After 35 years of hands on experience in the financial services sector, having held the post of Vice President, Corporate Security Risk Management for MasterCard, Richard Butcher established Cyber Security Risk Solutions Limited as a means of helping businesses across all sectors develop their use and understanding of quantitative risk assessment and measurement in their IT security space.
Having been a principle exponent and advocate of the FAIR methodology in VocaLink, he brought measurable, defined controls into place which enabled an accurate measurement of the risk posture of the business and the use of financially based risk assessments responding to changing threat profiles and vulnerabilities. Following the acquisition of Vocalink by Mastercard, the global business recognised the need for review and improvement in its risk management space which led to a further development of these processes.
Richard has held analysis roles throughout his business career, working within UK national and US international banks and financial institutions, understanding the challenges faced in driving change and gaining acceptance of new working methods in often very traditional environments. As a passionate advocate of the quantitative approach to risk management, whether that be using frameworks such as NIST, COBIT or ISO, the common thread running through them all is the need for an effective control set which reflects the assets requiring protection and the threats posed to them.
Whilst many technologies claim to have simple answers to these challenges, it is often the absence of a clear understanding of what is under threat, from whom, how, where from and exactly how is that measured and reported on using easy to understand mechanisms which eludes senior and executive management. Being able to use repeatable measurement techniques to validate the design and operational effectiveness of those controls is key to success.
Cyber Security Risk Solutions Limited can help bring that focus and clarity, as well as helping create and manage the risk taxonomies, processes, systems and reporting necessary to focus development and spending in the most effective way.
Call us today to find out how we can help you.