Cyber Supply Chain Risk Management – Should Penetration Testing be Required?

Let us begin by describing how to approach Cyber Supply Chain Risk Management (C-SCRM) and the risks your vendors pose to you. Then we will discuss if you should require them to show evidence that penetration testing was conducted and what remediations were taken. C-SCRM in a nutshell For simplicity let us split suppliers into […]

Shut Down the 5 Deadliest Web Application Attack Vectors

Web Application Attack Vectors

additionally,  Last update: 25 January 2022 Web applications are an essential component of any modern business. They can help convey the company vision, advertise services and deliver content to customers. Regardless of their use, they are a necessity to make oneself or a business known to the world. However, as beneficial as they can be […]

Conducting DPIAs: The Key to Unlocking Data Protection Compliance Webinar

Conducting DPIAs: The Key to Unlocking Data Protection Compliance -risk crew

Why else should you attend the webinar? You’ll not only receive expert insight into triggers and mistakes to avoid but will have the opportunity to ask your pressing questions surrounding the DPIA tool – which is the key to DPA and GDPR compliance. What else will be covered on DPIAs?   The 4 objectives for […]

3 Triggers for Conducting a DPIA

Here’s a funny thing – recital 84 of the EU’s GDPR legislation states “…where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible for the carrying-out of a data protection impact assessment…”. Paragraph 1 of Article 35 says pretty much the […]

What KPIs Should be Tracked for Security Penetration Testing?

security testing kpis

Cyber security is a journey and not just a destination. In the ever-changing security landscape, regular testing and mitigation are required. To prevent testing efforts from feeling like a sinkhole in time and funding, KPIs can be used to track the output of testing to show progress and motivate internal teams to improve their practices. […]

Risk & Compliance Predictions for 2021: A Not to Miss Webinar

If change is the only constant in cyber security, then what will the year ahead of us bring? How can we prepare for ever-evolving threats?   Register for the webinar: Risk & Compliance Predictions for 2021 The session will cover: The challenges of greater enforcement Ransomware and the next generation of threat vectors What boards […]

Risk Crew