No. 73: Stop Managing Risk in Cybersecurity
Stop managing risk! It doesn't work! Official bodies shall tell manufacturers which security measures are needed to meet the minimum bar. Telling them to figure it out themselves is a waste of time. Safety doesn't use risk assessment but more effective people. What can security learn?
Read next
A Pragmatic Approach to CRA Risk Assessment
In less than 30 minutes, I can explain a pragmatic approach how to model the threats of an embedded system, assess the cybersecurity risks and document the risks in security decision records (SDRs). Here is the video from my talk at the Torizon CRA Summit in Munich.
How Can Manufacturers Address and Remediate 1000+ CVEs?
Fixing 1000+ CVEs one by one is too costly. Filtering them is arbitrary and might miss important ones. Making the exploitation of hundreds of CVEs unlikely by multiple security measures in one go is nothing else but defence in depth!