1.1 - Risk management is broken. Let's rebuild it.
2026 Webinar Program: Rebuilding cyber risk management
Series 1: Cyber risk management, rebuilt: from ISO 27005 to the boardroom
To help you navigate your cyber risk management challenges, C-Risk has developed a three-part webinar series on rebuilding what's broken in cyber risk management. This approach reflects Gartner's guidance on CRQ: start with decisions, express exposure in ranges and set appetite thresholds. The result is a risk program that supports decisions across the business.
This series addresses the shift from compliance-focused to data-driven risk management, build the foundation for defensible analysis, and connect quantified cyber risk to enterprise governance.

1.1 - Risk management is broken. Let's rebuild it.
Cyber risk programs spend a lot of effort on compliance and controls testing, but these are only components of the risk management process.
This 30-minute Livestorm webinar diagnosed why many cyber risk programs can be audit-compliant yet still fail to provide value to corporate boards. The hosts positioned the core issue as a “data and governance chain gap” rather than a lack of tools, and outlined a target operating model for data-driven, board-relevant risk management.
Christophe Foret (C-Risk Co-founder) and Neil MacGowan (Customer Success Director, C-Risk) explored the following main topics:
- A board has different questions than an auditor: Most cyber risk programs can be “defensible” against an auditor, but they are “useless to a board” because board-level decisions require quantified, financial decision inputs.
- The gap is capability/data chain, not an absence of frameworks: Existing “risk-based” frameworks were described as written for auditors, not boards—so organizations often end up answering the wrong question with the wrong units.
- Siloed risk management creates outcomes that suppress strategy: Gartner research cited found 54% of organizations run siloed risk management; the hosts associated this with confusion, delayed timelines, and blockage of strategy, while noting that 70% of transformation projects fail when risk is handled poorly.
> Replay is available here.