|
By Kovrr
A recruitment system faces two obligations at once. AI rules classify it as high-risk and require the governance that follows. Employment law has required attention to discriminatory effect for decades, independent of any technology. They are not two versions of the same requirement.
|
By Kovrr
Saying a control reduces exposure is easy and almost always true. Saying it reduces exposure by a specific amount is a different claim, and the machinery for producing one is well established. Set a baseline from frequency and magnitude ranges, simulate, re-estimate the ranges with the control in place, simulate again, and report the difference. The method is sound. Applied to AI controls it runs into two problems, one about which term the control touches and one about what the estimate rests on.
|
By Kovrr
That human review becomes a bottleneck as agents scale is now widely observed. Five or ten agents working in parallel produce more decisions than one reviewer can evaluate, and under queue pressure the review degrades into approval without examination. The usual response is to move up a level, reviewing intents and boundaries rather than individual outputs.
|
By Kovrr
The OWASP GenAI Security Project unveiled an Agent Control Standard in early September, donated to the project and aimed at runtime enforcement for agentic systems. It sets out that agents should be inspectable, traceable and instrumentable, with declarative hooks and policy enforcement across frameworks. It answers which controls belong around an agent.
|
By Kovrr
An AI product sold in Europe is described as facing two incident reporting duties. One under product security rules and one under AI rules, with different triggers and different deadlines. Only one of them is running. Article 14 of the Cyber Resilience Act has applied since 11 September 2026. The AI duty moved, and coverage published in the last few weeks still describes it as live.
|
By Kovrr
Insurers are subject to AI governance rules and they are also the party asking other organizations AI governance questions as a condition of coverage. More than twenty states have adopted the model bulletin that turns AI oversight into an operational requirement for carriers, and those same carriers now send AI questionnaires to their corporate insureds. The sector facing both is well covered. What follows from it is not, and it produces something an insured can use.
|
By Kovrr
Somebody in operations builds an automation inside a sanctioned platform to solve a problem in their own workflow. It works, other people come to depend on its output, and eighteen months later that person leaves. The platform still lists the automation. Nobody inherits it, because it was never anybody's asset to begin with, and the offboarding checklist has no line for a thing that was never recorded as belonging to the person departing.
|
By Kovrr
An annual exposure figure for a retailer treats the year as uniform. Divide expected loss across twelve months, apply a duration, produce a number. The instinct that this understates a peak-season outage is correct and the usual reason given for it is wrong. The concentration is not where people assume, and the mechanism that makes a December outage expensive is not volume. It is that the demand has a deadline.
|
By Kovrr
A cyber insurance application is treated as a form to complete. Somebody gathers the answers, checks the boxes, submits it and waits for terms. Read the other way, the questions are a ranked list of what a market with claims data across thousands of organizations believes predicts loss. The list was assembled by parties who pay when they get it wrong, which makes it a more disciplined signal than most control frameworks and it arrives for free.
|
By Kovrr
Confidential data is usually something to protect indefinitely. Customer records, financial results, contract terms and personal information all need the same treatment next year as this year, so controls are judged on how well they hold over time. Unreleased content is different in a way that changes the calculation. Its commercial value depends entirely on not existing publicly yet, and on release day that requirement disappears completely.
AI is merging into the modern workplace at roughly the pace computers did in the 1980s, and the risks are evolving just as fast. IBM and Ponemon found that 97% of organizations hit by an AI-related security incident lacked basic access controls, and 63% had no AI governance policy at all. In this video, Yakir breaks down the seven categories of AI risk every GRC leader needs to understand, and what separates knowing you have a control gap from knowing what it will cost you.
Ransomware has shut down hospitals and data breaches have exposed millions of patient records. But healthcare organizations still struggle to manage cyber risk, because decisions get made on compliance checklists and generic threat scores that reveal nothing about real business impact. In this video, Kovrr breaks down how cyber risk quantification turns healthcare threats into financial terms, and why that changes the conversation between CISOs, compliance leads, and the board.
AI adoption inside the enterprise has outpaced the governance built to contain it — 57% of employees have used AI tools for work without telling their manager. Policies get written and committees get formed, but exposure keeps accumulating, because data governance, AI oversight, and security are almost always run as three separate programs. In this video, Kovrr breaks down the three pillars that need to connect, and what separates a durable AI governance program from a documented one.
By now, most organizations have invested in AI governance. Far fewer have solved the problem that makes governance possible in the first place: knowing what AI they are actually running — and with 57% of employees using AI tools at work without telling their manager, the gap is wider than most inventories admit. In this video, Kovrr breaks down what an AI asset inventory actually is, why traditional asset management never catches shadow AI, and what it takes to keep the record accurate.
For years, security and risk managers have relied on spreadsheets to track their cyber risk. But as regulatory expectations tighten and threats grow more sophisticated, manual tracking cannot keep up. In this video, Kovrr walks through what a modern cyber risk register looks like when cyber risk quantification is built into its foundation. We cover.
