Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by William D. Reed. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by William D. Reed or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Applying IRMBOK to Risk Management

53:03
 
Share
 

Manage episode 486674023 series 3494381
Content provided by William D. Reed. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by William D. Reed or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

In this episode of The Smart IT podcast, I welcomed Jeff Lowder, a seasoned risk professional and author of the upcoming Information Risk Management Body of Knowledge (IRMBOK), to the show. The conversation centered on how risk management professionals must evolve beyond traditional roles to become strategic partners in decision-making. Modern IT demands a deeper understanding of business objectives, as technology is not just about infrastructure—it’s about enabling organizations to thrive while managing risk effectively.

Jeff reviewed IRMBOK, a comprehensive guide for information risk management, covering both process frameworks and practical techniques. It covers a lot of intuitive and useful tools that risk practitioners can utilize in their work.

A major theme of the episode is the inadequacy of conventional risk methods—such as high/medium/low risk matrices—and the push toward quantitative approaches.

Many cybersecurity professionals are trained to focus only on downside risk, but real-world decision-making involves balancing both risks and opportunities. This broader perspective, which Jeff calls "decision management," leads to better alignment with how executives and boards think and make choices.

He emphasized the need for upskilling in quantitative risk analysis, stating that most of the required math is basic and accessible. He advocated for a more rigorous, business-aligned, and outcome-focused approach to IT and cybersecurity risk management, underlining that better decisions—not just compliance—should be the end goal.

“Risk management is about helping the business make better decisions—not just saying no.” - Jeff Lowder

Link to this episode: https://youtu.be/SRrvluPLuls

#SmartIT #IRMBOK #RiskManagment #CRQ #DecisionManagement #DecisionScience #CyberRisk #SiRA #SiRACon #SiRAcon25

Production: Brilliant Beam Media Syya Yasotornrat

Show Notes


  continue reading

35 episodes

Artwork
iconShare
 
Manage episode 486674023 series 3494381
Content provided by William D. Reed. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by William D. Reed or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

In this episode of The Smart IT podcast, I welcomed Jeff Lowder, a seasoned risk professional and author of the upcoming Information Risk Management Body of Knowledge (IRMBOK), to the show. The conversation centered on how risk management professionals must evolve beyond traditional roles to become strategic partners in decision-making. Modern IT demands a deeper understanding of business objectives, as technology is not just about infrastructure—it’s about enabling organizations to thrive while managing risk effectively.

Jeff reviewed IRMBOK, a comprehensive guide for information risk management, covering both process frameworks and practical techniques. It covers a lot of intuitive and useful tools that risk practitioners can utilize in their work.

A major theme of the episode is the inadequacy of conventional risk methods—such as high/medium/low risk matrices—and the push toward quantitative approaches.

Many cybersecurity professionals are trained to focus only on downside risk, but real-world decision-making involves balancing both risks and opportunities. This broader perspective, which Jeff calls "decision management," leads to better alignment with how executives and boards think and make choices.

He emphasized the need for upskilling in quantitative risk analysis, stating that most of the required math is basic and accessible. He advocated for a more rigorous, business-aligned, and outcome-focused approach to IT and cybersecurity risk management, underlining that better decisions—not just compliance—should be the end goal.

“Risk management is about helping the business make better decisions—not just saying no.” - Jeff Lowder

Link to this episode: https://youtu.be/SRrvluPLuls

#SmartIT #IRMBOK #RiskManagment #CRQ #DecisionManagement #DecisionScience #CyberRisk #SiRA #SiRACon #SiRAcon25

Production: Brilliant Beam Media Syya Yasotornrat

Show Notes


  continue reading

35 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play