# risk-management

A continuous process for identifying, analyzing, treating, and monitoring risks to projects, systems, or organizational operations.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## NFR Brain: challenging the status quo of risk management with data

DevFeed: [NFR Brain: challenging the status quo of risk management with data](<https://devfeed.tech/articles/nfr-brain-challenging-the-status-quo-of-risk-management-with-data-41436.md>)

Original publisher: [Read original article](<https://building.nu.com/nfr-brain-challenging-the-status-quo-of-risk-management-with-data/>)

Author: Nubank Editorial

Published: 2026-09-04T14:18:41Z

Content type: opinion

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [data](<https://devfeed.tech/topics/data.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [critical](<https://devfeed.tech/tags/critical.md>), [data](<https://devfeed.tech/tags/data.md>), [data-analytics](<https://devfeed.tech/tags/data-analytics.md>), [data-modelling](<https://devfeed.tech/tags/data-modelling.md>), [data-science-machine-learning](<https://devfeed.tech/tags/data-science-machine-learning.md>), [governance](<https://devfeed.tech/tags/governance.md>), [models](<https://devfeed.tech/tags/models.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Nubank describes NFR Brain, a platform for combining data, modelling, and expert judgement to make non-financial risk signals comparable and actionable. The article presents it as a way to support more consistent, transparent risk prioritization in business decisions without automating judgement.

### Source excerpt

Author : Mayara Zenati At Nubank, we believe the most meaningful problems for customers and for the business rarely come with ready-made answers. That is why we challenge the status quo: not to innovate for innovation's sake, but to remove complexity and build solutions that make important decisions simpler, faster and better. This mindset also [...] The post NFR Brain: challenging the status quo of risk management with data appeared first on Building Nubank.

## NFR Brain: challenging the status quo of risk management with data

DevFeed: [NFR Brain: challenging the status quo of risk management with data](<https://devfeed.tech/articles/nfr-brain-challenging-the-status-quo-of-risk-management-with-data-38852.md>)

Original publisher: [Read original article](<https://building.nubank.com/nfr-brain-challenging-the-status-quo-of-risk-management-with-data/>)

Author: Nubank Editorial

Published: 2026-09-04T14:18:41Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [data](<https://devfeed.tech/topics/data.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-analytics](<https://devfeed.tech/tags/data-analytics.md>), [data-science-machine-learning](<https://devfeed.tech/tags/data-science-machine-learning.md>), [management](<https://devfeed.tech/tags/management.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [service](<https://devfeed.tech/tags/service.md>)

### AI overview

Nubank is building NFR Brain, a platform that combines data, modelling and expert judgement to create a comparable and actionable view of non-financial risk. The article explains how the platform is intended to support clearer, more consistent prioritization across operational failures, customer complaints, third-party dependencies and other risk signals.

### Source excerpt

Author : Mayara Zenati At Nubank, we believe the most meaningful problems for customers and for the business rarely come with ready-made answers. That is why we challenge the status quo: not to innovate for innovation's sake, but to remove complexity and build solutions that make important decisions simpler, faster and better. This mindset also [...] The post NFR Brain: challenging the status quo of risk management with data appeared first on Building Nubank.

## Canon 3X: Explore/Expand/Extract

DevFeed: [Canon 3X: Explore/Expand/Extract](<https://devfeed.tech/articles/canon-3x-explore-expand-extract-39973.md>)

Original publisher: [Read original article](<https://newsletter.kentbeck.com/p/canon-3x-exploreexpandextract>)

Author: Kent Beck

Published: 2026-07-30T13:04:07Z

Content type: opinion

Language: en

Sources: [Software Design: Tidy First?](<https://devfeed.tech/sources/software-design-tidy-first.md>)

Topics: [implementation](<https://devfeed.tech/topics/implementation.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [implementation](<https://devfeed.tech/tags/implementation.md>), [management](<https://devfeed.tech/tags/management.md>), [project-management](<https://devfeed.tech/tags/project-management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Kent Beck explains the 3X framework of Explore, Expand, and Extract, arguing that each phase of a product or company's growth requires different approaches to finance, teams, project management, technology, risk management, implementation, marketing, and sales.

