Presenter: J. Wolfgang Goerlich
Topic: Risk Management's Last Mile

While risk management is an excellent way to prioritize security efforts, it has proven a poor way to change behaviors in the workplace. The common line of thinking says companies are in the business of taking risks. Risk is the language of the business, and therefore using risk management we can communicate security concepts to the business. This has proven to not be the case in cyber security.

It shouldn’t surprise us. Communicating risks hasn’t worked well in other fields either: from workplace safety to drivers safety, from child care to health care, people simply don’t respond to risk messages. It’s difficult to get psychological insight into how business people perceive and respond to GRC people. This session will pull on the body of research and place it within the context of an organization’s risk management program.

Presenter Bio: J. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. Prior to this role, he led IT and IT security in the healthcare and financial services verticals. Wolfgang has held VP positions at several consulting firms, leading advisory and assessment practices. He is an active part of the security community