|
SMALL BUSINESS CYBERSECURITY Simple, Easy to Follow Help Certified Information Systems Security Professional |
| Home | Credentials | Coaching | Contact |
|
Clean Definitions What is CyberWhat is Risk What is a Threat What is a Framework What is the Cloud What is a CISO or BISO What is a decent Plan? What is AI? Resources
Measuring and Manageing Information Risk,
Authors: Jack Freund and Jack Jones
How to Measure Anything in Cybersecurity Risk
Authors: Douglas W. Hubbard and Richard Seiersen |
Who is Ron? I'm just an ordinary, average guy, who has worked for many different types of businesses, doing the actual work, and not only information security. That helps me help you find a balance. I have a very strong business acumen. I know where the money comes from that your business needs to survive, and I know that information security is an expense that we hope will save more of your business's hard earned money than it costs to make it secure in the end. In my time doing Information Security, I have found that polices, standards and specifications are often written in "Cyber-speak," phrases and acronyms that are hard to understand for even IT people. I can help explain it at whatever level you need, unless it's even over my head, and then we'll have to do some digging. I'm here to help you realize that quite often it's not worth the major fret that some cybersecurity people stoke up. Information security is meant to make your business better, not more painful to run. Cybersecurity folks should never pretend they are the police, here to arrest anyone for the slightest infraction. They are supposed to be like doctors and nurses, here to find problems, stop damage and offer possible solutions. You decide if you can afford the therapy, the prescriptions and if you want the side effects. What is my Information Technology Experience? I've been a data equipment reseller, a network admin, a network security engineer, and a risk analyst for over 25 year. I've worked for small and very large companies, including those in critical infrastructure, financial, healthcare and manufacturing, helping folks figure out just how secure they need to be without emptying their bank account. Now, after all the years doing that, I want to share my aquired knowledge to explain that not all businesses need to worry about their information security as much as others. They can be quite custom with the way they do things, and that's all totally cool with NIST CSF, the holy grail of cybersecurity for United States based businesses. If they need to be totally rock solid and allow nothing to get by, and they have the budget for that, that's fine. If they need a more measured approach, that's fine for them, too. Most people who talk to me enjoy the experience. I teach. I don't preach. I help. I don't ridicule. I keep things private. I also can help you with your documentation, which seems to be a skill in short supply, sometimes. Remember that if you don't write down your plans, your rules, your standards, your policies and procedures, they are only wishes. |
Testimonials
NULL at the moment. |
Please email ronald@weist.net to schedule an appointment to talk about your information (don't say cyber) security.