### Source excerpt

I've started a series of Canon articles where I explain my ideas as plainly & unambiguously as possible--no analogies, no persuasion, just the facts.

## How Nubank uses causality, machine learning and Python to support credit limit increase decisions

DevFeed: [How Nubank uses causality, machine learning and Python to support credit limit increase decisions](<https://devfeed.tech/articles/how-nubank-uses-causality-machine-learning-and-python-to-support-credit-limit-increase-decisions-38849.md>)

Original publisher: [Read original article](<https://building.nubank.com/how-nubank-uses-causality-machine-learning-and-python-to-support-credit-limit-increase-decisions/>)

Author: Nubank Editorial

Published: 2026-07-01T16:16:31Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [Data Science](<https://devfeed.tech/topics/data-science.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Python](<https://devfeed.tech/topics/python.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>)

Tags: [causality](<https://devfeed.tech/tags/causality.md>), [data-science](<https://devfeed.tech/tags/data-science.md>), [life-at-nu](<https://devfeed.tech/tags/life-at-nu.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [python](<https://devfeed.tech/tags/python.md>), [risk](<https://devfeed.tech/tags/risk.md>), [scalability](<https://devfeed.tech/tags/scalability.md>)

### AI overview

A high-level technical overview of how Nubank applies data science, predictive modeling, causality, optimization, and monitoring to support credit limit increase decisions. It discusses balancing customer experience, risk management, operational sustainability, interpretability, computational cost, and scalability.

### Source excerpt

A technical, high-level view of how data science helps build more responsible and scalable credit decisions The post How Nubank uses causality, machine learning and Python to support credit limit increase decisions appeared first on Building Nubank.

## Maintenance of Everything : A Review

DevFeed: [Maintenance of Everything : A Review](<https://devfeed.tech/articles/maintenance-of-everything-a-review-39491.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/maintenance-of-everything-a-review>)

Author: Phil Venables

Published: 2026-04-18T10:45:19Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [maintenance](<https://devfeed.tech/topics/maintenance.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [review](<https://devfeed.tech/tags/review.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

A review of Stewart Brand's book Maintenance of Everything, discussing the importance of maintenance in technology risk management, security, and reliability. It also questions cybersecurity benchmarking that focuses on inputs such as budgets instead of outcomes such as control effectiveness.

### Source excerpt

I haven't done a book review for a while and there's no better way to get back to this than a look at Stewart Brand's Maintenance of Everything . Stewart developed a lot of this book in an open editing process and so the final delivery of what is Part 1 of a forthcoming series was all the more anticipated. I've long been obsessed with the need for maintenance in the context of technology risk management, security and reliability. A big part of technical debt build up and the security...

## What the Swedbank outage reveals about the limits of traditional change management

DevFeed: [What the Swedbank outage reveals about the limits of traditional change management](<https://devfeed.tech/articles/the-swedbank-outage-shows-that-change-controls-don-t-work-33611.md>)

Original publisher: [Read original article](<https://highscalability.com/the-swedbank-outage-shows-that-change-controls-dont-work/>)

Author: Bruce Johnston

Published: 2023-08-16T16:05:12Z

Content type: opinion

Language: en

Sources: [High Scalability](<https://devfeed.tech/sources/high-scalability-3.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [outage](<https://devfeed.tech/tags/outage.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

The article examines the Swedish FSA's judgment on Swedbank's April 2022 outage, which followed an unapproved IT change and affected customer balances and payments. It argues that traditional change-management controls, including manual approvals and change meetings, do not by themselves guarantee safe and secure changes.

