Ask Me Anything with Tom Keogh


Recording

General

What does it actually take to trace a technical vulnerability to a line on the income statement? Tom Keogh, founder of Square One Risk and a practitioner with 20 years across global enterprises, joined Marie Giesbert to answer exactly that.

The conversation is grounded in practice, not theory. Tom walks through the discipline of connecting vulnerability data to business impact, step by step, asking “and then what?” until the financial consequence becomes undeniable. He shares a case where quantification reversed what looked like an obvious decision: a fix that seemed cheap turned out to cost ten times the problem it was solving. The numbers changed the call before any formal analysis was even run.

The session also covers what it takes to build a CRQ program that lasts, without a large team, without starting from tooling, and without losing momentum after the first year. Tom’s view is direct: programs built around answering specific business questions survive; programs built around producing analyses don’t.

Forty-five minutes. One practitioner. The kind of conversation that makes cyber risk feel like a business management problem, because it is.

Learn more

For more information, you can always visit our site

Connect with team

Marie Giesbert

Marie Giesbert

Connect on LinkedIn