From Risk to Trust

Cybersecurity, mapped in four volumes.

A practical four-volume reference connecting the domains cybersecurity leaders and senior practitioners are expected to lead — written from two decades of building, running, and defending those programs directly.

Available in paperback and Kindle editions

2,281pages across
four connected volumes
Find the Series on Amazon
Four connected volumes rendered as a single continuous line of reasoning.

The series

Four volumes. One connected operating model.

Each volume stands on its own and cross-references the others — the way the actual job requires moving between governance, risk, assurance, and operations rather than staying in one lane.

Front cover of From Risk to Trust, Volume I: The CISO Operating Model
IVolume I

The CISO Operating Model

538 pages

  • CISO role, accountability, and leadership
  • ISO 27001, NIST CSF, SOC 2, CIS, and CSA
  • First 90/180 days and function scaling
  • COBIT, FAIR, and framework integration
  • Budgeting, business cases, and risk appetite
  • Governance forums, policy, and decision rights
  • Security organization and operating model
  • Board reporting, dashboards, and metrics
Front cover of From Risk to Trust, Volume II: Cyber Risk and Controls
IIVolume II

Cyber Risk and Controls

652 pages

  • Risk taxonomy, classification, and appetite
  • IAM, PAM, assets, and vulnerabilities
  • RCSA, registers, treatment, and acceptance
  • Logging, endpoint, and network security
  • FAIR, ISO 31000/27005, and NIST RMF
  • Cloud security, DevSecOps, and cryptography
  • Threat scenarios and board articulation
  • Recovery, human, physical, and supplier risk
Front cover of From Risk to Trust, Volume III: Digital Trust and Assurance
IIIVolume III

Digital Trust and Assurance

538 pages

  • Compliance, audit, evidence, and certification
  • Global regulation and cross-border transfers
  • Continuous assurance and corrective action
  • Cloud, containers, APIs, and secrets
  • Data security and information lifecycle
  • DevSecOps and Zero Trust
  • Privacy governance and operations
  • Product, supply-chain, OT, and IoT security
Front cover of From Risk to Trust, Volume IV: The Applied CISO Reference
IVVolume IV

The Applied CISO Reference

553 pages

  • AI security and governance
  • Third-party, SaaS, and supply-chain risk
  • Security operations and threat intelligence
  • Customer assurance, contracts, and reviews
  • Incident response, ransomware, crisis, and forensics
  • Control mapping, traceability, and board metrics
  • Cyber resilience, BCP, DR, and backup
  • Insurance, M&A, advisory, and interview guides

At a glance

Recognizable coverage across the profession

CISO leadershipBudgetingGovernanceBoard reportingRisk management ISO 27001SOC 2ComplianceAuditPrivacyData security IAM and PAMNetwork securityCloud securityDevSecOpsZero Trust Product securityAI securityIncident responseResilienceThird-party risk

Get the series

Take the operating model with you

Paperback and Kindle, four volumes, 2,281 pages.