The Fundamental Mistake in Cybersecurity Risk Management

The Fundamental Mistake in Cybersecurity Risk Management

Author: Jim Love March 21, 2026 Duration: 49:39

Cybersecurity Isn't Managing Risk—It's Managing Threats... And That's the Problem

Host David Shipley speaks with Jeff Gardiner, a former university CISO and now at Morgan Stanley, about Gardiner's doctoral research arguing that cybersecurity has structurally misclassified "risk management" as threat management. 

Gardiner explains that real risk is an expected loss calculation (impact × likelihood), while many cybersecurity frameworks and training emphasize vulnerabilities, exploitability, and system configuration without likelihood or business impact. He describes examples where teams labeled unlikely issues as "extremely high risk," discusses interviews where leaders universally expect cybersecurity staff to be risk managers, and cites findings that only about 11% of cybersecurity professionals actually perform risk calculations. Gardiner outlines a practical approach using qualitative likelihood and impact scales, prioritization, and clearer business framing, and notes ongoing discussions with NIST to improve the NICE framework.

Cybersecurity Today  would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale.  You can find them at Meter.com/cst


00:00 Sponsor Message
00:19 Meet Jeff Gardiner
01:51 Career Journey Origins
03:23 TLS Risk Epiphany
05:06 What Is Compute Canada
06:38 Risk Versus Threat
08:35 Why Labels Matter
11:13 Likelihood And Impact
12:26 Teaching Risk Qualitatively
15:29 Why Prioritize Risk
20:36 Training Frameworks Flaw
25:13 Research Frustrations
25:51 Risk Management Wins
26:44 Why CISOs Burn Out
27:43 Speaking Executive Risk
29:22 Teach Risk Broadly
31:36 Biases and Better Judgments
35:17 Sexy Scary vs Real Risk
36:12 Convincing the Room
39:15 Start Simple Frameworks
41:36 Risk Quadrants and Delegation
45:30 Mentorship and NIST V3
47:57 Wrap Up and Sponsor


Every morning, Jim Love sifts through the noise of the digital world to bring you a clear, concise briefing on what actually matters. Cybersecurity Today isn't about fearmongering; it's about practical awareness. You'll hear straightforward analysis of the most recent attacks targeting companies, from sophisticated ransomware campaigns to stealthy data theft. Jim breaks down the implications of major breach disclosures, explaining not just what was stolen, but how it happened and who is affected. The focus remains on actionable intelligence-concrete steps and strategic thinking that can help protect your organization's data and infrastructure. This daily podcast serves as an essential filter for IT professionals, business leaders, and anyone responsible for digital assets, transforming complex threats into understandable insights. Tune in for a grounded perspective on navigating an online landscape where the risks are constantly evolving, and the need for clear, timely information has never been greater.
Author: Language: English Episodes: 100

Cybersecurity Today
Podcast Episodes
Spiderman and Cybersecurity. [not-audio_url] [/not-audio_url]

Duration: 11:53
Cybersecurity Today: Spider-Man Phishing Kit, Gogs Zero-Day Exploits, and Recent Patches In this episode, host Jim Love discusses recent cybersecurity issues including the Spider-Man phishing kit targeting European banks…
Google Chrome's AI Safety Plan? More AI [not-audio_url] [/not-audio_url]

Duration: 11:42
Cybersecurity Today: Google Chrome's AI Safety Plan, React2Shell Fixes, & New Ransomware Tactics In this episode of Cybersecurity Today, host Jim Love discusses Google's new security blueprint for AI-powered Chrome agent…
DevelopmentTools May Allow Remote Compromise [not-audio_url] [/not-audio_url]

Duration: 13:08
Explosive React Vulnerability and AI Tool Flaws Uncovered: Major Implications for Cybersecurity In this episode of Cybersecurity Today, host David Shipley discusses a new significant React vulnerability, React2Shell, tha…
Cybersecurity Today Month In Review - December 5th, 2025 [not-audio_url] [/not-audio_url]

Duration: 54:06
Cybersecurity Today: The Rise of Living Off the Land Strategies & More In this episode of Cybersecurity Today's Month in Review, host Jim Love is joined by Laura Payne from White Tuque and David Shipley from Beauceron Se…
Living off the Land Attacks and Emerging Cyber Threats [not-audio_url] [/not-audio_url]

Duration: 12:42
This episode of Cybersecurity Today, hosted by Jim Love, delves into various cybersecurity threats and latest news. Topics include 'living off the land' attacks using Microsoft's native utilities, spoofing Calendly invit…