### Source excerpt

This week I've been reading through the recent judgment from the Swedish FSA on the Swedbank outage. If you're unfamiliar with this story, Swedbank had a major outage in April 2022 that was caused by an unapproved change to their IT systems. It temporarily left nearly

## Worthwhile Books Q4 2022

DevFeed: [Worthwhile Books Q4 2022](<https://devfeed.tech/articles/worthwhile-books-q4-2022-37134.md>)

Original publisher: [Read original article](<https://shostack.org/blog/worthwhile-books-q4/>)

Author: Adam

Published: 2022-12-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [safety](<https://devfeed.tech/tags/safety.md>)

### AI overview

A personal roundup of books read in late 2022, highlighting works about safety, maritime disaster, engineering, risk management, science, fiction, and astrobiology. The author emphasizes lessons that transfer from safety to cybersecurity.

### Source excerpt

Books that I read in the fourth quater that are worth your time include several about safety with lessons for cybersecurity

## Application Security Roundup - June

DevFeed: [Application Security Roundup - June](<https://devfeed.tech/articles/application-security-roundup-june-36680.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-june/>)

Author: Adam

Published: 2022-06-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [medical-devices](<https://devfeed.tech/tags/medical-devices.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A June application security roundup highlights articles about requirements for medical-device cybersecurity, policy and implementation, and the importance of appropriate risk management and investigation despite concerns about cost and delay.

### Source excerpt

Interesting appsec posts: from medical devices to bridges.

## Learning Lessons from Aviation

DevFeed: [Learning Lessons from Aviation](<https://devfeed.tech/articles/learning-lessons-from-aviation-36748.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cyber-lessons-learned/>)

Author: Adam

Published: 2021-11-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [recommendations](<https://devfeed.tech/topics/recommendations.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [aviation](<https://devfeed.tech/tags/aviation.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [recommendations](<https://devfeed.tech/tags/recommendations.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [third-party](<https://devfeed.tech/tags/third-party.md>)

### AI overview

The article discusses applying learning models from aviation to cybersecurity investigations. It describes a report examining what a cyber NTSB might be, recommends objective and independent investigations, and identifies research questions for further study.

### Source excerpt

The definition of insanity is doing the same thing over and over and expecting different results. We can do better, and a major new report explains how.

## What are we going to do: CO2 edition

DevFeed: [What are we going to do: CO2 edition](<https://devfeed.tech/articles/what-are-we-going-to-do-co2-edition-37116.md>)

Original publisher: [Read original article](<https://shostack.org/blog/what-are-we-going-to-do-co2-edition/>)

Author: Adam

Published: 2021-10-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [carbon](<https://devfeed.tech/tags/carbon.md>), [climate](<https://devfeed.tech/tags/climate.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ease](<https://devfeed.tech/tags/ease.md>), [emissions](<https://devfeed.tech/tags/emissions.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [usability](<https://devfeed.tech/tags/usability.md>)

### AI overview

The article uses Microsoft's evaluation of carbon-removal proposals to discuss how explicit criteria can improve mitigation and risk-management decisions. It applies this idea to cybersecurity threat modeling, including cost, bypass resistance, usability, and unusual circumstances.

### Source excerpt

What happened when Microsoft tried to buy climate abatements

## Zen and the art of not quantifying risk

DevFeed: [Zen and the art of not quantifying risk](<https://devfeed.tech/articles/zen-and-the-art-of-not-quantifying-risk-37136.md>)

Original publisher: [Read original article](<https://shostack.org/blog/zen-and-the-art-of-not-quantifying-risk/>)

Author: Adam

Published: 2021-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Development](<https://devfeed.tech/topics/development.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [development](<https://devfeed.tech/tags/development.md>), [dialog](<https://devfeed.tech/tags/dialog.md>), [meetings](<https://devfeed.tech/tags/meetings.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that threat modeling should not focus on producing precise risk numbers. Instead, security teams should work with development and operations on prioritization, using simpler relative sizing when appropriate. This approach can reduce conflict and help address easily fixed lower-priority issues alongside larger changes.

### Source excerpt

Many people want their threat modeling work to produce risk numbers, and in this post you'll learn why that's a mistake.

