118xBanin18xban.hashnode.dev·2d ago · 14 min readRisk Appetite vs Risk Tolerance // @18xBan · GRC Series · Chapter 14 Capacity, appetite, tolerance, trigger. Only one of them is a number. Tuesday, 10:40 AM: "Is that OK?" Priya's team wants to ship a product analytics SDK. It's 00
SKShivansh Khattarintechinsightshub11.hashnode.dev·3d ago · 5 min readServiceNow GRC: A Practical Guide to Governance, Risk, and ComplianceIntroduction Every large organization today operates under a web of regulations, internal policies, and risk frameworks. A single compliance failure can result in massive financial penalties and reput00
118xBanin18xban.hashnode.dev·Sep 20 · 14 min readThree Lines of Defence Explained@18xBan · GRC Series · Chapter 08 3 lines, drawn honestly.2 of them are the same person, and one is empty. Friday, 9:10 AM: "Who reviews you?" Gotham Mutual's analyst sends the 3 questionnaire item00
HCHazel Chirindainhazelsec.hashnode.dev·Sep 17 · 9 min readSecurity Tools Don’t Fix Bad Security ProcessesOne thing I've learned from working across different cybersecurity environments is that organisations can have very good security tools and still have security gaps. You can deploy EDR. You can implem00
118xBanin18xban.hashnode.dev·Sep 15 · 14 min readWhat GRC Actually Is (And What It Isn't)Three letters, one messy SaaS company, and the email that starts everything @18xBan · GRC Series · Chapter 01 ⚠️ This content is for educational purposes only. Wayne Industries is a fictional compan00
HCHazel Chirindainhazelsec.hashnode.dev·Sep 14 · 8 min readMicrosoft Secure Score: Why I Don’t Treat 100% as the GoalOne of the first things I look at when assessing a Microsoft security environment is its Microsoft Secure Score. It's useful because it gives you a quick indication of security controls that could pot00
LLoginsoftinloginsoft.hashnode.dev·Sep 9 · 8 min readCVE Backlogs and NVD Delays in 2026: How Security Teams Are Actually Coping Introduction If you run a vulnerability management program, the pattern is familiar: a CVE is published, your scanner detects it, and then you wait for NVD enrichment. When NVD enrichment is unavailab00
ZTZero Trust Threadsinzerotrustthreads.hashnode.dev·Sep 7 · 5 min readVulnerability, Threat, and Risk Are Not the Same ThingCybersecurity has a vocabulary problem. Words that have specific meanings are often used interchangeably in casual conversation. Three of the most common are: Vulnerability Threat Risk They are relate00
Rrathsarainrr-cyber.hashnode.dev·Aug 31 · 19 min readOpenID Connect: The Identity Layer OAuth Was MissingBy the time I actually heard the word OIDC, I'd already been through OAuth and PKCE conversations I hadn't fully understood, years apart from each other, and this one arrived even later than those. It00
SESecurity Engineerinsecuritynode.hashnode.dev·Aug 24 · 28 min readCISSP Frameworks & Standards — The Ultimate Exam Cheat SheetWhat You Really Need to Know for the CISSP Exam If you're preparing for the CISSP exam, frameworks and standards can become one of the most confusing parts of your study plan. You encounter names such00