Adversarial Risk Management
The Art and Science of Managing Organisation Security in the Hostile 21st Century
Inbunden, Engelska, 2026
2 069 kr
Kommande
Conventional risk management was not built for adversaries. The frameworks that organisations rely upon, ISO 31000, COSO ERM, and their derivatives, were designed for a world of probabilistic hazards, accidents, system failures, and random operational disruptions. Against a ransomware operator who studies your disaster recovery plan for weaknesses, a nation-state actor conducting multi-year reconnaissance through your supply chain, or an insider quietly exfiltrating intellectual property while compliance scores remain perfect, they fail. They fail because they were designed for a fundamentally different kind of risk, one governed by statistical distributions rather than human decision-making. An adversary is not a hurricane. Applying actuarial logic to intelligent, adaptive opponents does not produce security. It produces the appearance of security, and adversaries have learned to exploit the gap between the two.This book makes the case for a different paradigm. Adversarial Risk Management places the adversary's decision-making at the centre of the analytical problem. If a threat actor cannot acquire the intent to harm your organisation, cannot develop or sustain the capability to do so, and cannot identify or create the opportunity to act, the risk does not materialise. ARM works by disrupting that chain, systematically and continuously, across every domain in which your organisation is exposed.The framework rests on two interlocking constructs. The Intent, Capability, Opportunity model provides the analytical lens through which adversarial threats are deconstructed and understood. The Frame, Assess, Respond, Monitor cycle provides the operational discipline through which that analysis is translated into action, and renewed as adversaries evolve. ARM is applied across six security domains: cyber, physical, information, personnel, personal security, and supply chain, within a single coherent methodology that reflects how adversaries actually operate, without regard for organisational boundaries or disciplinary silos.ARM does not ask organisations to discard existing governance structures. It integrates with ISO 27001, NIST CSF, COSO ERM, and ISO 31000, providing the adversarial layer those frameworks were never designed to deliver, and it gives security leaders the measurement tools to demonstrate genuine outcome rather than compliance activity.This book is written for professionals who understand that the hostile twenty-first century demands more than compliance. It demands adversarial thinking.
Produktinformation
- Utgivningsdatum2026-12-23
- Mått178 x 254 x undefined mm
- FormatInbunden
- SpråkEngelska
- Antal sidor432
- FörlagTaylor & Francis Ltd
- ISBN9781041095446