Full description not available
H**Z
A masterpiece
This is a masterpiece for those of us who are engineers. The author gives the tools to solve many difficult situations, where measuring is fundamental, as it is in risk management.
D**N
Required reading for security and risk professionals
The cybersecurity profession is rich in data and the boardroom is desperate for meaningful risk analysis, but our traditional ways of communicating risk doesn't use the data and favors vague phrases to communicate the message. This book aims to remedy this problem and does so masterfully.Many readers will need to un-learn some habits in order to embrace risk measurement, but the authors make a solid case for why the traditional qualitative risk register isn't adequate for the modern landscape. I personally had to read some sections more than once, which is a complement to the authors. Some of the best books I read involve some struggle and "How to Measure Anything in Cybersecurity Risk" is easily among the top ten books in this profession I've read.I'll further add that I'm not often a five star sort of reviewer, thinking often the truth lies in middle but this book is the exception to the rule. If you work in cybersecurity and want to improve your decision making ability this book is for you.
R**B
Transformative book
The bad reviews seem inorganic for this book. No comments for all but one bad review.This books was transformative for me and our organization. I read the original version in 2017 and am currently reading the updated version.The authors make the case for quantitative risk. The readers of the book may understand but it is really important that they can CONVINCE others that quantitative risk is much better than qualitative risk.The book then delves into how you can relatively easily use math to build quantitative models.Following "How to Measure Anything in Cybersecurity Risk" will lead to much better results and allow for even small organizations to use quantitative risk.
E**C
Concepts could be explained better
I think the book preaches a good method. However I found the explanations a bit dense and certain terminology could have been explained better. Having visual charts/graphs to explain would have made this easier to digest. I’d sometimes read a page regarding a specific statistical term or process multiple times and still not understanding it. A quick google search on that term always seems to clarify what I don’t understand instantly…. Which made me frustrated and wondering why the book didn’t do a better job.
P**Y
MUST HAVE for cyber risk managers
Think risk quantification is too hard? I promise it's not as hard as trying to figure out what to spend on a "high" risk. Even small improvements in your methods will reap huge rewards. Start here, you wont regret it!
W**.
espectacular
muy buen producto
S**N
Roadmap to quantifying security risk and justifying your security budget
Simple, actionable and invaluable resource for any CISO or product security Exec.
Trustpilot
1 day ago
1 week ago
3 weeks ago