|
By Kovrr
The standard answer to fragmented AI compliance is a responsibility matrix mapped across the lifecycle. Procurement accountable at intake, legal responsible for regulatory vetting, engineering accountable at implementation, security accountable for monitoring. Every stage has an owner and every function knows its part. Read that arrangement carefully and the problem is visible inside the solution.
|
By Kovrr
A governance program looks complete until somebody asks it to prove something on a deadline it did not set. A supervisor sends an information request. An underwriter asks for control coverage before binding. A prospect's security team asks how a specific control operated last quarter, and the deal waits on the answer. Most programs can describe what they do accurately and cannot evidence it inside the window. The difference is not a documentation problem.
|
By Kovrr
Arguments for quantifying cyber risk are abundant and mostly sound. What gets published far less often is a plain account of what a modeled figure does not tell you, which is unfortunate, because stating the limits is more persuasive to a skeptical audience than another argument for the method. We build these models. What follows is what they cannot do, written plainly, followed by what remains useful once those limits are accepted.
|
By Kovrr
Cross-mapping tables for AI evidence in life sciences already exist and are broadly right. Data integrity practice lines up against data governance requirements, software lifecycle logs against technical documentation and logging, human review checks against human oversight duties, post-market surveillance against post-market monitoring. Build one repository, present it two ways. All of that is sound and it starts one step too late.
|
By Kovrr
Monitoring an agent tells you what that agent did. Every useful question about a multi-agent deployment concerns what happened between agents, and those are properties of the connections rather than of the participants. A per-agent view records nodes and the problems live on the edges. The shortfall is not a tooling problem waiting on a product.
|
By Kovrr
An annual quantification gets produced in March and quoted as fact in November. Everyone involved knows the figure has aged and nobody knows by how much, so it keeps being presented with the same confidence it had on the day it was signed off. The usual framing is that a number decays gradually and needs refreshing more often. The framing is half right and it misleads on the part that matters, because most of the decay does not happen gradually at all.
|
By Kovrr
Guidance on agent governance concentrates almost entirely on what happens after deployment. Monitoring, sprawl, identity, attribution, retirement. The decision to put the agent into production in the first place gets treated as a software release, and software release processes ask none of the questions that matter for something which acts on its own. Agent governance generally assumes the agent is already running.
|
By Kovrr
A quantification program with a dozen scenarios usually produces its annual figure by adding them together. Each scenario was modeled carefully, the arithmetic is simple, and the result is close to right for one of the two numbers the model produces. Summing scenarios treats them as independent, and cyber scenarios share dependencies. The consequence is specific rather than general, and it is worth being precise about because it determines which decisions the resulting figure can support.
|
By Kovrr
The standard method for sizing a cyber program from a loss curve has two halves. Set the retention where the balance sheet can absorb the loss, and set the limit at the one-in-hundred-year figure. The first half is sound. The second is a convention borrowed from property catastrophe practice, and the curve does not derive it. The distinction matters because organizations treat both numbers as outputs of the same model, then defend a limit the model never produced.
|
By Kovrr
An AI coding agent's own telemetry answers real questions well: which agents are running, what they invoked, the shape of a session, whether a run looks abnormal. It cannot, no matter how completely it is instrumented, stand alone as evidence. The agent under review is also the party writing the record. The record shows an attempt, not an outcome. And the vocabulary for describing any of it is still being written in public, one unstable commit at a time.
AI is merging into the modern workplace at roughly the pace computers did in the 1980s, and the risks are evolving just as fast. IBM and Ponemon found that 97% of organizations hit by an AI-related security incident lacked basic access controls, and 63% had no AI governance policy at all. In this video, Yakir breaks down the seven categories of AI risk every GRC leader needs to understand, and what separates knowing you have a control gap from knowing what it will cost you.
Ransomware has shut down hospitals and data breaches have exposed millions of patient records. But healthcare organizations still struggle to manage cyber risk, because decisions get made on compliance checklists and generic threat scores that reveal nothing about real business impact. In this video, Kovrr breaks down how cyber risk quantification turns healthcare threats into financial terms, and why that changes the conversation between CISOs, compliance leads, and the board.
AI adoption inside the enterprise has outpaced the governance built to contain it — 57% of employees have used AI tools for work without telling their manager. Policies get written and committees get formed, but exposure keeps accumulating, because data governance, AI oversight, and security are almost always run as three separate programs. In this video, Kovrr breaks down the three pillars that need to connect, and what separates a durable AI governance program from a documented one.
By now, most organizations have invested in AI governance. Far fewer have solved the problem that makes governance possible in the first place: knowing what AI they are actually running — and with 57% of employees using AI tools at work without telling their manager, the gap is wider than most inventories admit. In this video, Kovrr breaks down what an AI asset inventory actually is, why traditional asset management never catches shadow AI, and what it takes to keep the record accurate.
For years, security and risk managers have relied on spreadsheets to track their cyber risk. But as regulatory expectations tighten and threats grow more sophisticated, manual tracking cannot keep up. In this video, Kovrr walks through what a modern cyber risk register looks like when cyber risk quantification is built into its foundation. We cover.
