Artwork

Nội dung được cung cấp bởi Compromising Positions. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Compromising Positions hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.
Player FM - Ứng dụng Podcast
Chuyển sang chế độ ngoại tuyến với ứng dụng Player FM !

EPISODE 21: Bringing The Curtain Down On Risk Theatre And Applauding Objective-Centred Risk Management

30:34
 
Chia sẻ
 

Manage episode 406328031 series 3517973
Nội dung được cung cấp bởi Compromising Positions. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Compromising Positions hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

Welcome to Compromising Positions!

The tech podcast that asks non-cybersecurity professionals what we in the industry can do to make their lives easier and help make our organisations more prepared to face ever-changing human-centric cyber threats!


This week we are joined by Sabrina Segal, an integrity, risk, and compliance advisor, with almost 20 years of experience in the public, private, and third-sectors.

In this week’s episode, Bringing the Curtain Down on Risk Theatre and Applauding objective-centred Risk Management, Sabrina shares with us, a quite frankly amazing model to work from: The OCRM, Objective-centred Risk Management.

This model a great antidote to what Sabrina describes as ‘risk theatre’ which is the performance of risk governance activities, without real substance or accountability but with the dangerous consequence of making an organisation still feel like they have ‘done something’ when really it’s not worth the paper, or Excel doc, it is written on. This approach is scalable, practical, and effective, and it can help you achieve your goals while managing your risks and opportunities.

Key Takeaways:

Shift the Focus: Ditch the risk register and start with your objectives. What are you trying to achieve? What could stop you? This simple change aligns risk with your mission and drives informed decision-making.

Price Your Risks: Don't just identify risks, quantify them. Calculate the resource and software costs associated with each. This transparency reveals your true risk appetite and exposes gaps between rhetoric and reality.

Go-No-Go Decisions: OCRM empowers you to make clear, objective decisions based on risk pricing. Is the potential upside worth the cost? This eliminates wasted time and resources on low-impact risks.

Psychological safety: How to create an environment where employees feel empowered to speak up and challenge the status quo, even about risks.

The "halo effect": How the good work of charities and non-profits can sometimes mask poor risk management practices.

Utilising External Board Members: How to ensure they have the full picture and can effectively advise on cyber risks.

Links to everything we discussed in this episode can be found in the show notes and if you liked the show, please do leave us a review.

Follow us on all good podcasting platforms and via our YouTube channel, and don't forget to share on LinkedIn and in your teams.

It really helps us spread the word and get high-quality guests, on future episodes.

We hope you enjoyed this episode - See you next time, keep secure, and don’t forget to ask yourself, ‘Am I the compromising position here?’

Keywords: cybersecurity, risk management, objective-centred, OCRM, risk appetite, RACI, psychological safety, halo effect, board members, third sector, technical challenges.

SHOW NOTES

Tim Leech’s LinkedIn

A Post Sabrina did on Objective Mapping

The Halo-effect with Isabel de Bruin Cardoso - Tolerable Risk Podcast

Governance, Strategy and Risk with Claris D’Cruz - Tolerable Risk Podcast

ABOUT SABRINA M. SEGAL

Sabrina M. Segal is an integrity, risk, and compliance advisor, international development and humanitarian assistance professional, licensed US attorney, and Certified Fraud Examiner with almost 20 years of experience in the public, private, and third-sectors.

Sabrina's focus is risk in the third-sector as the impact of risk management, when done poorly, can be devastating to both third-sector organizations and the beneficiaries they serve. Sabrina is an active writer on LinkedIn and hosts the Tolerable Risk podcast.

LINKS FOR SABRINA M. SEGAL

Sabrina’s LinkedIn

Sabrina’s Podcast, Tolerable Risk

  continue reading

35 tập

Artwork
iconChia sẻ
 
Manage episode 406328031 series 3517973
Nội dung được cung cấp bởi Compromising Positions. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Compromising Positions hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

Welcome to Compromising Positions!

The tech podcast that asks non-cybersecurity professionals what we in the industry can do to make their lives easier and help make our organisations more prepared to face ever-changing human-centric cyber threats!


This week we are joined by Sabrina Segal, an integrity, risk, and compliance advisor, with almost 20 years of experience in the public, private, and third-sectors.

In this week’s episode, Bringing the Curtain Down on Risk Theatre and Applauding objective-centred Risk Management, Sabrina shares with us, a quite frankly amazing model to work from: The OCRM, Objective-centred Risk Management.

This model a great antidote to what Sabrina describes as ‘risk theatre’ which is the performance of risk governance activities, without real substance or accountability but with the dangerous consequence of making an organisation still feel like they have ‘done something’ when really it’s not worth the paper, or Excel doc, it is written on. This approach is scalable, practical, and effective, and it can help you achieve your goals while managing your risks and opportunities.

Key Takeaways:

Shift the Focus: Ditch the risk register and start with your objectives. What are you trying to achieve? What could stop you? This simple change aligns risk with your mission and drives informed decision-making.

Price Your Risks: Don't just identify risks, quantify them. Calculate the resource and software costs associated with each. This transparency reveals your true risk appetite and exposes gaps between rhetoric and reality.

Go-No-Go Decisions: OCRM empowers you to make clear, objective decisions based on risk pricing. Is the potential upside worth the cost? This eliminates wasted time and resources on low-impact risks.

Psychological safety: How to create an environment where employees feel empowered to speak up and challenge the status quo, even about risks.

The "halo effect": How the good work of charities and non-profits can sometimes mask poor risk management practices.

Utilising External Board Members: How to ensure they have the full picture and can effectively advise on cyber risks.

Links to everything we discussed in this episode can be found in the show notes and if you liked the show, please do leave us a review.

Follow us on all good podcasting platforms and via our YouTube channel, and don't forget to share on LinkedIn and in your teams.

It really helps us spread the word and get high-quality guests, on future episodes.

We hope you enjoyed this episode - See you next time, keep secure, and don’t forget to ask yourself, ‘Am I the compromising position here?’

Keywords: cybersecurity, risk management, objective-centred, OCRM, risk appetite, RACI, psychological safety, halo effect, board members, third sector, technical challenges.

SHOW NOTES

Tim Leech’s LinkedIn

A Post Sabrina did on Objective Mapping

The Halo-effect with Isabel de Bruin Cardoso - Tolerable Risk Podcast

Governance, Strategy and Risk with Claris D’Cruz - Tolerable Risk Podcast

ABOUT SABRINA M. SEGAL

Sabrina M. Segal is an integrity, risk, and compliance advisor, international development and humanitarian assistance professional, licensed US attorney, and Certified Fraud Examiner with almost 20 years of experience in the public, private, and third-sectors.

Sabrina's focus is risk in the third-sector as the impact of risk management, when done poorly, can be devastating to both third-sector organizations and the beneficiaries they serve. Sabrina is an active writer on LinkedIn and hosts the Tolerable Risk podcast.

LINKS FOR SABRINA M. SEGAL

Sabrina’s LinkedIn

Sabrina’s Podcast, Tolerable Risk

  continue reading

35 tập

Tất cả các tập

×
 
Loading …

Chào mừng bạn đến với Player FM!

Player FM đang quét trang web để tìm các podcast chất lượng cao cho bạn thưởng thức ngay bây giờ. Đây là ứng dụng podcast tốt nhất và hoạt động trên Android, iPhone và web. Đăng ký để đồng bộ các theo dõi trên tất cả thiết bị.

 

Hướng dẫn sử dụng nhanh