Ineffective risk analysis lowers information security
Even though there are multiple quantitative methods for managing IT risks, and thus improving security, these methods are often used inadequately. The IT industry has a lot to learn from the financial industry which has been using these methods more effectively for risk analysis Thomas Roka-Aardal, Head of Information Security at Nagarro, has noted that there are largely two ways in which companies and organizations approach information security. The first is to demonstrate compliance, i.e. they adapt to existing certifications and rules. Compliance is something that can be shown