Mar 23Four non-financial takeaways from the current bank flameouts 🔥Everyone (well, every risk and crisis manager) can learn something from what’s happening with the banks right now. Here are four things I think are worth reflecting on. 1 — There are two kinds of risk management and both matter. One is compliance / audit centric and looks at how things match up to the relevant regulations and standards. The other is…Risk Management2 min readRisk Management2 min read
Mar 6How Often Should You Train Your Crisis Management Team?Last week, there was a great discussion on the frequency of crisis management exercises in a forum I’m part of. What was most surprising to me was the degree of consensus on the ideal tempo. Most folks aim for: - Quarterly low-intensity tabletops focused on skills development and team cohesion. - Annual high-intensity simulations to reinforce learning and test teams and systems in a realistic environment.1 min read1 min read
Mar 2Four Ways to Make Sure your Risk Metrics WorkRisk metrics seem to be getting a bad rap these days. Too subjective. Too easy to manipulate. Too simplistic. And sometimes, all of these can be true, but using metrics and numeric scales can be highly effective. …Risk2 min readRisk2 min read
Published inKISS_risk·Apr 1, 202110 Considerations for New Risk ManagersI received an email a few years ago from someone just getting started in risk management asking if I had any thoughts or advice on the risk management skills they needed. The response quickly became several pages long and I thought it was worth turning it into a blog piece…Risk11 min readRisk11 min read
Published inKISS_risk·Mar 7, 2021Becoming a risk managerBecoming a risk manager can seem to be more art than science. There’s not a clear pathway from degree to junior risk manager to senior risk manager to CRO (Chief Risk Officer) in the same way that you can chart the progress from freshly minted CPA (Certified Public Accountant) to…Risk9 min readRisk9 min read
Feb 28, 2021Using blockchain to validate records in DCDRSecurity is a guiding principle for DCDR, and protecting user data has been baked in from the start. However, there’s more to data security than restricting access and managing user permissions. I’ve used the INFOSEC abbreviation CIA — confidentiality, integrity, and availability — as a guide to help determine the…Risk Management6 min readRisk Management6 min read
Published inKISS_risk·Feb 28, 2021What is a risk manager?Googling ‘what is a risk manager?’ will get you variations on ‘it’s the person who manages that organization’s risks,’ which is a pretty weak answer. It’s certainly not enough to help anyone who’s just starting in the role to understand what they’re supposed to do. …Risk6 min readRisk6 min read
Published inKISS_risk·Jan 11, 202180 / 20 your risk managementThis is a very short post which should work because it’s a very simple idea. Obviously, I’m a fan of simple ( this is KISS risk management after all) but, as with lots of simple ideas, the trick is sticking to the idea and seeing it through without getting distracted. …Risk3 min readRisk3 min read
Published inKISS_risk·Nov 16, 2020When risks become eventsHow can you spot the point where a risk — a thing that could occur — becomes an event that is occurring? I’d argue that you don’t need to identify the specific point of change, and you’ll waste valuable time trying to spot the exact moment of transition. …Risk5 min readRisk5 min read
Published inKISS_risk·Nov 11, 2020Risk, Emergencies, Crisis & DisastersSeven takeaways from reviewing my degree notes. — I looked back at some of my degree notes the other day and came across something I’ve been meaning to work on for a long time. (By long time, I mean about 10 years*.) It’s based on two concepts. First, the work that Brian Toft, Simon Reynolds and Barry Turner…Risk2 min readRisk2 min read