© The Author(s), under exclusive license to APress Media, LLC, part of Springer Nature 2022
R. LeirvikUnderstand, Manage, and Measure Cyber Riskhttps://doi.org/10.1007/978-1-4842-7821-5_4

4. Understanding the Problem

Ryan Leirvik1  
Arlington, VA, USA

Knowing which problem you are solving is the most critical part in solving any problem, and cybersecurity risk is no different. Spending time exploring the main issues helps ensure a crisp and accurate problem statement. This typically means asking probing questions within the organization to identify what others see as the problem, gathering facts and opinions (and knowing the difference between the two), and then agreeing upon a problem statement to solve that categorically encompasses all the ...

