A practical guide to risk quantification: what it is, why to quantify by scenario rather than risk by risk, how Monte Carlo simulation works (VaR, TVaR, loss tail), and how to get started without perfect data.
Latest news and updates
ISO 31000: The standard that helps you manage risks
In an increasingly complex and competitive business world, risk management has become a key component for the success and sustainability of any organization. The International Organization for Standardization (ISO) provides…
What is the ISO 22301 standard and what is it for?
The ISO 22301 standard is an international standard that establishes the requirements for business continuity management systems. It was published by the International Organization for Standardization (ISO) in May 2012…
Cybersecurity and Ethical Hacking: how to Keep My Company Protected?
Cybercrime is a very lucrative and constantly expanding business. Each year there is an increase in the number of attacks targeting companies, according to CCN-CERT statistics, ransomware attacks increased dramatically…
ISO 27001: What are the main controls of this standard?
ISO 27001 is an international standard developed by the International Organization for Standardization (ISO) with the aim of providing a model for Information Security Management within organizations. The first version…
What is the MITRE ATT&CK framework? What is it used for?
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is a dynamic tool used by organizations to understand and mitigate cybersecurity threats. This framework provides a common language for…
What is GRC? Governance, risk and compliance
Risk management, compliance, and governance are key elements for the success of any organization. Although separate tools have been used to manage each of these aspects, an integrated solution known…
What is the ISO 27001 standard and what is its purpose?
Introduction to ISO 27001 standard The ISO 27001 standard is an international standard that establishes the requirements for the implementation, maintenance, and continuous improvement of an Information Security Management System…
DORA Cybersecurity Regulation
What is DORA? The Digital Operational Resilience Act (DORA) is a regulation of the European Union designed to establish a unified framework that standardizes how financial entities should manage digital…
NIS2: Directive on Cybersecurity Measures Published
The NIS2 DirectiveDirective (EU) 2022/2555 (standing for Network and Information Security), establishes an information security framework to ensure the protection of information systems and networks within the European Union, with…
New Version ISO 27001:2022
The Evolution of the ISO 27001 Standard Currently, there is an undeniable need to implement effective cybersecurity measures in organizations due to the growing trend of security attacks. Therefore, companies…
What is a whistleblowing channel? Who is it for?
Following the publication, in the Official Journal of the European Union of 26 November 2019, of the new Directive (EU) 2019/1937 of the European Parliament and of the Council of…
Benefits of applying a cybersecurity risk management system
Key Advantages of Risk Management Systems Having a risk management system in place is a wise decision that every organization, regardless of its size, nature, or professional sector, should make.…
The New Surveys Module of GlobalSuite® Comes to Light
Collect information, manage your processes, identify and assess your risks, monitor and demonstrate the maturity of your controls with our renovated surveys module We believe that the use of surveys…
Keys to optimize the management of our GRC system
Why is it important to optimize GRC system management in the company? The GRC strategy of companies is implemented to work effectively and efficiently with a unique methodology for the…
Do You Know the Risks of Working on Public Wi-Fi Networks?
The recent rise of remote working has brought us great advantages, such as savings on transport costs or greater ease in balancing family and work life. However, it has indirectly…
















