Risk is Our Business

From Heatmaps to Histograms: Rewriting Cyber Risk on the Bridge with Tony Martin-Vegue

1 h 5 min · 13 apr 2026
aflevering From Heatmaps to Histograms: Rewriting Cyber Risk on the Bridge with Tony Martin-Vegue artwork

Beschrijving

In this return episode of Risk Is Our Business, Captain Michael Rasmussen reconnects with Tony Martin-Vegue for a wide-ranging conversation built around his new book, From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification. At the center of the discussion is a simple but uncomfortable idea: most organizations aren’t really measuring cyber risk, they’re describing it. Heatmaps, scoring models, and qualitative frameworks may look familiar, but they rarely help leaders make better decisions. Tony breaks down what’s going wrong, and why. Along the way, he uses an unexpected historical example (the Hanoi Rat Massacre of 1902) to illustrate how well-intentioned interventions can create worse outcomes when incentives, measurement, and behavior are misaligned. The conversation moves through the core themes of the book: * Why cybersecurity often behaves like two separate disciplines under one label * Why quantitative risk is less about advanced math and more about structured thinking * The biggest myth about data that keeps organizations stuck in qualitative approaches * Where methods like Monte Carlo simulation and FAIR fit and where they don’t They also explore why many cyber risk quantification programs fail, what it takes to make them practical, and how the same principles apply beyond cyber to operational risk more broadly. At over an hour, this is one of the most in-depth conversations on the show! It's less a summary and more a working session on how to move from risk reporting to decision-making.

Reacties

0

Wees de eerste die een reactie plaatst

Meld je nu aan en word lid van de Risk is Our Business community!

Probeer gratis

Probeer 14 dagen gratis

€ 9,99 / maand na proefperiode. · Elk moment opzegbaar.

  • Podcasts die je alleen op Podimo hoort
  • 20 uur luisterboeken / maand
  • Gratis podcasts

Alle afleveringen

59 afleveringen

aflevering Conducting Resilience: Beyond Compliance and Into Action with Aurore Chatard artwork

Conducting Resilience: Beyond Compliance and Into Action with Aurore Chatard

Recorded live at Risk-!n Conference 2026, this episode of Risk Is Our Business features Aurore Chatard in a conversation about what it truly takes to build resilience in an increasingly complex and interconnected world. Captain Michael Rasmussen and Aurore begin by discussing what keeps resilience leaders awake at night and why many organizations still struggle to move beyond a compliance-driven view of continuity and resilience. They unpack what bad resilience looks like, including programs that exist primarily to satisfy regulatory requirements, before exploring the characteristics of organizations that are genuinely prepared to adapt, respond, and recover. A central theme of the discussion is orchestration. Michael and Aurore compare resilience to a symphony orchestra, where success depends not on individual performers but on how well people, processes, technologies, and leadership work together. Without coordination, even the most capable functions can fail when disruption strikes. The conversation also explores the growing influence of regulations such as NIST and DORA, examining whether they help organizations become more resilient or risk turning resilience into another compliance exercise. Along the way, Aurore shares lessons learned from years spent leading security, continuity, and crisis management programs, offering practical insights for professionals looking to strengthen resilience capabilities within their own organizations. They close by reflecting on Risk-!n Conference 2026 itself, discussing the growth of the event, the conversations shaping the future of the profession, and the increasing recognition that resilience is becoming a core business capability rather than a specialist discipline.

Gisteren11 min
aflevering Shaking the Prime Directive: Rethinking Risk from the Ground Up with Adrian Clements artwork

Shaking the Prime Directive: Rethinking Risk from the Ground Up with Adrian Clements

Recorded live at Risk-!n Conference 2026, this episode of Risk Is Our Business begins with a warning from Adrian Clements. Before agreeing to come aboard, he made it clear that he intended to "shake the tree." Captain Michael Rasmussen's response was simple: engage. What follows is a conversation that challenges some of the profession's most deeply held assumptions. Adrian argues that many organizations are still navigating with outdated star charts, relying on inherited frameworks and conventional wisdom that no longer match the realities of today's environment. Rather than tweaking existing approaches, he makes the case for stepping back, questioning first principles, and rebuilding from the ground up. They explore what that looks like in practice. How do organizations break free from legacy thinking? How do leaders create the conditions for better decision-making? And what practical steps can be taken to transform risk from a compliance exercise into a driver of performance and value creation? The discussion also examines the role of technology. Not as the destination, but as an enabler that helps organizations operationalize better thinking, improve visibility, and support more intelligent decisions. Along the way, Adrian and Michael reflect on their key takeaways from Risk-!n Conference 2026, discussing the ideas and trends that suggest the profession may be entering a new phase of evolution.

