ICT Risk Management

StrategyandGovernance

Develop strategies, policies, governance models and controls to manage the Risk Management

• Organizational and Technological model
• Framework and methodology
• Policies, Standards, Processes and Guidelines
• Maturity Assessment, Posture and Gap Analysis
• Training and Awareness
• Risk Management program and certification (e.g. ISO 31000, etc.)

Risk Impact Assessment

Assess and evaluate risks and issues (in different business and specialized areas, or multidisciplinary context), also considering as-is and target scenario

• Information Risk management
• Risk taxonomy definition (e.g.quantitative, qualitative, etc.)
• Cyber Risk assessment
• Resilience Risk governance (ref. DORA, etc.)
• ICT Risk analysis (e.g.asset-based, vulnerability-based, etc.)

Threat Intelligence

Discover and assess as-is and future threats in order to improve the risks overview and knowledge base, enabling better decision making

• Vulnerability assessment
• Threat assessment (e.g. deep web investigation, etc.)
• Third Parties Risk management (e.g. contract management, etc.)
• Event Risk evaluation (e.g. threat-based, etc.)

Mitigation Management

Enable the risks management across the organization defining and addressing stable solutions and contingencies to ensure a risks exposure governance

• Contingencies evaluation
• Cost / benefit assessment
• Mitigation prioritizaitona and implementation monitoring