## Review: Practical Cybersecurity Architecture

DevFeed: [Review: Practical Cybersecurity Architecture](<https://devfeed.tech/articles/review-practical-cybersecurity-architecture-36957.md>)

Original publisher: [Read original article](<https://shostack.org/blog/review-practical-cybersecurity-architecture/>)

Author: Adam

Published: 2021-05-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [practical](<https://devfeed.tech/tags/practical.md>), [review](<https://devfeed.tech/tags/review.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Adam Shostack reviews Practical Security Architecture by Diana Kelley and Ed Moyle, praising its concise, practical, customer-focused approach to security architecture. He also discusses its treatment of application security, risk management, and threat modeling, including his view that likelihood can often be simplified when analyzing public-facing applications.

### Source excerpt

Adam Shostack's review of the book Practical Cybersecurity Architecture

## Includes No Dirt: Healthcare Threat Modeling (Thursday)

DevFeed: [Includes No Dirt: Healthcare Threat Modeling (Thursday)](<https://devfeed.tech/articles/includes-no-dirt-healthcare-threat-modeling-thursday-36838.md>)

Original publisher: [Read original article](<https://shostack.org/blog/includes-no-dirt-healthcare-threat-modeling-thursday/>)

Author: Adam

Published: 2019-10-31T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [development-process](<https://devfeed.tech/tags/development-process.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

A commentary on the "Includes No Dirt" threat modeling approach by William Dogherty and Patrick Curry of Omada Health. The article describes its focus on security, privacy, and compliance, outlines the NO DIRT model and supporting worksheets, and discusses its potential use in development and vendor risk management.

### Source excerpt

"Includes No Dirt" is a threat modeling approach by William Dogherty and Patrick Curry of Omada Health, and I've been meaning to write about it since it came out.

## A roundup of articles and papers on risk management, security automation, SDL, and threat modeling

DevFeed: [A roundup of articles and papers on risk management, security automation, SDL, and threat modeling](<https://devfeed.tech/articles/interesting-reads-risk-automation-lessons-and-more-36843.md>)

Original publisher: [Read original article](<https://shostack.org/blog/interesting-reads-2/>)

Author: Adam

Published: 2019-10-15T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>)

Tags: [academics](<https://devfeed.tech/tags/academics.md>), [automation](<https://devfeed.tech/tags/automation.md>), [devices](<https://devfeed.tech/tags/devices.md>), [governance](<https://devfeed.tech/tags/governance.md>), [paper](<https://devfeed.tech/tags/paper.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sdl](<https://devfeed.tech/tags/sdl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This blog post highlights several readings on cybersecurity, including a risk management and governance knowledge area, automated security design flaw detection, lessons from 15 years of SDL, and threat modeling for devices.

### Source excerpt

Just what the title says.

## Safety and Security in Automated Driving

DevFeed: [Safety and Security in Automated Driving](<https://devfeed.tech/articles/safety-and-security-in-automated-driving-36962.md>)

Original publisher: [Read original article](<https://shostack.org/blog/safety-and-security-in-automated-driving/>)

Author: Adam

Published: 2019-07-08T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [autonomous vehicles](<https://devfeed.tech/topics/autonomous-vehicles.md>), [Security](<https://devfeed.tech/topics/security.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [automotive](<https://devfeed.tech/tags/automotive.md>), [autonomous-vehicles](<https://devfeed.tech/tags/autonomous-vehicles.md>), [driving](<https://devfeed.tech/tags/driving.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [safety](<https://devfeed.tech/tags/safety.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This commentary examines how cybersecurity can be integrated into the established safety discipline for automated driving. It discusses threat modeling, minimal risk conditions, emergency stops, risk-treatment strategies, and risks associated with generic vehicle architectures.

### Source excerpt

Let's explore the risks associated with Automated Driving.

## Recommended Reads on IT Security, Cybersecurity, and Organizational Resilience

DevFeed: [Recommended Reads on IT Security, Cybersecurity, and Organizational Resilience](<https://devfeed.tech/articles/interesting-monday-reads-36842.md>)

Original publisher: [Read original article](<https://shostack.org/blog/interesting-monday-reads-20170814/>)

Author: Adam

Published: 2017-08-14T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [IT\_Security](<https://devfeed.tech/topics/it-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [culture](<https://devfeed.tech/tags/culture.md>), [it-security](<https://devfeed.tech/tags/it-security.md>), [management](<https://devfeed.tech/tags/management.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [weather](<https://devfeed.tech/tags/weather.md>)

### AI overview

A curated selection of long, thought-provoking reads covering IT security, cybersecurity risk management for the U.S. government, and company culture for handling failure.