For years, CISOs have walked into boardrooms with technical data dumps that don't land. In this video, Kovrr breaks down the 7 cybersecurity metrics that actually resonate with board directors, all framed in the financial and business terms they use to govern the enterprise. We cover: Generated with the help of AI.
live webinar with Aaron Turner, IANS Faculty, who presents findings from his recent IANS research, 7 Steps to Securing Multi-AI Deployments, and explain how security teams can apply proven principles to modern AI systems.
Kovrr’s new AI Risk Governance Suite gives enterprises the visibility, structure, and measurable control needed to manage GenAI responsibly across its full lifecycle. Join us for Office Hours: Part 1, where Or Amir will walk through the first three modules of the suite—showing how enterprises can gain real-time oversight and quantifiable insight into their AI landscape: Discover how these capabilities help enterprises align innovation with accountability—building a defensible foundation for responsible GenAI adoption.
In this session, Or Amir, Product Manager at Kovrr, showcases our new AI Risk Assessment and AI Risk Quantification modules — helping enterprises gain visibility, benchmark maturity, identify shadow AI, and turn exposure into measurable outcomes.
Explore Kovrr’s brand-new CRQ-Powered Cyber Risk Register — a first-of-its-kind solution that’s redefining the way organizations build cyber GRC programs and manage cyber risk. Led by Or Amir, Product Manager at Kovrr, this session will offer a hands-on deep dive into the risk register’s extensive capabilities and show you why moving beyond static, spreadsheet-based registers to a fully quantified, dynamic risk intelligence framework is necessary for achieving resilience in today’s landscape.
|
By Kovrr
By its nature, cyber risk is dynamic. New events happen and evolve all the time, making it difficult for enterprises to financially quantify their financial exposure to cyber attacks. Around two years ago, for example, distributed denial-of-service (DDoS) attacks were making headlines, and now ransomware has come into heightened focus. It's reasonable to believe that other types of attacks will emerge in another two years and continue to change thereafter.
|
By Kovrr
The number of data breaches reported in the first 6 months of 2022 has put this year on track to be the lowest year of reports in the last 5 years for large US corporations. By looking at the rate at which data breach events have been reported so far this year, we predict that the number of events reported is expected to be 15-20% of the number of breaches reported in 2021
|
By Kovrr
The 2022 Verizon Data Breach Investigations Report (DBIR), the fifteenth such report in as many years, leads off with a startling statistic: Credentials are the number one overall attack vector hackers use in data breaches. Use of stolen credentials accounts for nearly half the breaches studied by Verizon, far ahead of phishing and exploit vulnerabilities, which account for 19% and 8% of attacks, respectively. Botnets, the fourth most common entry path for hackers, represent a mere 1% of attacks.
- September 2026 (35)
- August 2026 (64)
- July 2026 (28)
- June 2026 (6)
- May 2026 (4)
- April 2026 (3)
- March 2026 (4)
- February 2026 (3)
- January 2026 (4)
- December 2025 (4)
- November 2025 (3)
- October 2025 (3)
- September 2025 (3)
- August 2025 (3)
- July 2025 (3)
- June 2025 (3)
- May 2025 (4)
- April 2025 (3)
- March 2025 (3)
- February 2025 (5)
- January 2025 (3)
- December 2024 (1)
- November 2024 (3)
- October 2024 (4)
- September 2024 (3)
- August 2024 (1)
- July 2024 (4)
- June 2024 (3)
- May 2024 (5)
- April 2024 (4)
- March 2024 (3)
- February 2024 (4)
- January 2024 (10)
- December 2023 (5)
- November 2023 (1)
- October 2023 (4)
- September 2023 (1)
- August 2023 (4)
- July 2023 (3)
- June 2023 (2)
- May 2023 (1)
- April 2023 (2)
- March 2023 (4)
- February 2023 (13)
- January 2023 (6)
- December 2022 (2)
- November 2022 (2)
- July 2022 (3)
- June 2022 (1)
- October 2020 (1)
Kovrr financially quantifies cyber risk on demand. Our technology enables decision makers to seamlessly drive actionable cyber risk management decisions.
Kovrr's Quantum Cyber Risk Quantification platform enables decision makers to understand and financially quantify the changing profile of their cyber risk exposure.
Cyber Risk Management Made Easy:
- Communicate Cyber Risk in Financial Terms: Enhance the board and C-Suite’s decision-making process by financially quantifying cyber risk.
- Cybersecurity Investment Optimization: Prioritize and justify cybersecurity investments based on business impacts and risk reduction.
- Measure Cyber Security Programs’ Effectiveness: Assess the ROI of your cybersecurity program and stress test it based on potential risk mitigation actions, thereby supporting better resource allocation.
- 3rd Party Vendors Cyber Risk Exposure Analysis: Financially quantify cyber risk within your supply chain. Gain insights Into 3rd and 4th party exposure.
- Regulatory Compliance and Governance Reporting: Meet increased demands from regulators to continuously quantify and manage cyber risk exposure.
- Cyber Insurance Coverage and Price Optimization: Identify gaps between risk mitigation impact versus risk cyber insurance spending and needed coverage for 1st party and 3rd party.
- Quantitatively Benchmark and Compare your Cyber Risk Exposure: Benchmark to your industry peers and internally compare between different business entities in a consistent, measurable and accurate way.
A cyber risk management platform to quantify custom cyber risk scenarios.