1 jun 202625 min
aflevering The Speed of Risk: Controls and Decision-Making with Hermann Suter artwork

The Speed of Risk: Controls and Decision-Making with Hermann Suter

Recorded live at the Risk-!n Conference 2026, this episode of Risk Is Our Business features Hermann Suter, Head of Group Enterprise Risk Management at Barry Callebaut Group, in a conversation on how risk management must evolve in an environment where the speed of change is accelerating faster than many organizations can absorb. Hermann and Captain Michael Rasmussen begin with a deceptively simple question. If organizations claim to have an enterprise-wide view of risk, shouldn’t they also have an enterprise-wide view of controls? From there, the discussion turns to what actually keeps risk leaders awake at night. Not just specific threats, but the sheer pace and velocity of risk itself. They unpack what bad risk and control management looks like. In contrast, they argue that effective risk management starts with understanding that every meaningful decision already contains a form of risk analysis, whether organizations recognize it or not. The conversation also explores how to align risk with business culture rather than impose it from the outside, how Swiss and broader European perspectives influence approaches to governance and controls, and where technology is genuinely helping modern ERM programs. They close by discussing what excited them most at the conference itself, including the growing focus on interconnected risk, operational resilience, and the future direction of enterprise risk management.

26 mei 202618 min
aflevering The Extended Enterprise: Third-Party Risk at Warp Scale with Darren Smith artwork

The Extended Enterprise: Third-Party Risk at Warp Scale with Darren Smith

In this episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Darren Smith for a deep dive into third-party risk management in the age of the extended enterprise. The conversation explores how modern organizations now operate through vast and increasingly interconnected networks of suppliers, partners, outsourcers, and service providers, creating a web of dependencies that stretches far beyond traditional organizational boundaries. Darren explains why TPRM can no longer sit within a single function, and how procurement, security, compliance, legal, operations, sustainability, and business leadership all play critical roles in managing third-party exposure. They also unpack what separates bad TPRM (fragmented, compliance-driven, reactive) from good TPRM that is integrated, collaborative, and aligned with business objectives. They also examine how organizations define “critical suppliers,” why that definition is often more complex than it appears, and how businesses can better coordinate across departments to create a unified view of third-party risk. The discussion then turns to technology and AI. Darren shares his perspective on where current TPRM tooling adds value, where maturity is still lacking, and how organizations can move beyond treating TPRM as a checkbox exercise toward something more strategic and forward-looking. This episode is about managing risk in a world where the enterprise no longer ends at the company boundary and where resilience depends on understanding the entire ecosystem connected to the ship.

19 mei 202619 min
aflevering From Controls to Clarity: Aligning Risk and Control Across the Enterprise with Kristina Wiese Tranberg, Karoline Corfitz & Morten Bjerregaard artwork

From Controls to Clarity: Aligning Risk and Control Across the Enterprise with Kristina Wiese Tranberg, Karoline Corfitz & Morten Bjerregaard

In this return episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Kristina Wiese Tranberg back to the bridge, joined by Karoline Corfitz and Morten Bjerregaard, for a practical deep dive into internal controls and their role in modern GRC. Building on Kristina’s previous appearance, the conversation shifts from operating models and transformation to a core question of what is the real value of controls? The group explores how organizations can move beyond checkbox compliance toward control optimization that supports business outcomes rather than slowing them down. They also challenge a common disconnect. Many organizations aim for an enterprise-wide view of risk, but lack an enterprise view of controls. Without understanding how controls operate across processes and functions, can risk truly be understood at scale? The discussion then examines the relationship between risk owners and control owners, and when they should be the same, when they should be different, and how that choice affects accountability and effectiveness. They also unpack the 1-10-100 rule, illustrating how the cost of fixing issues escalates the later they are detected, and why embedding controls early in processes is critical. This episode offers a grounded, experience-led perspective on aligning risk, controls, and ownership across the enterprise.

4 mei 202628 min