For years, CISOs have walked into boardrooms with technical data dumps that don't land. In this video, Kovrr breaks down the 7 cybersecurity metrics that actually resonate with board directors, all framed in the financial and business terms they use to govern the enterprise. We cover: Generated with the help of AI.
live webinar with Aaron Turner, IANS Faculty, who presents findings from his recent IANS research, 7 Steps to Securing Multi-AI Deployments, and explain how security teams can apply proven principles to modern AI systems.
Kovrr’s new AI Risk Governance Suite gives enterprises the visibility, structure, and measurable control needed to manage GenAI responsibly across its full lifecycle. Join us for Office Hours: Part 1, where Or Amir will walk through the first three modules of the suite—showing how enterprises can gain real-time oversight and quantifiable insight into their AI landscape: Discover how these capabilities help enterprises align innovation with accountability—building a defensible foundation for responsible GenAI adoption.
In this session, Or Amir, Product Manager at Kovrr, showcases our new AI Risk Assessment and AI Risk Quantification modules — helping enterprises gain visibility, benchmark maturity, identify shadow AI, and turn exposure into measurable outcomes.
Explore Kovrr’s brand-new CRQ-Powered Cyber Risk Register — a first-of-its-kind solution that’s redefining the way organizations build cyber GRC programs and manage cyber risk. Led by Or Amir, Product Manager at Kovrr, this session will offer a hands-on deep dive into the risk register’s extensive capabilities and show you why moving beyond static, spreadsheet-based registers to a fully quantified, dynamic risk intelligence framework is necessary for achieving resilience in today’s landscape.
|
By Kovrr
By its nature, cyber risk is dynamic. New events happen and evolve all the time, making it difficult for enterprises to financially quantify their financial exposure to cyber attacks. Around two years ago, for example, distributed denial-of-service (DDoS) attacks were making headlines, and now ransomware has come into heightened focus. It's reasonable to believe that other types of attacks will emerge in another two years and continue to change thereafter.
|
By Kovrr
The number of data breaches reported in the first 6 months of 2022 has put this year on track to be the lowest year of reports in the last 5 years for large US corporations. By looking at the rate at which data breach events have been reported so far this year, we predict that the number of events reported is expected to be 15-20% of the number of breaches reported in 2021
|
By Kovrr
The 2022 Verizon Data Breach Investigations Report (DBIR), the fifteenth such report in as many years, leads off with a startling statistic: Credentials are the number one overall attack vector hackers use in data breaches. Use of stolen credentials accounts for nearly half the breaches studied by Verizon, far ahead of phishing and exploit vulnerabilities, which account for 19% and 8% of attacks, respectively. Botnets, the fourth most common entry path for hackers, represent a mere 1% of attacks.
- September 2026 (6)
- August 2026 (64)
- July 2026 (28)
- June 2026 (6)
- May 2026 (4)
- April 2026 (3)
- March 2026 (4)
- February 2026 (3)
- January 2026 (4)
- December 2025 (4)
- November 2025 (3)
- October 2025 (3)
- September 2025 (3)
- August 2025 (3)
- July 2025 (3)
- June 2025 (3)
- May 2025 (4)
- April 2025 (3)
- March 2025 (3)
- February 2025 (5)
- January 2025 (3)
- December 2024 (1)
- November 2024 (3)
- October 2024 (4)
- September 2024 (3)
- August 2024 (1)
- July 2024 (4)
- June 2024 (3)
- May 2024 (5)
- April 2024 (4)
- March 2024 (3)
- February 2024 (4)
- January 2024 (10)
- December 2023 (5)
- November 2023 (1)
- October 2023 (4)
- September 2023 (1)
- August 2023 (4)
- July 2023 (3)
- June 2023 (2)
- May 2023 (1)
- April 2023 (2)
- March 2023 (4)
- February 2023 (13)
- January 2023 (6)
- December 2022 (2)
- November 2022 (2)
- July 2022 (3)
- June 2022 (1)
- October 2020 (1)
Kovrr financially quantifies cyber risk on demand. Our technology enables decision makers to seamlessly drive actionable cyber risk management decisions.
Kovrr's Quantum Cyber Risk Quantification platform enables decision makers to understand and financially quantify the changing profile of their cyber risk exposure.
Cyber Risk Management Made Easy:
- Communicate Cyber Risk in Financial Terms: Enhance the board and C-Suite’s decision-making process by financially quantifying cyber risk.
- Cybersecurity Investment Optimization: Prioritize and justify cybersecurity investments based on business impacts and risk reduction.
- Measure Cyber Security Programs’ Effectiveness: Assess the ROI of your cybersecurity program and stress test it based on potential risk mitigation actions, thereby supporting better resource allocation.
- 3rd Party Vendors Cyber Risk Exposure Analysis: Financially quantify cyber risk within your supply chain. Gain insights Into 3rd and 4th party exposure.
- Regulatory Compliance and Governance Reporting: Meet increased demands from regulators to continuously quantify and manage cyber risk exposure.
- Cyber Insurance Coverage and Price Optimization: Identify gaps between risk mitigation impact versus risk cyber insurance spending and needed coverage for 1st party and 3rd party.
- Quantitatively Benchmark and Compare your Cyber Risk Exposure: Benchmark to your industry peers and internally compare between different business entities in a consistent, measurable and accurate way.
A cyber risk management platform to quantify custom cyber risk scenarios.