logo

Protecting value at risk - the role of a risk operations center

ID: c9dc2049-be8c-5eac-a480-fc71f5414597

STIX ID: report--c9dc2049-be8c-5eac-a480-fc71f5414597

Feed Name: The Register (Security)

Date Published: 2025-12-10

Date Updated: 2026-04-26

Author: Matt Middleton-Leal, managing director EMEA, Qualys

...
...

The piece advocates implementing cyber risk quantification (CRQ) to express threats as value at risk and establishing a risk operations center (ROC) to continuously manage “peacetime” risks, moving beyond one-off metrics like CVSS. It promotes integrating security and IT data for ongoing, business-aligned prioritization, enabling CISOs to communicate risk in monetary terms, justify investments, and focus on controls that reduce the most impactful risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.