can argue whether it was a black swan, grey rhino, or octarine un...
#11 Risk Management is a Game of Snakes AND Ladders
02 Jul 2021
Contributed by Lukas
Is your risk management one-sided, designed to minimise the likelihood and negative impacts of uncertain events. How is the uncertainty of events with...
#10 Supply Chain Risk (with Vincent Thiele)
13 May 2021
Contributed by Lukas
News of business impacts from the realisation of cyber risks is all around us. Many of the largest breaches in recent years have involved one or more ...
#9 Privacy: Security's New Clothes?
06 Apr 2021
Contributed by Lukas
The desire for privacy is nothing new, but societal expectations have certainly come a long way since the middle ages. Over the last two decades many...
#8 Certifications - Value or Vanity
22 Feb 2021
Contributed by Lukas
The information security field is awash with certifications. To an outsider many job adverts, in what is increasingly a sellers market, are full of im...
#7 Risk & Risk Appetite (with Jaco Jacobs)
21 Dec 2020
Contributed by Lukas
Enlightened risk management frameworks say we should manage risks to the business within the risk appetite. But what is the risk appetite? Can anyone ...
#6 Zero Trust - Revolutionary, Evolutionary or Snake Oil? (with Chris Blunt)
26 Nov 2020
Contributed by Lukas
Do you trust your network? Did you resist the lure of cloud services and network virtualisation, content with your on premise network security, only t...
#5 SWOT - Context, Capability, Challenge & Course
29 Oct 2020
Contributed by Lukas
What threats does your project, or business, face? What opportunities have you identified that you could pursue? What strengths do you have that you c...
#4 Business Risk & Risk Ownership (with Bill Schultz)
27 Sep 2020
Contributed by Lukas
Does the CISO own all cyber related risks to the business? It depends, but in many businesses that is the default position. Who is responsible for ris...
#3 Compliance
09 Sep 2020
Contributed by Lukas
In our previous episode we referenced not being in business to be compliant. Of course, that doesn't mean that compliance is never important; in some ...
#2 Ransomware
27 Aug 2020
Contributed by Lukas
Ransomware does not appear to have fallen victim to the pandemic. On the contrary, successful attacks appear to have increased and the impacts are esc...
#1 Trust
17 Aug 2020
Contributed by Lukas
In the light of recurring instances of security issues in foundational components of modern IT and software stacks, and the superfast world our busine...