Open in app

Sign In

Write

Sign In

Ryan McGeehan
Ryan McGeehan

2.6K Followers

Home

About

Published in Starting Up Security

·6 days ago

Talking about risk with thresholds 🔥

Imagine you encounter a fire in the woods. You’d instinctively decide to do one of two things: Kick dirt on the fire. or… Call for help! Of course, this depends on the size of the fire. What size threshold changes how you’ll act? This essay is about openly acknowledging these…

Security

3 min read

Talking about risk with thresholds 🔥
Talking about risk with thresholds 🔥
Security

3 min read


Published in Starting Up Security

·Dec 8, 2022

A blameless post-mortem of USA v. Joseph Sullivan

Our industry deserves a complete retrospective into the incidents behind the criminal case against Uber’s former Chief Security Officer. We need more than opinions about an individual’s guilt. Those who have been around long enough know that positive change is most efficient with a clear and blameless retrospective (1, 2)…

Security

32 min read

A blameless post-mortem of USA v. Joseph Sullivan
A blameless post-mortem of USA v. Joseph Sullivan
Security

32 min read


Published in Starting Up Security

·Aug 24, 2022

Endpoint Security: Intuition around the Mudge Disclosures

The Mudge disclosures bring up specific pain points around how endpoint security is measured and communicated and what baselines are acceptable. This is a valuable launching point for discussing the intuition behind endpoint security overall for those of us growing security programs. The first is endpoint coverage. At issue for…

Mudge

7 min read

Endpoint Security: Intuition around the Mudge Disclosures
Endpoint Security: Intuition around the Mudge Disclosures
Mudge

7 min read


Nov 15, 2021

How to estimate legal costs from a data breach.

We need budget and headcount to mitigate risks. Larger risks should encourage more resources towards mitigation efforts. Legal costs are wild area of costs… along with costs to the business and regulatory risks. A better understanding of legal uncertainties will help encourage mitigations that avoid them. The legal costs following…

Security

10 min read

How to estimate legal costs from a data breach.
How to estimate legal costs from a data breach.
Security

10 min read


May 31, 2021

Troubles with quantified risk

Risk quantification can be confusing and derailing to groups and decision makers. The following points are areas of pain when working with quantitative models with others. These areas of friction cause bad experiences, and bad experiences change our approaches in the future. We’ll talk about the following topics: Security return-on-investment…

Risk

10 min read

Troubles with quantified risk
Troubles with quantified risk
Risk

10 min read


Nov 20, 2020

A risk decomposition walkthrough

This is a method I’ve used to help frame and model cybersecurity risks over the past few years. It helps organize a lot of complexity when dealing with a large organization. This method uses forecasts, scenarios, multiplication and addition. As all risk modeling goes, this has more to do with…

7 min read

A risk decomposition walkthrough
A risk decomposition walkthrough

7 min read


May 5, 2020

Risk and Performance Management

Risk measurement quickly raises questions about management…. but not about risk management. Rather, managing the performance of people who manage complex risks. My writing on risk measurement often gets attention from management roles. The management audience desires methods to manage the performance of defenders with risk based measurement. …

Risk

9 min read

Risk and Performance Management
Risk and Performance Management
Risk

9 min read


Apr 6, 2020

Hypothesis, Risk, and Science

My hope is that the cyber security community will develop as a risk science. Science starts with correctable claims. Progress towards more useful knowledge come from continuous corrections. However, a risk hypothesis may represent future events that have never previously happened, might not ever happen, or may not be observed…

Risk

11 min read

Hypothesis, Risk, and Science
Hypothesis, Risk, and Science
Risk

11 min read


Mar 18, 2020

Subjectivity, Risk, and Science

A topic described as subjective is often considered non-scientific. Risk, being a subjective topic, must certainly be one that science has a hand in. Can we pursue a science of risk with these limitations? An exploration of subjectivity and risk in a context of science forces us to confront the…

Science

7 min read

Science

7 min read


Mar 16, 2020

The value of risk organizations

How do we approximate the amount of resource we allocate for security? In this essay, we’ll cover some principles before the quant. Let’s start simple: What risks does the organization face? How might the security team reduce these risks? Were the associated costs worth the reduced risks? This approach might…

Risk Management

11 min read

The value of risk organizations
The value of risk organizations
Risk Management

11 min read

Ryan McGeehan

Ryan McGeehan

2.6K Followers

Writing about risk, security, and startups.

Following
  • Cassie Kozyrkov

    Cassie Kozyrkov

  • Sarah Fluchs

    Sarah Fluchs

  • Naomi Gleit

    Naomi Gleit

  • Matt Richard

    Matt Richard

  • Marcel Laverdet

    Marcel Laverdet

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech