RAFA Model. Rethinking Cyber Risk Management in Organizations
摘要
In a highly volatile scenario such as the current one, current cyber risk management practices, based on standards and best practices, begin to lose ground in their effectiveness, given that their scope and proposals are restricted to known and certain scenarios, while the concrete reality of the company is configured in a new abnormality, in uncertain and unknown conditions, which increases tensions in its supply chain, generates instability in geopolitical conditions, warns of disruption with the incorporation of new technologies and implies new conditions to ensure regulatory compliance required by regulators. In this sense, this paper introduces a conceptual and practical model of cyber risk management called RAFA (Resilience, Antifragility, Flexibility and Anticipation) that allows developing a vigilant and active position of organizations as a way to propose alternatives to mobilize the efforts of the organization before the inevitability of failure, making it more resistant to attacks, creating incomplete maps of the reality and challenges of adversaries, and ways to move forward even before the materialization of adverse events.