Does anyone have experience with cyber risk quantification tools like balbix, safe security? I run risk management at my company. Is it comprehensive enough for risk identification etc?

like
Posting as :
works at
You are currently posting as works at

Superb, we have rapid7 and would be looking to move to tenable one. We use Nist CSF and winging it method today lol. We have a risk register tho

like

Are you already following any specific risk management frameworks?

Also what are you using for vulnerability management? And ballpark annual spend for that / general info security?

We’re not using any crq right now (can’t even get people to identify a critical system) but:

Your existing VM platform may already have this built in or as an add on. You’ll also want a tool that maps to or integrates the RMF you’re using g, at least to get good value. But also they’re not cheap.

We’ve got tenable and I’d looked at tenable one for this. Rapid7 may have it buried in their overall tooling but I can’t find anything by name. Our siem and xdr tooling (elastic, Microsoft ) also has some of this functionality

We’re using top down CRQ tools to quantify value at risk and some risk impact scenarios. The models are based on peer firmographics and historical cyber loss data mostly from insurance. Gives us some good value for board reporting and discussions with cyber insurance providers

Related Posts

Anybody have thoughts on Troutman Pepper’s Consumer Financial Services practice group? SoCal particularly.

like

Arnold & Porter Not matching Cravath. What is happening? Do we think they’ve decided not to match or is this just a hiccup? Do we expect more firms even in the V50 to not match?

like

Saw this on LI. What do you guys think about this guys rant and his reason for disqualifying applicants?

Post Photo
like

ZS or Synechron?
Both offering same package
But I think learning curve will be more in ZS.
Tech Stack: ETL dev
YOE: 4.4

like

Has anyone here gotten a job through FB or, if you’re a hiring atty, recruited a good candidate?

like

I am new to United Silver and I purchase economy tickets. Is the best strategy to check in exactly 24 hours ahead and switch my seat to an open economy plus seat?

like

I’m F traveling to Delhi for the first time with another F friend. I would like to tour Delhi and Agra over 3 days. Looking for personalized services as I’m interested in visiting specific spots in Delhi. Appreciate any tour services recommendations. (Safety is our biggest concern.)

like

I will be joining BGSW CoB location in Jan. I have 6.5 years of experience and offered L51 - Senior Associate consultant role. Is this correct role for my experience?

like

My work quality is slipping due to brain fog and mental health issues and I don’t know how to address it with my firm or who to go to. I was considered one of the best associates in our practice group, but now it can take me 3-4x the time to write an average brief. I can’t seem to think and organize my thoughts any more. This is incredibly scary bc obvi, that’s what this job is all about. I’m in IP litigation at a V50 firm and a mom. Do I raise it with partners and how?

like

I have been in my current job for 1 year now as a booking coordinator for a logistics company. When I started I had no idea of what my workload would be, now I noticed that my coworkers took the opportunity to pass most of their job to me. I’m burned out, can barely take break and end my days totally drained and exhausted, also the same people is harassing me with questions like: “why are you working that slow?” Or the “quality of your job is questionable because…..” continue in comments

Haven’t practiced a single Sim for REG and test in 4 days...am I screwed?

Hi everyone! What remote jobs are you working that you feel is good for your ADHD?

like

Hello there audit folks! Anybody considering a shift to financial due diligence? Happy to discuss opportunities at EY, please DM me if interested. We are really looking for folks with healthcare or tech experience and can move extremely quickly during the interview process. I've been in the group for years and transitioned as a senior so can share the positives and negatives.

like

Curious to hear from the community, what is the best sales approach for enteprise? MEDDICC, MEDDPICC, Challenger Sale, Command of the message etc. Also, what approach do the major tech companies train their sales team on?

like

Please help me with 11likes! 🙃

like

Any thoughts on BNP M&A in nyc

like

Hi everyone! I have an interview with Morgan Stanley next week in their private WM division. Any advice? Anything I should know going in?

like

Been trying to find a new job because $112k just doesn't seem right for 3+ years as an Eng 3. On the east coast wanting to move out to California. Not getting many bites. Do employers ignore applications for people who would need to relocate?

likefunny

Anyone on a statin (eg Crestor)? I’m 40/m and had elevated cholesterol last checkup. Rx Crestor and second opinion concurred. I’m still hesitant to start. I exercise, eat pretty well, don’t smoke, use alcohol. Asking for experiences not medical advice. Thanks!

like

Is AAS a good area to gain transferable skills and learn a lot? Comparing to audit.

Additional Posts in Cyber Security Bowl

What does a senior cyber consultant make at EY or other b4 firms Chicago if that makes a difference

like

Hey Cyber friends! I’m a life long professional creative looking to get out. I’m fascinated by Cybersec/Infosec and have been learning a small amount. Tryhackme + YouTube + beginning to learn some python. However, I’m well aware that these baby steps don’t compare to the real job.

My questions: do you like what you do? Would you recommend the field or your discipline to a friend? What is the best and worst part of your job? Grateful for any and all responses. Thanks for letting me lurk! 🙏🏻🙏🏻

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Can any Deloitte Cyber folks provide data on their recently increased compensation? Are you happy with the increase?

like

How much does Deloitte pay for cybersecurity or devops senior Deloitte roles

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

What’s a good taxonomy for defining requirements for logging & monitoring? (i.e., apps, db, infra, etc.)

likefunny

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

CCSP (cloud security certification) is it worth to do ?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

How to make a jump to cloud security when I just have SOC experience? Currently studying for Solutions Architect cert

like

As more and more companies institute a work from home policy, I think it will gradually become the norm. As a 28 year old man who wants to settle down soon, which city would you recommend I look into, assuming me and my partner can work from home? I work in Cybersecurity so would prefer to be closer to the jobs in my field without having to live in the same city.

like

I have a younger family member (almost 13) who is very interested in cybersecurity. How can this person learn and grow in a safe manner if he/she isn’t near a city with youth clubs and etc? Idea is to reinforce ethics, but this material is far too advanced for the parents.

like

Anyone in a FAANG looking for a cyber manager. DM me please! (Generalist - Focus on governance, compliance, risk and strategy)

like

Any tips or tricks for CSX certification?

like

I have interviews coming up with BCG. Any BCG Platinion folks willing to discuss example case interview questions?

like

Tell me it’s not true.

Post Photo
funnylike

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal