Demystifying cyber risk in the age of AI
Demystifying cyber risk in the age of AI
Managing cyber risk without a specialist team
If you are an executive or board member of an organisation that does not have a specialist cyber team, tackling cyber risk in a practical yet appropriate way might seem out of reach. With each day bringing news about increased AI threats, particularly with respect to information security, it can seem overwhelming and difficult to manage risk. To respond to this, Steve Brown, a 30-year respected veteran of the Australian information technology and security community and KSIB’s head of technology, AI and cyber, has created a comprehensive, practical guide to help CEO’s, directors and business executives, along with IT teams, manage cyber risk in the age of AI.
The guide incorporates all the important requirements of the various cyber and information security checklists and frameworks that exist and distils these into an easy-to-navigate, actionable plan.
The real value, however, is not simply the guide alone. It is the applied judgement of a seasoned global CISO that defines material harm, sets a defensible risk appetite and prioritises risk scenarios. This enables executives and boards to answer, with evidence, four questions:
- What are the cyber events that could seriously harm us?
- How much of that risk are we choosing to carry?
- What are we doing about the risk we are not willing to carry?
- How do we know it is working?
How the guide works
The first 3 chapters of the guide focus on defining risks, setting context and providing an introduction. The remaining 12 chapters (each on a digestible step in the process) help you act.
In summary:
First establish what the organisation must protect. Cyber risk only matters insofar as it threatens important business outcomes.
The impact scale pins down, in concrete terms, what Limited, Major and Severe harm to each outcome look like. Without this, every later conversation about “high risk” means something different to each person in the room.
Risk appetite is the board saying, for each kind and level of harm, how much likelihood it will live with. Because it is expressed on the impact scale, it is checkable later.
The asset register is built by walking from each outcome down to the systems, data, suppliers and people it rests on. An asset’s importance is derived from the harm its failure could cause.
The threat profile is a short list of attacker and hazard types relevant to the sector – drawn from published threat reporting.
Scenarios are the working unit of risk in this method: “this class of threat, acting on these assets, causes this level of harm to this outcome, about this often.” Each scenario is then rated for impact and likelihood, and its position against appetite is derived by comparing those ratings with the appetite table.
The controls library starts from a universal baseline every organisation needs regardless of analysis, then works scenario by scenario: for each risk sitting outside appetite, choose treatments that bring it inside, and records the reasoning.
Metrics prove controls are present and effective. The board pack puts scenarios, appetite positions, treatment progress and metrics on one page.
Set the review loop: an annual re-walk of the whole chain, quarterly board reporting, and defined events – an incident, a new system, a new obligation – that reopen specific steps out of cycle. The review loop is the method’s continual-improvement mechanism: the artefacts are living documents, and reality (incidents, metrics, audit findings) feeds back into the ratings.
THE YARDSTICK
What harm means, and how much is tolerated
Context and triggers
Scope, obligations, and the nine conditions that add rigour
Outcomes
The four to six things that must hold for the organisation to survive
Impact scale
Limited, Major and Severe harm written out per outcome
Risk appetite
The board’s tolerated likelihood for each level of harm
THE RISK
What could happen, how bad, how often
Threat profile
The actors and hazards relevant here
Asset register
What the outcomes depend on, and the zones they sit in
Scenario register
Threats acting on assets, harming an outcome
Ratings and positions
How bad, how often, and inside or outside appetite
MANAGING IT
What we do, whether it works, who decides
Controls and treatments
A baseline for everyone, plus a package per scenario outside appetite
Metrics and control health
Whether the controls are present, working, and closing the gap
Board pack
Assembled by selection from a small set of the earlier steps
Review loop
The annual pass, the events that reopen, the decisions that expire
CONFIRM OR REOPEN, ANNUALLY AND ON EVENTS
The method, end to end: the yardstick, the risk, and managing it.
To discuss how to obtain a high level strategic assessment of your needs and access to the detailed guide, contact us at www.ksib.com.au or email Kristin or Steve directly at kristin@ksib.com.au or steve@ksib.com.au. We work with you and your team to help you manage this risk in the most practical way possible. Our work ranges from initial assessments and strategic direction through to hands-on support where needed.
Liability limited by a scheme approved under Professional Standards Legislation.