### Source excerpt

Each of these is long and thought-provoking and worth savoring.

## Introducing Cyber Portfolio Management

DevFeed: [Introducing Cyber Portfolio Management](<https://devfeed.tech/articles/introducing-cyber-portfolio-management-36847.md>)

Original publisher: [Read original article](<https://shostack.org/blog/introducing-cyber-portfolio-management/>)

Author: Adam

Published: 2017-02-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [challenges](<https://devfeed.tech/tags/challenges.md>), [communication](<https://devfeed.tech/tags/communication.md>), [management](<https://devfeed.tech/tags/management.md>), [portfolio](<https://devfeed.tech/tags/portfolio.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [talk](<https://devfeed.tech/tags/talk.md>)

### AI overview

The article introduces Cyber Portfolio Management, a proposed approach to driving effective security programs by managing distributed security portfolios and improving communication between security and business teams. It also discusses a related RSA talk, audio and slides, and an upcoming ebook draft.

### Source excerpt

[no description provided]

## The art of the startup pivot from a founder-CTO point of view

DevFeed: [The art of the startup pivot from a founder-CTO point of view](<https://devfeed.tech/articles/the-art-of-the-startup-pivot-from-a-founder-cto-point-of-view-34702.md>)

Original publisher: [Read original article](<https://medium.com/unexpected-token/the-art-of-the-startup-pivot-from-a-founder-cto-point-of-view-b8747f80b5be?source=rss----2d2624499d2---4>)

Author: Yann Lechelle

Published: 2015-04-30T13:15:07Z

Content type: opinion

Language: en

Sources: [eFounders](<https://devfeed.tech/sources/efounders.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [efounders](<https://devfeed.tech/tags/efounders.md>), [management](<https://devfeed.tech/tags/management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [startup](<https://devfeed.tech/tags/startup.md>), [startups](<https://devfeed.tech/tags/startups.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

An opinion piece examines startup pivots from a founder-CTO perspective, covering why strategic changes occur, their effects on founders, investors, revenue, and company structure, and how repeated pivot experience may inform risk management.

### Source excerpt

A risk management perspectiveYann Lechelle (LinkedIn, Twitter) is a Paris-based entrepreneur with a number of pivots under his belt. He was founder and CEO at Etheryl (acquired by private investors), co-founder at KickYourApp.com (acquired by Change), co-founder and COO/CTO at Appsfire.com (acquired by MNG), co-founder at Sonetin.com and currently COO at Snips.ai using AI to make technology disappear. Yann occasionally invests in and advises other startups, on pivots among other things!~ TL;DR: this post discusses the generic notion of a startup pivot. Technically minded readers might prefer to focus on the product & tech sections, or anything else in bold. Pivots are a fact of life in the startup world. Yet, very few founders, especially first-time founders, will provision for it. The founder mindset is typically focused on a single go-to-market strategy. The investors are sold on the potential based on that initial strategy, signing off a budget calibrated accordingly. Everyone sings the same tune until the shareholders realize, hopefully before it's too late, that the strategy is going nowhere, and that a radical change is required. This scenario occurs more often than not, over 65% of the time according to Fred Wilson. While this iterative process appears natural, and with the benefit of hindsight, accepted and even praised as part of the startup folklore, it remains a traumatic event from the inside, and possibly a direct cause for failure. Reversely, if done right, a pivot is almost inevitably cause for success. Structurally, there can only be a handful of pivots within the lifetime of a company. Repeat entrepreneurs may have experienced it multiple times and therefore developed their art of the pivot... hence becoming pivot artists, a trait that VCs should consider as key risk management expertise! Here are a few awesome pivot artists: Multi-pivot repeat entrepreneur Stewart Butterfield: from video game to Flickr and from video game to Slack; product & vision p