0
Utility
About UsConferencePartner With Us
  • Infrastructure
    Compliance
    Gas Control
    Grid
    Transmission and Distribution
  • Field Operations
    Utilities Field Service
    Utility Locating and Mapping
    Wastewater Treatment
  • Utility Intelligence
    Utilities AI
    Utilities Asset Management
    Utilities Billing
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Magazines
  • CXO Awards
×
#

Utilities Tech Outlook Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Utilities Tech Outlook

Subscribe

loading
THANK YOU FOR SUBSCRIBING

Weekly Brief

loading

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Utilities Tech Outlook Advisory Board.

ISO New England Inc

Albert Evans, Chief of Information Security

Enhancing Cyber Risk Management: An Integrated Approach

Cyber threats continue to grow in frequency and impact, making robust cyber risk management more crucial than ever. Organizations can no longer rely on siloed frameworks to secure critical assets. Instead, they need integrated strategies that provide complete visibility into cyber risk. This article outlines a robust methodology for managing cyber risks by unifying three leading frameworks—MITRE ATT&CK, Factor Analysis of Information Risk (FAIR), and the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

MITRE ATT&CK enriches threat modeling by revealing real-world adversary behavior. The knowledge base maps out actual attack tactics, techniques, and procedures (TTPs) observed in the wild (MITRE, 2022). Integrating these TTPs into asset evaluations and penetration testing uncovers previously unseen risk vectors. Organizations can preemptively close gaps that attackers exploit through better system segmentation, upgraded controls, and improved detection coverage.

“Organizations can no longer rely on siloed frameworks to secure critical assets. Instead, they need integrated strategies that provide complete visibility into cyber risk”

However, understanding risk is only the first step. Organizations also need to measure and prioritize cyber risks to guide mitigation efforts. This is where FAIR comes in. The quantitative model converts qualitative assessments into comparable value and financial risk estimates (Fair Institute, 2022). By putting a dollar figure on cyber risks, decision-makers can objectively evaluate which threats pose the most significant impact. Resources flow to the vulnerabilities that genuinely matter rather than vague notions of high or critical risks.

NISTs flexible framework ties the process together (National Institute of Standards and Technology, 2022). It provides structured guidance for maintaining cybersecurity programs with continuous improvement cycles. Following NIST guidelines, organizations can institutionalize processes for identifying critical assets, selecting security controls, detecting threats, responding to incidents, and recovering normal operations. Each iteration further enhances resilience and risk posture.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping utilities technology and digital infrastructure. Participation is by invitation only. It features leaders who are not merely observing technological transformation, but actively contributing to it through innovation in grid and system management.
EDITOR'S CHOICE
  • Willis Towers Watson

    Con Edison Transmission, Inc [NYSE: ED]

    Con Edison Customers want Clean Energy: Technology And Companys Commitment are Making it Possible for them to Get it

    Walter Alvarado, Vice President, Electric Transmission, Con Edison Transmission, Inc.

  • Willis Towers Watson

    AVANGRID [NYSE: AGR]

    OptimizEV Helps Shape a Clean Energy Future

    Sean K. Sullivan, Senior Director - Clean Energy Policy, Avangrid

  • Willis Towers Watson

    California Water Service [NYSE: CWT]

    Consider an Audit Perspective to Enhance and Validate an Asset Management Program

    Stephen Harrison, Director of Asset Management/Interim Director of Internal Audit, California Water Service

  • Willis Towers Watson

    Alliant Energy [NASDAQ: LNT]

    Harnessing Technology in the Utility Sector

    Alberto Ruocco, Senior Vice President and Chief Information Officer, Alliant Energy

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

Utilities Tech Outlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@utilitiestechoutlook.com
  • sales@utilitiestechoutlook.com
  • marketing@utilitiestechoutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 Utilities Tech Outlook. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

www.utilitiestechoutlook.com/cxoinsight/enhancing-cyber-risk-management-an-integrated-approach-nwid-1472.html