A practical guide to risk quantification: what it is, why to quantify by scenario rather than risk by risk, how Monte Carlo simulation works (VaR, TVaR, loss tail), and how to get started without perfect data.
Latest news and updates
Main Differences between Internal and External Auditing
Objectives of Internal and External Auditing What is the importance of auditing an organization? Audits are part of business management and their main objective is to control the organization, promote…
Best Practices to Protect Your Digital Identity
The concept of a password was developed to help users control access to a resource they do not want to share, primarily information. Passwords are the main barrier that prevents…
Legal Compliance Software: What it is and how it Helps your Company
Legal compliance software is a program designed to manage the set of all ethical actions and practices implemented in an organization to detect and tackle legal risks. The ultimate goal…
PCI DSS Standard Update: What to Expect for Your Organization
The new PCI DSS v4.0 version was published on March 31, 2022, by the Payment Card Industry Data Security Standard. Organizations that process and handle credit card (CC) payments have…
What are Cyber Risks and What is Their Impact on Businesses
Definition of Cyber Risks. What are They? The globalized digital ecosystem in which we find ourselves has been evolving and developing disruptive technologies that have displaced traditional formats, creating new…
How to Manage Risk Maps: Criminal, Ethical and Business
Introduction and Current Trends in Integrated Risk Management Currently, companies are obliged to manage a wide variety of regulations, for example, those that involve compliance with legal regulations, others specific…
How can I improve my company’s cybersecurity strategy?
There are many factors and premises an organization must consider to define its cybersecurity strategy; however, the mere fact that an organization asks itself this question is already a sign…
Risk Map in your Company
There is no doubt that risk identification and assessment (with their risk maps) currently represents one of the unavoidable pillars of management in any company. In an increasingly globalized context…
The Main Changes in the ISO 27002:2022 Standard Update
On February 16, 2022, ISO (International Organization for Standardization) published the ISO 27002 update, a standard designed for use by organizations as a reference for selecting controls within the process…
What is Consent Management in Personal Data Processing?
One of the most significant changes in the General Data Protection Regulation (hereinafter, “GDPR”) is consent management. Specifically, consent is regulated in Art. 6 – lawfulness of processing -, in…
How to Reflect Qualifications in the Audit Report
The audit report is perhaps one of the most analyzed documents within an entity that, after a more or less long period of work on a management system, sees its…
Internal Audit of a Management System: Role of the Audit Team
Internal Audit of a Management System in Companies An internal audit is a process of verification and/or validation of compliance with an activity according to the plan and stipulated guidelines.…
GlobalSuite® for Compliance Management System Monitoring
In this white paper, we will see the benefits of this type of system and how GlobalSuite® helps organizations comply with the different international or national regulations to which they…
PDCA Cycle for ISO 27001 Management
Due to the growing need to implement effective cybersecurity measures in organizations as a result of numerous existing security attacks, the introduction of ISO standards in companies is a reality.…
Compliance Controls in an Audit
In the context of conducting audits of legal or regulatory management systems of any kind, it is vitally important to consider the compliance controls that have been previously identified to…
















