A practical guide to risk quantification: what it is, why to quantify by scenario rather than risk by risk, how Monte Carlo simulation works (VaR, TVaR, loss tail), and how to get started without perfect data.
Latest news and updates
Automation of the model of the 3 lines of defense
Three lines of defense: risk and audit Each organization, on a daily basis, carries out an evaluation process, often unconsciously, of risks to which it is exposed, and which can…
ISO 22316. Organizational resilience
Resilience in organizations ISO 22316 Published in 2017, this standard sets out principles, attributes and activities that an organization must consider in order to maintain and enhance its resilience. Organizational…
keys to implementing a BCP and DRP (Business Continuity Plan – Disaster Recovery Plan)
Introduction In recent times, organizations have become increasingly concerned about incidents that could jeopardize their business. Events as shocking as attacks, large-scale cyberattacks or pandemics are no longer considered implausible…
10 Tips for establishing policies for Internet use
Purpose of an Internet usage policy is to define what is allowed or not when using network and establish Internet connections, so that company workers and collaborators can carry out…
What is a Statement of Applicability, SOA? and, How useful is it?
What is SoA, Statement of Applicability? Statement of Applicability (SoA) of standard ISO 27001, of Information Security Management System (ISMS), is a document formed by the complete list of the…
What is BIA? What is its importance in Business Continuity?
What is Business Impact Analysis (BIA)? BIA’s acronym refers to Business Impact Analysis A BIA is carried out within the activities of a Business Continuity Management System (BCMS). Its formal…
What is COSO’s model? How do we manage risk?
WHAT IS COSO’s model? COSO (Committee of Sponsoring Organizations of the Treadway Commission) is an organization made up of private organizations, established in the USA, dedicated to providing a common…
The figure of the Data Controller and Data Processor in the GDPR
Data Controller vs Data Processor The General Data Protection Regulation (GDPR) has brought about the creation of two new concepts: Data Controller and Data Processor. These figures already had their…
What is it and how to develop a Record of Processing Activities, risk analysis and impact assessment?
Records of Processing Activities, risk analysis and GDPR impact assessment The entry into force of both the General Data Protection Regulation (GDPR), as well as the Organic Law on the…
What is and how to develop a compliance risk assessment?
Compliance risk maps. how to develop a compliance risk assessment? From the perspective of the Compliance function, it must be identified the situations or processes in which breaches of legal,…
What is risk appetite?
Risk appetite. Risk apetite. Corporate Risk management Within the risk management of a company, the need arises to establish the risk appetite that will decisively influence the achievement of the…
Crisis management and business continuity in the face of a pandemic
The appearance of the coronavirus puts Spanish companies in check On March 11, World Health Organization raised the public health emergency situation caused by the COVID-19virus to the level…
Protecting personal data in the coronavirus crisis
From the beginning of the Coronavirus crisis (COVID-19)different customers of the company consulted us if they could take the temperature of employees and visits to prevent possible contagion and access…
ISO 27018. Security and Protection of Personal Information in the Cloud
In recent years technology has advanced exponentially, as is the case of storage in cloud which offers multiple benefits related to speed of access to information from any point with…
What are ISO standards?
¿What is the fundamental objective of ISO standards? ISO Standards are a set of internationally recognized standards that were created with the aim of helping companies to establish levels of…
















