Uploaded April 2025 | Updated September 2026, 1 week ago
Security metrics are one way to evaluate cyber risk. However, companies with seemingly good security metrics have been hacked due to other corporate risk factors. JC discusses non-security data and business indicators you should look at through a cyber risk lens.
There are mountains of non-security data about company risk: financial health or distress, ownership changes, regulatory violations and legal issues, and business performance. On-time delivery. Defects. Contract cancellation. Layoffs. Staffing in general.
Many security professionals have lived through chapters of company history when security posture is insufficient. Lack of focus. Other priorities. But those other priorities have a way of showing up in non-security data. This session helps you identify and use these leading indicators of security incidents.
Security metrics are one way to evaluate cyber risk. However, companies with seemingly good security metrics have been hacked due to other corporate risk factors. JC discusses non-security data and business indicators you should look at through a cyber risk lens.
There are mountains of non-security data about company risk: financial health or distress, ownership changes, regulatory violations and legal issues, and business performance. On-time delivery. Defects. Contract cancellation. Layoffs. Staffing in general.
Many security professionals have lived through chapters of company history when security posture is insufficient. Lack of focus. Other priorities. But those other priorities have a way of showing up in non-security data. This session helps you identify and use these leading indicators of security incidents.




 Poland 2025: Attack on the Electric System](https://i.ytimg.com/vi/VUb2_8NKoQo/mqdefault.jpg)



 Decision Points: OT Fit-For-Purpose Or IT](https://i.ytimg.com/vi/X5MKHzOhBAU/mqdefault.jpg)

