Shared Assessments' Insurance Vertical Strategy Group came together for its quarterly meeting last week. Conversation was engaging and covered the widening scope of assessments, the multitude of third party types and the need for re-risking vendors in light of the...
Information Security
Guide to Cybersecurity: Information Security Needs a New Narrative
Many companies have a fundamental information security problem, according to the co-authors of the A Leader’s Guide to Cybersecurity (Harvard Business Review Press, 2019). Those organizations pay too much attention to network and system vulnerabilities and too little...
2020 Information Security and Data Privacy Perspectives: 5 Not-So-Pretty Predictions
When we asked Santa Fe Group Vice President and CISO Tom Garrubba to gaze into his crystal ball last month, he identified several events related to Third Party Risk Management that he thinks may materialize this year, including: Privacy breaches (those caused...
Holistic Information Security – People, Process and Technology
The attention to People and Process is lagging far behind In reviewing the recent plethora of data breach stories, I am beginning to see a pattern here. While many companies answer to breaches with more and more technology, it appears that they are ignoring...
The NSA, Snowden and Third-Party Risk: Preliminary Lessons Learned
Remember this: Edward Snowden Worked for a Third-Party Vendor. While it remains uncertain what exactly Mr. Snowden shared with other nations, we do know this: he wasn’t authorized to disclose classified information. Some may believe he is a hero, others believe he is...
Information Security in the Financial Industry. More Regulation or Better Regulation
Santa Fe Group Consultant and Shared Assessments Program Director, Brad Keller, was recently interviewed by John DiMaria, Product Marketing Manager, BSI Management Systems. Brad, along with members from BITS and the Financial Services Roundtable, share their...