07 Sep 2023 | 36:11 Share this
E21: 4 Simple, Easy & Budget-Friendly Steps to Reduce Your
In this episode of the GRC & Cyber Security Podcast, Brent Deterding, CISO at Afni, joins Matthew Davies, VP of Product at SureCloud, to share his refreshingly practical approach to organisational risk. Brent breaks down the four steps he uses to significantly reduce cyber risk in a way that is simple, easy and inexpensive — a framework that any business, regardless of size or maturity, can adopt.
He explains how Afni prioritises efforts within its security programme, the role of frameworks like FAIR, and the thinking behind a risk-first, complexity-last mindset. Brent also reveals how he achieved a one-third reduction in cyber insurance costs, and the cultural, operational and technical changes that supported this outcome.
This conversation offers clarity for leaders overwhelmed by competing priorities, limited resources and increasing pressure to demonstrate measurable risk reduction. Brent’s insight is practical, honest and highly actionable — making this episode essential listening for CISOs, security managers, risk professionals and anyone responsible for reducing organisational exposure.
What You’ll Learn
-
Brent’s four-step framework for simple, inexpensive and high-impact risk reduction
-
How Afni prioritises security work using risk-based thinking and FAIR principles
-
The structure and maturity of Afni’s information security programme
-
How Brent achieved a significant reduction in cyber insurance costs
-
What’s working well today in Afni’s cyber strategy
-
Current areas of concern for CISOs in 2023 and how to address them
-
The skills that make a great information security professional
-
Brent’s “one wish” for solving a major security problem
Hosted by: Mathew Davies Chief Product Officer - Surecloud
Guest: Brent Deterding CISO at Afni
- Risk Management
- Information Security
Latest Episodes
E28: Rory Innes - A World Where Cybercriminals Don’t Win
28 May 2024
- Cybersecurity
E20: Building Resilient Organisations: Business Continuity & Disaster Recovery with IFCO CISO Alexander Zhitenev
20 Aug 2023
- Risk Management
- Cybersecurity
E19: Cybersecurity Leadership: A New Era — Karla Reffold on CISO Advisory, Board Impact & Career Evolution
06 Aug 2023
- Cybersecurity
E18: The Real Risks of AI: Sam Bisbee on Protecting Organisations from Emerging Threats
18 May 2023
- Information Security
Useful Resources
- GRC
- Other
- GRC
- White Paper
- Compliance
- Other
- DORA
- Compliance
- Other
- DORA
- Compliance
- White Paper
- Compliance
- Other


