BSides Bristol 2024

The human factor: Quantifying human risk
2024-08-30 , Track 1

This talk will explore the growing field of human risk management and quantification, diving into the next step in an organizations risk journey - quantifying people. We will talk about where the market is, how people are adopting it, and what organizations can gain from human risk management.


I'd like to do a session on the emerging and evolving field of human risk quantification; which aims to apply quantitative methods to assign risk scores to every employee at a company based on the actions they're taking and the things they have access to. I think this space is very similar to where cyber risk quantification was about 4 years ago - there were a few start ups in the market and a few active voices on Linkedin advocating for the adoption of these practices, but think it will start to become a lot bigger in the new year. I've done extensive research into where the players in the market are and how companies are adopting it. I think this will be the next step of a risk journey for many companies. Over 80% of breaches involve the human element, if organizations want to stop them they need to understand how the people they employ are effecting their security posture.

Sara Anstey is the Director of Data Analytics and Risk at Novacoast who is passionate about empowering businesses to use everyday data to make strategic business decisions. She believes that the intentional adoption of a data-driven culture can be a key differentiator to companies in today’s security climate. Sara has experience in cyber risk quantification, artificial intelligence, data analytics, business intelligence, and applied statistics.

sanstey@novacoast.com
https://www.linkedin.com/in/sara-anstey/