Implementing a Quantitative Cyber-Risk Framework: A FinSrv Case Study
Dr. Jack Freund, Director, Cyber Risk, TIAA This session will review the Cyber-Risk Framework implemented by TIAA that scales from the granular level up to business-level aggregate risk reporting, avoiding some typical pitfalls by avoiding being too narrow or broad. Included in this session will be discussions about policy, standards, configuration baselines, quantification, ORM/ERM risk reporting and project lifecycle engagement. Learning Objectives: 1: Sharing the successes and challenges of risk management tools and techniques. 2: Educating about the relationship between risk assessment and management action. 3: Equipping attendees with tools and techniques to take back and implement. https://www.rsaconference.com/videos/...

▶︎
10 Tenets of CISO Success

▶︎
Understanding Cybersecurity Risk Management

▶︎
Insights from NSA’s Cybersecurity Threat Operations Center

▶︎
Introduction with Risk Quantification and FAIR with Jack Jones

▶︎
From “No Data” to “Drowning in Data”—It’s Time for a Reality Check

▶︎
AJ Styles On Retirement, Gunther, Hall Of Fame, John Cena, One More Match?

▶︎
Chichvarkin Saves Putin | Vitaly Portnikov

▶︎
Hjalmar Schacht: The Untold Story of Hitler’s Economic Mastermind Documentary

▶︎
Cyber Risk Reporting to the Board: A Step by Step Playbook

▶︎
The Evolution of Cyber Risk Management and Cyber Risk Quantification

▶︎
How to Make Sense of Cybersecurity Frameworks

▶︎
Enterprise Risk Management, Cybersecurity Oversight and Cyber Risk's Future, with James Lam

▶︎
Basic Knowledge of NovaStar Control System

▶︎
An Overview of Risk Assessment According to ISO 27001 and ISO 27005

▶︎
How to Perform Effective OT Cyber Security Risk Assessments
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
▶︎
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

▶︎
Using NIST 800-161 to Meet Today’s Cybersecurity Supply Chain Risk Management Challenges

▶︎
A case study master class on Reporting Cyber Risk to the Board by Omar Khwaja

▶︎
"Unlock the Secret to Building the Perfect Risk Management Plan"

▶︎
